[ << ALL_FEED ]

No longer Rezet, or the New Attacks of Rare Wolf

More in General

No Longer Rezet, or New Rare Wolf Attacks 🐺

The PT ESC cyber intelligence group continues to record attacks by the Rare Wolf group: for example, in late May, the attackers sent phishing emails on behalf of antey-almaz-info.site to defense industry companies. The current campaign is very similar to the one we described in late January (screenshot 1).

The group still delivers a malicious SCR file inside an archive, with the password provided in the email body. When launched, the SCR file distracts the victim by opening a decoy document while simultaneously downloading an archive with PowerShell and BAT scripts to the host. This time, a hidden folder C:\Users\admin\Window is used to extract the scripts (screenshots 2–3).

Rare Wolf still collects system information, including dumps of the SAM and SYSTEM registry hives, scans local subnets in an attempt to copy files from other devices, and covertly installs AnyDesk for remote access.

🕗 It should be noted that the local subnet scan uses hardcoded IP addresses and takes about 9–10 minutes, which significantly exceeds the dynamic analysis limits of most public sandboxes. Typically, such services limit emulation time to a few minutes (from 1 to 6), and in extended modes — no more than 10–12 minutes. The purpose of such delays is likely to prevent sandboxes from recording the malicious files’ further actions.

🙅‍♂️ The only notable changes are the abandonment of the rezet.cmd file previously used in attacks and the switch from public tunneling via ngrok to a custom reverse SSH tunnel using Tuna and the standard sshd — this improves the stealth and reliability of the communication channel with the C2 server.

To achieve this, the attackers install the sshd daemon and the tuna.exe executable on the infected device, add a firewall rule allowing inbound TCP port 22, and configure key authentication, ensuring the sshd service starts automatically at system boot and maintaining a reverse SSH connection to the command server. Tuna initiates an outbound connection to the C2 and proxies all traffic to the local sshd daemon, providing a covert and secure channel.

😠 When attempting to manually invoke tuna (for example, running tuna tcp 22 in the command line), you can see the email address used by the attackers. The screenshot also shows an error stating that the account is inactive — perhaps they simply forgot to renew the payment (screenshot 4).

In March of this year, the group also attempted to distribute malware, but the archive password did not match the one specified by the attackers in the email body. And the domain used, almaz-antey-info.online, was a slightly modified version of the domain used in the May attacks (screenshot 5).

IoCs

mir.travelldn@gmail.com

almaz-antey-info.online
antey-almaz-info.site

b7543b3e0c3fa6bd8973dde12258c7f7
fc0b6c43185061c2b3b11ab0bfdf924f 
9eb2c87299e3b1d86268ab1752b83502
Code language: plaintext (plaintext)


#TI #APT #phishing #malware #ioc
@ptescalator

More from ti_author

More from ti_author

More in General