Tag: Rare Werewolf (previously Rare Wolf)

Rare Werewolf APT Uses Legitimate Software in Attacks on Hundreds of Russian Enterprises
News

Rare Werewolf APT Uses Legitimate Software in Attacks on Hundreds of Russian Enterprises

Numerous cyberattacks on Russia and the Commonwealth of Independent States (CIS) nations have been connected to the threat actor Rare Werewolf (previously Rare Wolf). The attackers' preference for utilizing trustworthy third-party software versus creating their own malicious binaries is a defining characteristic of this threat, according to Kaspersky. "PowerShell scripts and command files are used to carry out the malicious functionality of the campaign detailed in this article. The assaults aim to remotely access compromised servers, spoof login credentials, and install the bitcoin miner XMRig. A lower number of infections were also reported in Belarus and Kazakhstan, but the activity affected hundreds of Russian users from engineering colleges and industrial businesses. An adva...