From Invoice to AnyDesk: Uncovering a Phishing Campaign Targeting Russian Aerospace Organizations
A sophisticated spear-phishing campaign targeting Russian aerospace and aviation organizations has been identified, likely attributed to the Rare Werewolf threat group. The attack begins with fraudulent emails impersonating a legitimate Russian aerospace research institute, delivering password-protected archives containing malicious installers. The campaign employs living-off-the-land techniques, abusing legitimate tools including AnyDesk, Blat, WinRAR, and Tray Minimizer to establish persistent remote access. The attack chain deploys portable AnyDesk with unattended access configured using a predefined password, exfiltrates configuration data via SMTP to attacker-controlled infrastructure, and establishes persistence through scheduled tasks. The operators conceal their activities by minimizing the AnyDesk interface and removing forensic artifacts. This methodology aligns with previously documented Rare Werewolf campaigns targeting strategically important sectors across Russia, Belarus, and Kazakhstan, par...
AI Analysis
Technical Summary
This campaign involves spear-phishing emails impersonating a Russian aerospace research institute, delivering password-protected archives containing malicious installers. The attackers leverage living-off-the-land techniques by abusing legitimate tools including AnyDesk (configured for unattended remote access), Blat (SMTP exfiltration), WinRAR, and Tray Minimizer. Persistence is achieved through scheduled tasks, and the attackers conceal their presence by minimizing the AnyDesk interface and removing forensic artifacts. The campaign is attributed to the Rare Werewolf threat group and targets aerospace and aviation organizations primarily in Russia and neighboring countries. The attack chain facilitates persistent remote access and data exfiltration to attacker-controlled infrastructure.
Potential Impact
The campaign enables attackers to gain persistent remote access to targeted aerospace organizations, potentially allowing unauthorized data exfiltration and long-term espionage. The use of legitimate tools complicates detection and forensic analysis. The targeting of strategic aerospace and aviation sectors in Russia and nearby countries suggests potential impact on critical infrastructure and sensitive information confidentiality.
Mitigation Recommendations
No official patch or fix applies as this is a phishing campaign leveraging legitimate tools. Organizations should focus on user awareness training to recognize spear-phishing attempts, implement email filtering to block malicious attachments, and monitor for unusual use of AnyDesk and other legitimate tools. Restricting or monitoring the use of remote access tools like AnyDesk and enforcing strong password policies for unattended access can reduce risk. Scheduled tasks should be audited regularly to detect unauthorized persistence mechanisms. Since this campaign uses living-off-the-land techniques, endpoint detection and response (EDR) solutions tuned to detect anomalous behavior of legitimate tools are recommended.
Affected Countries
Russia, Belarus, Kazakhstan
Indicators of Compromise
- ip: 194.87.57.81
- hash: 0dc0fa727f900ed5033f46f8ba6cf2d97d20ab95fd334cabc0f216da6e0622b0
- hash: 144a0a499e007931628c98f38929466f
- hash: c7eccd855d2e97b57420afd23a4b9261f42f5b84
- hash: 12648cd9d425f78db2dbc6e03c14f11e6ac6aadf8b3975c23cce9519e2b58d33
- hash: 47854deb456cb08c651b7f9ae2f9d87c72d0719de6af233340632efb3c1980f4
- hash: f57e010541fb4ccbf23aefc4a827f753a6ff3f8792d9c04c3eea83f6963c6bae
- ip: 109.106.178.14
- ip: 198.54.120.13
- domain: vniir-info.space
- domain: vniir-avia.space
- hash: 6cc3c68c56e099792fdeadde76256d56
- hash: 7884be8a701f31421717c0835add92d5
- hash: eabd440c996846d0992e37ab01d01208
- hash: 5d9d91cf9da3b37d8eee87d5d4dd38dbfec28358
- hash: 7d415612a00d99617bd89670e1570c145863ad08
- hash: ee577f1880397a00480b210fcd6bc84d2330a19e
From Invoice to AnyDesk: Uncovering a Phishing Campaign Targeting Russian Aerospace Organizations
Description
A sophisticated spear-phishing campaign targeting Russian aerospace and aviation organizations has been identified, likely attributed to the Rare Werewolf threat group. The attack begins with fraudulent emails impersonating a legitimate Russian aerospace research institute, delivering password-protected archives containing malicious installers. The campaign employs living-off-the-land techniques, abusing legitimate tools including AnyDesk, Blat, WinRAR, and Tray Minimizer to establish persistent remote access. The attack chain deploys portable AnyDesk with unattended access configured using a predefined password, exfiltrates configuration data via SMTP to attacker-controlled infrastructure, and establishes persistence through scheduled tasks. The operators conceal their activities by minimizing the AnyDesk interface and removing forensic artifacts. This methodology aligns with previously documented Rare Werewolf campaigns targeting strategically important sectors across Russia, Belarus, and Kazakhstan, par...
