Rare Wolf prepares for the hunt

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
The PT ESC cyberthreat intelligence team consistently tracks down new command-and-control servers used by threat groups, as well as the tools involved in attacks. Recently, we came across artifacts indicating that the Rare Wolf group is in the preparation stage for new attacks: malware payload samples and new persistence techniques have been identified.
The Rare Wolf group was first described by colleagues in late 2023. In September 2024, changes in the attackers’ behavior (under a different name — Librarian Ghouls) were described by other researchers. Initially, the attack involved collecting data from office documents and Telegram sessions, and last year the group began hunting for files related to computer-aided design and engineering software such as AutoCAD and SolidWorks.
🔗 The new attack chain — a mix of previous attacks with new tools and techniques being tested by the group.
A
.scr/.exe file disguised as a legitimate document is sent to the victim. When the executable is opened, the same cmd script is created, but under a new name, find.cmd, and a decoy document is launched. The script is responsible for launching the next stages of the attack: downloading tools for the subsequent attack, configuring data for sending the collected information via email, and installing AnyDesk. Among the new steps, we noticed the following.Use of ngrok:
C:\Users\admin\AppData\Roaming\Windows\driver.exe x -r -ep2 -hplimpid2903392 C:\Users\admin\AppData\Roaming\Windows\pas.rar ngrok.exe C:\Users\admin\AppData\Roaming\Windows\ /yCode language: YAML (yaml)Adding a new scheduled task “Find update” to launch ngrok in hidden mode using the NirCmd utility:
schtasks /create /tn "Find update" /tr "C:\Users\admin\AppData\Roaming\Windows\nircmd.exe exec hide C:\Users\admin\AppData\Roaming\Windows\task.bat" /sc onlogon /rl highest /fCode language: plaintext (plaintext)Working directory change: now instead of the hidden folder
C:\Intel, %APPDATA%\Windows is used.The
bat.bat file has also been upgraded. It is now responsible for collecting system data, sending it to a mail server, and launching a new ssh.ps1, which opens port 22 and starts the sshd service. The task.bat added to autorun, possibly written with the help of a neural network (judging by the Russian-language comments in the code), is responsible for launching ngrok and hiding it using NirCmd so that the user does not see the console window.In previous attacks,
rezet.cmd collected files by extension (doc, docx, pdf, etc.), while bat.bat searched for data related to crypto wallets. These actions are absent in the new samples.In addition, the attack being tested by the threat actors includes the files
ps.ps1 and bat1.bat. They are not executed in the current version of the attack, but are also presumably written with the help of neural networks and may be intended for manual execution. The bat1.bat file scans the network for active devices, finds shared Users folders, and copies the malicious .SCR file to the Downloads, Desktop, and Public directories. It then launches ps.ps1, which adds Edge to autorun and deletes the previous script.🕵️ IoCs were published on Telegraph.




#TI #APT #Malware
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



