Squid Werewolf cyber spies masquerade as recruiters


Espionage activity clusters may pose as recruiters to distribute phishing emails, targeting key employees in organizations of interest. In December 2024, the BI.ZONE Threat Intelligence team uncovered a peculiar phishing campaign aimed at luring victims with fake job opportunities at an industrial organization.

A detailed analysis revealed that the attack had been carried out by Squid Werewolf (APT37, Ricochet Chollima, ScarCruft, Reaper Group). The attack would begin with a phishing email, which the adversaries disguised as a job offer from a United Industrial Complex HR representative. The attachment comprised a password‑protected file Предложение о работе.zip, with the password provided in the email. The ZIP archive included an LNK file Предложение о работе.pdf.lnk which, once opened, executed the following command:

Read more…
Source: BI.ZONE Threat Intelligence


Sign up for our Newsletter


Related:

  • Over 100,000 UK Police and staff have personal data leaked in attack on national database

    August 4, 2026

    The UK’s Police National Legal Database (PNLD) suffered a cyberattack recently, in which it allegedly lost sensitive data on more than 100,000 criminal justice professionals. In a short press release, PNLD confirmed the breach, saying it happened over a weekend. The threat actors, which were not named in the announcement, were said to have taken names, organizations, and ...

  • Feds get 3 days to patch N-able God mode flaw under active exploit

    August 4, 2026

    The US Cybersecurity and Infrastructure Security Agency (CISA) has added an exploited N-able vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, giving federal agencies three days to patch a flaw that could let attackers reach managed service provider (MSP) customers. Attackers exploiting the flaw can gain “full administrative access to an N-central console,” Tracked as CVE-2026-18577 (8.2 ...

  • Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

    August 3, 2026

    This article analyzes new attack classes against passwordless authentication, focusing on Google’s synced passkey ecosystem and the Cloud Authenticator used by desktop clients. The attacks demonstrate how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to take over passkey-protected accounts. Palo Alto Unit 42 shows how an attacker can authenticate ...

  • INTERPOL report finds AI linked to more than half of cybercrime in Africa

    August 3, 2026

    Artificial intelligence is enabling 55 per cent of reported cybercrimes across Africa making attacks faster, more scalable, and increasingly difficult for victims and platforms to detect, according to INTERPOL’s African Cyberthreat Assessment Report 2026. With more than 1.1 billion mobile subscribers recorded in 2025, Africa’s digital transformation is expanding rapidly. However, cybercrime legislation is fragmented and AI readiness ...

  • Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

    July 31, 2026

    Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, conducting widespread but targeted traffic manipulation attacks involving hospitality sector networks served by captive portals worldwide. Despite some tactic, technique, and procedure (TTP) similarities to the Forest Blizzard DNS hijacking operation that we publicly disclosed in April 2026, we attribute this campaign, ...

  • Network Anomaly Detection in KATA

    July 31, 2026

    Once the attacker has breached the corporate network, subsequent stages of the attack often involve leveraging standard domain infrastructure protocols: using Kerberos, running DNS queries, accessing internal services, opening network shares, and other common networking actions. Because this activity is virtually indistinguishable from legitimate network traffic, it is extremely difficult to detect it with traditional ...