Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

From Invoice to AnyDesk: Uncovering a Phishing Campaign Targeting Russian Aerospace Organizations

0
Medium
Published: 07/09/2026 (07/09/2026, 11:27:09 UTC)
Source: AlienVault OTX General

Description

A sophisticated spear-phishing campaign targeting Russian aerospace and aviation organizations has been identified, likely attributed to the Rare Werewolf threat group. The attack begins with fraudulent emails impersonating a legitimate Russian aerospace research institute, delivering password-protected archives containing malicious installers. The campaign employs living-off-the-land techniques, abusing legitimate tools including AnyDesk, Blat, WinRAR, and Tray Minimizer to establish persistent remote access. The attack chain deploys portable AnyDesk with unattended access configured using a predefined password, exfiltrates configuration data via SMTP to attacker-controlled infrastructure, and establishes persistence through scheduled tasks. The operators conceal their activities by minimizing the AnyDesk interface and removing forensic artifacts. This methodology aligns with previously documented Rare Werewolf campaigns targeting strategically important sectors across Russia, Belarus, and Kazakhstan, par...

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/08/2026, 12:41:36 UTC

Technical Analysis

This campaign involves spear-phishing emails impersonating a Russian aerospace research institute, delivering password-protected archives containing malicious installers. The attackers leverage living-off-the-land techniques by abusing legitimate tools including AnyDesk (configured for unattended remote access), Blat (SMTP exfiltration), WinRAR, and Tray Minimizer. Persistence is achieved through scheduled tasks, and the attackers conceal their presence by minimizing the AnyDesk interface and removing forensic artifacts. The campaign is attributed to the Rare Werewolf threat group and targets aerospace and aviation organizations primarily in Russia and neighboring countries. The attack chain facilitates persistent remote access and data exfiltration to attacker-controlled infrastructure.

Potential Impact

The campaign enables attackers to gain persistent remote access to targeted aerospace organizations, potentially allowing unauthorized data exfiltration and long-term espionage. The use of legitimate tools complicates detection and forensic analysis. The targeting of strategic aerospace and aviation sectors in Russia and nearby countries suggests potential impact on critical infrastructure and sensitive information confidentiality.

Defensive Guidance

No official patch or fix applies as this is a phishing campaign leveraging legitimate tools. Organizations should focus on user awareness training to recognize spear-phishing attempts, implement email filtering to block malicious attachments, and monitor for unusual use of AnyDesk and other legitimate tools. Restricting or monitoring the use of remote access tools like AnyDesk and enforcing strong password policies for unattended access can reduce risk. Scheduled tasks should be audited regularly to detect unauthorized persistence mechanisms. Since this campaign uses living-off-the-land techniques, endpoint detection and response (EDR) solutions tuned to detect anomalous behavior of legitimate tools are recommended.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.seqrite.com/blog/from-invoice-to-anydesk-uncovering-a-phishing-campaign-targeting-russian-aerospace-organizations/"]
Adversary
Rare Werewolf
Pulse Id
6a4f858d17f60f10d1e16c2c
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip194.87.57.81
ip109.106.178.14
ip198.54.120.13

Hash

ValueDescriptionCopy
hash0dc0fa727f900ed5033f46f8ba6cf2d97d20ab95fd334cabc0f216da6e0622b0
hash144a0a499e007931628c98f38929466f
hashc7eccd855d2e97b57420afd23a4b9261f42f5b84
hash12648cd9d425f78db2dbc6e03c14f11e6ac6aadf8b3975c23cce9519e2b58d33
hash47854deb456cb08c651b7f9ae2f9d87c72d0719de6af233340632efb3c1980f4
hashf57e010541fb4ccbf23aefc4a827f753a6ff3f8792d9c04c3eea83f6963c6bae
hash6cc3c68c56e099792fdeadde76256d56
hash7884be8a701f31421717c0835add92d5
hasheabd440c996846d0992e37ab01d01208
hash5d9d91cf9da3b37d8eee87d5d4dd38dbfec28358
hash7d415612a00d99617bd89670e1570c145863ad08
hashee577f1880397a00480b210fcd6bc84d2330a19e

Domain

ValueDescriptionCopy
domainvniir-info.space
domainvniir-avia.space

Threat ID: 6a4f9c6568715ace4365dcef

Added to database: 07/09/2026, 13:04:37 UTC

Last enriched: 08/08/2026, 12:41:36 UTC

Last updated: 08/22/2026, 17:08:54 UTC

Views: 133

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses