Rare Werewolf is a threat actor known for targeting organizations in Russia, Belarus, and Kazakhstan, with a particular focus on industrial, engineering, aerospace, and aviation-related entities. The group is also known as Librarian Ghouls and has previously been referred to as Rare Wolf. Available reporting consistently associates it with campaigns against Russian organizations, including aerospace-sector targets, using spear-phishing and low-noise post-compromise tradecraft oriented toward persistent remote access and espionage-like collection. Rare Werewolf commonly relies on phishing lures themed around business documents such as invoices and uses spoofed or lookalike sender infrastructure to increase credibility. Its intrusion chains have been characterized by the use of password-protected archives, decoy documents, staged payload delivery, and delayed execution to reduce detection and hinder automated analysis. Rather than depending primarily on bespoke malware, the actor frequently abuses legitimate third-party software and living-off-the-land techniques. Observed tooling includes remote administration software for unattended access, command-line mail utilities for exfiltration, archive tools for packaging stolen data or configuration material, and utilities that minimize or hide application windows to reduce user awareness. A recurring pattern in Rare Werewolf operations is the deployment and silent configuration of legitimate remote access software to establish covert persistence. The actor has been observed setting unattended-access credentials, launching remote access components in the background, and creating scheduled tasks disguised as benign update activity so access is re-established at user logon. Cleanup actions such as deleting scripts, archives, logs, and decoy files after installation are also consistent with its tradecraft and complicate forensic reconstruction. The group’s operational style emphasizes stealth, persistence, and the abuse of trusted software over overtly malicious implants. Reporting also links Rare Werewolf to the use of living-off-the-land and off-the-shelf malware in campaigns against Russian entities. Some related activity attributed to the actor has involved cryptomining, including XMRig deployment after persistence is established, although not every observed intrusion includes mining behavior. Overall, Rare Werewolf is best characterized as a regionally focused threat actor that blends spear-phishing, legitimate remote administration tools, scheduled-task persistence, artifact cleanup, and selective follow-on payload use to maintain long-term access to targeted organizations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
35 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a targeted spear-phishing campaign using a fake aerospace-related business invoice delivered via a spoofed domain to deploy malware that configures AnyDesk for unattended remote access and persistence, while abusing living-off-the-land tools such as AnyDesk, Blat, WinRAR, and Tray Minimizer to maintain long-term access and reduce visibility.
Espionage-oriented phishing campaign using invoice lures to deploy and configure AnyDesk for unattended remote access, establish scheduled-task persistence, exfiltrate configuration data, and delete artifacts to maintain long-term covert access.
Uses legitimate remote access software during intrusions, specifically AnyDesk.
Targets Russian and CIS entities; emphasizes living-off-the-land/legitimate third-party tools over custom malware development.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.