216.73.216.233

Sapphire Werewolf refines Amethyst stealer to attack energy companies

· Published 09/04/2025 15:50 · Modified 09/04/2025 20:10

Export JSON

Essential information

Published
09/04/2025 15:50
Modified
09/04/2025 20:10
Tags
2025-04-09 amethyst stealer credential-theft phishing virtualization detection
Related entities
1 intrusion sets (apt), 13 techniques (mitre), 1 malware, 1 others

Description

The Sapphire Werewolf cluster has upgraded its toolkit with a new version of the , targeting energy companies through emails. The enhanced malware features advanced checks for virtualized environments and uses Triple DES for string encryption. The attack involves distributing a malicious attachment disguised as an official memo, which contains a C#-based loader protected with .NET Reactor. The collects extensive system data, credentials from various applications, and documents from compromised systems. The threat actor's sophisticated approach includes improved evasion techniques and data exfiltration methods, posing a significant risk to targeted organizations.

External references