Skip to main content

From Invoice to AnyDesk: Uncovering a Phishing Campaign Targeting Russian Aerospace Organizations

0
Medium
Published: 07/09/2026 (07/09/2026, 11:27:09 UTC)
Source: AlienVault OTX General

Description

A sophisticated spear-phishing campaign targeting Russian aerospace and aviation organizations has been identified, likely attributed to the Rare Werewolf threat group. The attack begins with fraudulent emails impersonating a legitimate Russian aerospace research institute, delivering password-protected archives containing malicious installers. The campaign employs living-off-the-land techniques, abusing legitimate tools including AnyDesk, Blat, WinRAR, and Tray Minimizer to establish persistent remote access. The attack chain deploys portable AnyDesk with unattended access configured using a predefined password, exfiltrates configuration data via SMTP to attacker-controlled infrastructure, and establishes persistence through scheduled tasks. The operators conceal their activities by minimizing the AnyDesk interface and removing forensic artifacts. This methodology aligns with previously documented Rare Werewolf campaigns targeting strategically important sectors across Russia, Belarus, and Kazakhstan, par...

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/08/2026, 12:41:36 UTC

Technical Analysis

This campaign involves spear-phishing emails impersonating a Russian aerospace research institute, delivering password-protected archives containing malicious installers. The attackers leverage living-off-the-land techniques by abusing legitimate tools including AnyDesk (configured for unattended remote access), Blat (SMTP exfiltration), WinRAR, and Tray Minimizer. Persistence is achieved through scheduled tasks, and the attackers conceal their presence by minimizing the AnyDesk interface and removing forensic artifacts. The campaign is attributed to the Rare Werewolf threat group and targets aerospace and aviation organizations primarily in Russia and neighboring countries. The attack chain facilitates persistent remote access and data exfiltration to attacker-controlled infrastructure.

Potential Impact

The campaign enables attackers to gain persistent remote access to targeted aerospace organizations, potentially allowing unauthorized data exfiltration and long-term espionage. The use of legitimate tools complicates detection and forensic analysis. The targeting of strategic aerospace and aviation sectors in Russia and nearby countries suggests potential impact on critical infrastructure and sensitive information confidentiality.

Defensive Guidance

No official patch or fix applies as this is a phishing campaign leveraging legitimate tools. Organizations should focus on user awareness training to recognize spear-phishing attempts, implement email filtering to block malicious attachments, and monitor for unusual use of AnyDesk and other legitimate tools. Restricting or monitoring the use of remote access tools like AnyDesk and enforcing strong password policies for unattended access can reduce risk. Scheduled tasks should be audited regularly to detect unauthorized persistence mechanisms. Since this campaign uses living-off-the-land techniques, endpoint detection and response (EDR) solutions tuned to detect anomalous behavior of legitimate tools are recommended.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.seqrite.com/blog/from-invoice-to-anydesk-uncovering-a-phishing-campaign-targeting-russian-aerospace-organizations/"]
Adversary
Rare Werewolf
Pulse Id
6a4f858d17f60f10d1e16c2c

Indicators of Compromise

Ip

ValueDescriptionCopy
ip194.87.57.81
—
ip109.106.178.14
—
ip198.54.120.13
—

Hash

ValueDescriptionCopy
hash0dc0fa727f900ed5033f46f8ba6cf2d97d20ab95fd334cabc0f216da6e0622b0
—
hash144a0a499e007931628c98f38929466f
—
hashc7eccd855d2e97b57420afd23a4b9261f42f5b84
—
hash12648cd9d425f78db2dbc6e03c14f11e6ac6aadf8b3975c23cce9519e2b58d33
—
hash47854deb456cb08c651b7f9ae2f9d87c72d0719de6af233340632efb3c1980f4
—
hashf57e010541fb4ccbf23aefc4a827f753a6ff3f8792d9c04c3eea83f6963c6bae
—
hash6cc3c68c56e099792fdeadde76256d56
—
hash7884be8a701f31421717c0835add92d5
—
hasheabd440c996846d0992e37ab01d01208
—
hash5d9d91cf9da3b37d8eee87d5d4dd38dbfec28358
—
hash7d415612a00d99617bd89670e1570c145863ad08
—
hashee577f1880397a00480b210fcd6bc84d2330a19e
—

Domain

ValueDescriptionCopy
domainvniir-info.space
—
domainvniir-avia.space
—

Threat ID: 6a4f9c6568715ace4365dcef

Added to database: 07/09/2026, 13:04:37 UTC

Last enriched: 08/08/2026, 12:41:36 UTC

Last updated: 10/04/2026, 02:10:24 UTC

Views: 272

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses