Librarian Ghouls
Librarian Ghouls is an APT group also known as Rare Werewolf and Rezet. The group targets organizations and users in Russia, the CIS, and Central Asia, with reporting specifically noting Russia, Belarus, and Kazakhstan. Researchers observed hundreds of Russian victims, especially industrial enterprises and engineering schools, and reporting also cites theft of technical know-how such as 3D or physical models and CAD/CAM designs. The group primarily uses targeted spear-phishing emails containing password-protected archives with executable files, often disguised as messages from legitimate organizations with official-looking document attachments. Rather than relying mainly on custom malware, Librarian Ghouls heavily abuses legitimate third-party tools and scripts. Reported tools and utilities include AnyDesk for remote access, Blat for SMTP exfiltration, Defender Control to disable Windows Defender, 4t Tray Minimizer to hide activity, XMRig for cryptocurrency mining, and in some cases Mipko Personal Monitor, WebBrowserPassView, ngrok, and NirCmd. In the described intrusion chain, a self-extracting installer created with Smart Install Maker deploys components into directories such as C:\Intel and C:\Intel\AnyDesk, including a decoy PDF, curl.exe, and a malicious shortcut. A script then contacts attacker infrastructure including downdown[.]ru to download additional files, including a customized WinRAR console build used for archiving stolen data, Blat, AnyDesk, PowerShell scripts, and Defender Control. The attackers configure unattended AnyDesk access, with reporting noting a hardcoded password of QWERTY1234566 in one script, disable Windows Defender, and alter power settings. A notable operational pattern is the use of scheduled tasks to wake infected systems at 1:00 AM and shut them down at 5:00 AM, creating a four-hour window for unauthorized remote access. Reporting describes tasks named WakeUpAndLaunchEdge and ShutdownAt5AM. The group steals credentials, cryptocurrency wallet data, seed phrases, and registry dumps including HKLM\SAM and HKLM\SYSTEM, packages stolen data into password-protected archives, and exfiltrates it via SMTP using Blat. The attackers also install a miner package from bmapps[.]org that includes XMRig. Associated infrastructure and phishing activity mentioned in the reporting includes command-and-control domains downdown[.]ru and dragonfires[.]ru, both resolving to 185.125.51[.]5, as well as phishing domains users-mail[.]ru and deauthorization[.]online designed to harvest mail.ru credentials. Reporting states the group remained active through May 2025 and continuously updated its scripts and bundled utilities.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Capital Goods
Tradecraft
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Observables
59 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Targeted espionage in Russia/Central Asia via spear-phishing password-protected archives, using legitimate remote/admin tools for access and exfiltration, plus opportunistic cryptomining.
Criminal group targeting Russian and former Soviet-state companies; steals credentials and crypto-wallet data, then deploys crypto miners; uses time-based execution to exfiltrate at night.
Referenced as an example of attackers stealing industrial technical know-how, including 3D/physical models and CAD/CAM designs.
Active APT campaign targeting primarily Russian organizations, using phishing emails with password-protected archives, legitimate third-party tools, PowerShell and batch scripts for remote access, credential theft, data exfiltration, phishing-based email credential harvesting, and deployment of an XMRig crypto miner.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.