A sophisticated cyberattack campaign, attributed to the Advanced Persistent Threat (APT) group known as Librarian Ghouls (also Rare Werewolf and Rezet), has been actively targeting Russian and CIS entities. The group employs legitimate third-party software to establish remote access, steal credentials, and deploy XMRig cryptocurrency miners, impacting hundreds of industrial enterprises and engineering schools.
Key Takeaways
-
Sophisticated Phishing: Librarian Ghouls employs highly convincing phishing emails tailored to Russian-speaking targets.
-
Abuse of Legitimate Software: A defining characteristic is the extensive use of legitimate third-party tools, making detection and attribution challenging.
-
Stealthy Operations: The scheduled wake-up and shutdown times are designed to hide their activities from users.
-
Dual Objective: The group aims for both data theft (credentials, crypto wallets) and financial gain through cryptojacking.
-
Ongoing Threat: The campaign remains active, with continuous refinement of tactics and tools observed by cybersecurity researchers.
Librarian Ghouls: A Persistent Threat
Rare Werewolf has been active since at least 2019, consistently focusing on organizations in Russia and the Commonwealth of Independent States (CIS). Their operations, which continued through May 2025, primarily target industrial enterprises and engineering schools, with some victims also reported in Belarus and Kazakhstan. The group's tactics suggest a potential hacktivist motivation, characterized by their reliance on readily available, legitimate software rather than custom-developed malware.
Modus Operandi: Phishing and Legitimate Tools
The initial infection vector for Librarian Ghouls is highly targeted phishing emails. These emails, often crafted in Russian and containing Russian-language filenames and decoy documents, are disguised as official communications or payment orders. They include password-protected archives containing malicious executables. Once a victim opens these files, a complex infection chain is initiated:
-
Initial Payload: An installer, often created with Smart Install Maker, deploys legitimate software like 4t Tray Minimizer to obscure their presence.
-
Remote Access and Data Exfiltration: Intermediate payloads fetch additional tools from remote servers, including:
-
AnyDesk: For remote control of compromised machines.
-
Blat: A utility for sending stolen data via SMTP.
-
Defender Control: To disable Windows Defender.
-
Customized WinRAR 3.80: For data compression.
-
WebBrowserPassView: To steal browser-stored credentials.
-
Mipko Personal Monitor: For monitoring victims, including screenshots and keystrokes.
-
ngrok: For secure network service connections.
-
NirCmd: For covertly running scripts.
-
-
Scheduled Operations: The attackers program infected devices to wake up at 1 AM and shut down at 5 AM local time. This four-hour window allows them to conduct their activities, such as data theft and crypto mining, while minimizing user suspicion.
-
Data Theft: The group specifically targets:
-
Cryptocurrency wallet credentials and seed phrases.
-
Dumps of HKLM\SAM and HKLM\SYSTEM registry keys.
-
-
Cryptocurrency Mining: After data exfiltration, the XMRig cryptocurrency miner is installed. The miner is configured based on the victim's system information (CPU cores, RAM, GPU) to optimize mining operations.
Organizations in Russia and CIS countries are urged to enhance their cybersecurity defenses, implement robust email security measures, and educate employees about phishing threats to mitigate the risks posed by this evolving APT group.
Sources
-
Rare Werewolf APT Uses Legitimate Software in Attacks on Hundreds of Russian Enterprises, The Hacker News.
-
Cryptojacking Group Hacks Hundreds Of Devices To Mine Crypto, Cointelegraph.
-
'Librarian Ghouls' APT Group Targets Organizations, GBHackers News.
-
Librarian Ghouls APT carries out attacks with data theft and crypto miner deployment, Securelist.
-
Hacker group Rare Werewolf hijacks Russian devices to mine crypto and steal data, Crypto News.
This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.
