Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
1 malware family

Librarian Ghouls

Also known aslibrarian_ghouls

Librarian Ghouls is an APT group also known as Rare Werewolf and Rezet. The group targets organizations and users in Russia, the CIS, and Central Asia, with reporting specifically noting Russia, Belarus, and Kazakhstan. Researchers observed hundreds of Russian victims, especially industrial enterprises and engineering schools, and reporting also cites theft of technical know-how such as 3D or physical models and CAD/CAM designs. The group primarily uses targeted spear-phishing emails containing password-protected archives with executable files, often disguised as messages from legitimate organizations with official-looking document attachments. Rather than relying mainly on custom malware, Librarian Ghouls heavily abuses legitimate third-party tools and scripts. Reported tools and utilities include AnyDesk for remote access, Blat for SMTP exfiltration, Defender Control to disable Windows Defender, 4t Tray Minimizer to hide activity, XMRig for cryptocurrency mining, and in some cases Mipko Personal Monitor, WebBrowserPassView, ngrok, and NirCmd. In the described intrusion chain, a self-extracting installer created with Smart Install Maker deploys components into directories such as C:\Intel and C:\Intel\AnyDesk, including a decoy PDF, curl.exe, and a malicious shortcut. A script then contacts attacker infrastructure including downdown[.]ru to download additional files, including a customized WinRAR console build used for archiving stolen data, Blat, AnyDesk, PowerShell scripts, and Defender Control. The attackers configure unattended AnyDesk access, with reporting noting a hardcoded password of QWERTY1234566 in one script, disable Windows Defender, and alter power settings. A notable operational pattern is the use of scheduled tasks to wake infected systems at 1:00 AM and shut them down at 5:00 AM, creating a four-hour window for unauthorized remote access. Reporting describes tasks named WakeUpAndLaunchEdge and ShutdownAt5AM. The group steals credentials, cryptocurrency wallet data, seed phrases, and registry dumps including HKLM\SAM and HKLM\SYSTEM, packages stolen data into password-protected archives, and exfiltrates it via SMTP using Blat. The attackers also install a miner package from bmapps[.]org that includes XMRig. Associated infrastructure and phishing activity mentioned in the reporting includes command-and-control domains downdown[.]ru and dragonfires[.]ru, both resolving to 185.125.51[.]5, as well as phishing domains users-mail[.]ru and deauthorization[.]online designed to harvest mail.ru credentials. Reporting states the group remained active through May 2025 and continuously updated its scripts and bundled utilities.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Capital Goods
MITRE ATT&CK

Tradecraft

24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

12 of 15 tactics38 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
3 techniques
T1583
Acquire Infrastructure
T1584
Compromise Infrastructure
T1584.004
Server
T1588
Obtain Capabilities
T1588.002
Tool
TA0001
Initial Access
1 technique
T1566
Phishing
T1566.001
Spearphishing Attachment
TA0002
Execution
2 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1059
Command and Scripting Interpreter
T1059.001
PowerShell
T1059.003
Windows Command Shell
TA0003
Persistence
3 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1112
Modify Registry
T1547
Boot or Logon Autostart Execution
TA0004
Privilege Escalation
2 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1547
Boot or Logon Autostart Execution
TA0005
Stealth
1 technique
T1070
Indicator Removal
T1070.004
File Deletion
TA0112
Defense Impairment
1 technique
T1112
Modify Registry
TA0006
Credential Access
4 techniques
T1003
OS Credential Dumping
T1056
Input Capture
T1056.001
Keylogging
T1555
Credentials from Password Stores
T1649
Steal or Forge Authentication Certificates
TA0009
Collection
4 techniques
T1005
Data from Local System
T1056
Input Capture
T1056.001
Keylogging
T1113
Screen Capture
T1560
Archive Collected Data
T1560.001
Archive via Utility
TA0011
Command and Control
2 techniques
T1105
Ingress Tool Transfer
T1219
Remote Access Tools
TA0010
Exfiltration
2 techniques
T1048
Exfiltration Over Alternative Protocol
T1537
Transfer Data to Cloud Account
TA0040
Impact
1 technique
T1496
Resource Hijacking
ARSENAL

Associated malware families

1 malware family attributed to this actor across reporting.

IOCS

Observables

59 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping24

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables59

Domains, IPs, and hashes tied to this actor, refreshed continuously.