Rare Werewolf
❔ UnknownLast active: 2026-08-08First seen: 2026-07-09
0
linked CVEs
Targeted industries
Aerospace
Targeted regions
Russian Federation
A sophisticated spear-phishing campaign targeting Russian aerospace and aviation organizations has been identified, likely attributed to the Rare Werewolf threat group. The attack begins with fraudulent emails impersonating a legitimate Russian aerospace research institute, delivering password-protected archives containing malicious installers. The campaign employs living-off-the-land techniques, abusing legitimate tools including AnyDesk, Blat, WinRAR, and Tray Minimizer to establish persistent remote access. The attack chain deploys portable AnyDesk with unattended access configured using a predefined password, exfiltrates configuration data via SMTP to attacker-controlled infrastructure, and establishes persistence through scheduled tasks. The operators conceal their activities by minimizing the AnyDesk interface and removing forensic artifacts. This methodology aligns with previously documented Rare Werewolf campaigns targeting strategically important sectors across Russia, Belarus, and Kazakhstan, par...
Source: otx · Collected: 2026-08-10
⚡ Vulnerabilities & Exploits0 CVEs
threat_actor_cve → cves / exploits.cve_ids
No CVE correlation on record for this actor yet.
🔍 Detection Coverage0 Sigma
Derived from linked CVEs — not a direct actor match
No Sigma rules mapped via this actor's CVEs yet.
🧬 YaraComing soon
🛰️ Infrastructure & IOCs14
| sha256 | 0dc0fa727f900ed5033f46f8ba6cf2d97d20ab95fd334cabc0f216da6e0622b0 | — | 2026-08-08 |
| md5 | 144a0a499e007931628c98f38929466f | — | 2026-08-08 |
| sha1 | c7eccd855d2e97b57420afd23a4b9261f42f5b84 | — | 2026-08-08 |
| sha256 | 12648cd9d425f78db2dbc6e03c14f11e6ac6aadf8b3975c23cce9519e2b58d33 | — | 2026-08-08 |
| sha256 | 47854deb456cb08c651b7f9ae2f9d87c72d0719de6af233340632efb3c1980f4 | — | 2026-08-08 |
| sha256 | f57e010541fb4ccbf23aefc4a827f753a6ff3f8792d9c04c3eea83f6963c6bae | — | 2026-08-08 |
| domain | vniir-info.space | — | 2026-08-08 |
| domain | vniir-avia.space | — | 2026-08-08 |
| md5 | 6cc3c68c56e099792fdeadde76256d56 | — | 2026-08-08 |
| md5 | 7884be8a701f31421717c0835add92d5 | — | 2026-08-08 |
| md5 | eabd440c996846d0992e37ab01d01208 | — | 2026-08-08 |
| sha1 | 5d9d91cf9da3b37d8eee87d5d4dd38dbfec28358 | — | 2026-08-08 |
| sha1 | 7d415612a00d99617bd89670e1570c145863ad08 | — | 2026-08-08 |
| sha1 | ee577f1880397a00480b210fcd6bc84d2330a19e | — | 2026-08-08 |
📰 Threat Intel Coverage0
Digest reports mentioning this actor (incl. aliases)
No threat intel digest coverage found.