Librarian Ghouls carry out attacks with data theft and crypto miner deployment (securelist.com)
from Pro@programming.dev to cybersecurity@infosec.pub on 09 Jun 11:18
https://programming.dev/post/31891380

#cybersecurity

threaded - newest

Pro@programming.dev on 09 Jun 11:19 collapse

Librarian Ghouls, also known as “Rare Werewolf” and “Rezet”, is an APT group that targets entities in Russia and the CIS. Other security vendors are also monitoring this APT and releasing analyses of its campaigns. The group has remained active through May 2025, consistently targeting Russian companies.

A distinctive feature of this threat is that the attackers favor using legitimate third-party software over developing their own malicious binaries. The malicious functionality of the campaign described in this article is implemented through command files and PowerShell scripts. The attackers establish remote access to the victim’s device, steal credentials, and deploy an XMRig crypto miner in the system.

Our research has uncovered new tools within this APT group’s arsenal, which we will elaborate on in this article.