216.73.216.197

From Invoice to AnyDesk: Uncovering a Phishing Campaign Targeting Russian Aerospace Organizations

· Published 09/07/2026 13:27

Export JSON

Essential information

Published
09/07/2026 13:27
Modified
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
aerospace targeting anydesk living-off-the-land remote access tool russian victims scheduled task persistence smtp exfiltration spear-phishing
Related entities
9 indicators, 5 observables, 1 intrusion sets (apt), 15 techniques (mitre)

Description

A sophisticated campaign targeting Russian aerospace and aviation organizations has been identified, likely attributed to the Rare Werewolf threat group. The attack begins with fraudulent emails impersonating a legitimate Russian aerospace research institute, delivering password-protected archives containing malicious installers. The campaign employs techniques, abusing legitimate tools including , Blat, WinRAR, and Tray Minimizer to establish persistent remote access. The attack chain deploys portable with unattended access configured using a predefined password, exfiltrates configuration data via SMTP to attacker-controlled infrastructure, and establishes persistence through scheduled tasks. The operators conceal their activities by minimizing the interface and removing forensic artifacts. This methodology aligns with previously documented Rare Werewolf campaigns targeting strategically important sectors across Russia, Belarus, and Kazakhstan, par...

External references