216.73.216.6

Espionage cluster Paper Werewolf engages in destructive behavior

· Published 25/12/2024 20:12 · Modified 26/12/2024 20:50

Export JSON

Essential information

Published
25/12/2024 20:12
Modified
26/12/2024 20:50
Tags
2024-12-25 freyja goffee owowa phishing powerrat powershell powertaskel qwakmyagent
Related entities
1 intrusion sets (apt), 18 techniques (mitre), 5 malware, 5 others

Description

The Paper Werewolf cluster, also known as , has increased its activity, targeting Russian organizations in government, energy, finance, and media sectors. Their primary method involves emails with malicious Microsoft Word attachments containing macros. The group has evolved from cyber espionage to actively disrupting compromised infrastructures. They utilize scripts, custom malware, and post-exploitation frameworks like Mythic. The attackers employ techniques such as reverse shells, credential interception, and destructive actions like changing passwords and deleting registry keys. Their arsenal includes tools like , , and Chisel. The group's sophisticated approach combines open-source frameworks with custom implants, making detection challenging.

External references