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This campaign involves spear-phishing emails impersonating a Russian aerospace research institute, delivering password-protected archives containing malicious installers. The attackers leverage living-off-the-land techniques by abusing legitimate tools including AnyDesk (configured for unattended remote access), Blat (SMTP exfiltration), WinRAR, and Tray Minimizer. Persistence is achieved through scheduled tasks, and the attackers conceal their presence by minimizing the AnyDesk interface and removing forensic artifacts. The campaign is attributed to the Rare Werewolf threat group and targets aerospace and aviation organizations primarily in Russia and neighboring countries. The attack chain facilitates persistent remote access and data exfiltration to attacker-controlled infrastructure.
Potential Impact
The campaign enables attackers to gain persistent remote access to targeted aerospace organizations, potentially allowing unauthorized data exfiltration and long-term espionage. The use of legitimate tools complicates detection and forensic analysis. The targeting of strategic aerospace and aviation sectors in Russia and nearby countries suggests potential impact on critical infrastructure and sensitive information confidentiality.
Defensive Guidance
No official patch or fix applies as this is a phishing campaign leveraging legitimate tools. Organizations should focus on user awareness training to recognize spear-phishing attempts, implement email filtering to block malicious attachments, and monitor for unusual use of AnyDesk and other legitimate tools. Restricting or monitoring the use of remote access tools like AnyDesk and enforcing strong password policies for unattended access can reduce risk. Scheduled tasks should be audited regularly to detect unauthorized persistence mechanisms. Since this campaign uses living-off-the-land techniques, endpoint detection and response (EDR) solutions tuned to detect anomalous behavior of legitimate tools are recommended.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.seqrite.com/blog/from-invoice-to-anydesk-uncovering-a-phishing-campaign-targeting-russian-aerospace-organizations/"]
- Adversary
- Rare Werewolf
- Pulse Id
- 6a4f858d17f60f10d1e16c2c
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip194.87.57.81 | — | |
ip109.106.178.14 | — | |
ip198.54.120.13 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash0dc0fa727f900ed5033f46f8ba6cf2d97d20ab95fd334cabc0f216da6e0622b0 | — | |
hash144a0a499e007931628c98f38929466f | — | |
hashc7eccd855d2e97b57420afd23a4b9261f42f5b84 | — | |
hash12648cd9d425f78db2dbc6e03c14f11e6ac6aadf8b3975c23cce9519e2b58d33 | — | |
hash47854deb456cb08c651b7f9ae2f9d87c72d0719de6af233340632efb3c1980f4 | — | |
hashf57e010541fb4ccbf23aefc4a827f753a6ff3f8792d9c04c3eea83f6963c6bae | — | |
hash6cc3c68c56e099792fdeadde76256d56 | — | |
hash7884be8a701f31421717c0835add92d5 | — | |
hasheabd440c996846d0992e37ab01d01208 | — | |
hash5d9d91cf9da3b37d8eee87d5d4dd38dbfec28358 | — | |
hash7d415612a00d99617bd89670e1570c145863ad08 | — | |
hashee577f1880397a00480b210fcd6bc84d2330a19e | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainvniir-info.space | — | |
domainvniir-avia.space | — |
Threat ID: 6a4f9c6568715ace4365dcef
Added to database: 07/09/2026, 13:04:37 UTC
Last enriched: 08/08/2026, 12:41:36 UTC
Last updated: 08/22/2026, 17:08:54 UTC
Views: 133
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.