Rare Werewolf, also known as Librarian Ghouls and formerly Rare Wolf, is a threat actor associated with targeted intrusions against organizations in Russia, Belarus, and Kazakhstan. Reported victimology centers on industrial, engineering, aerospace, and aviation-related entities, with documented campaigns specifically targeting Russian aerospace organizations. The actor is characterized by spear-phishing operations that use business-themed lures and spoofed sender infrastructure to deliver initial payloads. Its tradecraft emphasizes living-off-the-land techniques and the abuse of legitimate third-party software rather than bespoke malware. In observed campaigns, operators deployed remote administration software for unattended access, established persistence through scheduled tasks, hid malicious activity with window-minimization utilities, and used common utilities for compression and command-line email transmission. Rare Werewolf’s intrusion chains have included staged delivery through password-protected archives, decoy documents to preserve the phishing pretext, remote retrieval of additional tooling, silent configuration of remote-access software, and exfiltration of configuration material needed to maintain operator access. The actor has also been observed deleting scripts, archives, logs, and other artifacts after setup to reduce forensic visibility and complicate incident reconstruction. The group’s operational style reflects a preference for stealthy long-term access, defense evasion through legitimate tools, and post-compromise data removal or transfer rather than noisy malware deployment. Related reporting notes that some campaigns attributed to the actor have involved cryptomining after persistence is established, although that behavior was not present in every observed intrusion. Overall, Rare Werewolf is best understood as a targeted intrusion actor using phishing, persistence, remote access abuse, exfiltration, and artifact cleanup against industrial and aerospace-aligned organizations in the Russian-speaking region.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
35 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a targeted spear-phishing campaign using a fake aerospace-related business invoice delivered via a spoofed domain to deploy malware that configures AnyDesk for unattended remote access and persistence, while abusing living-off-the-land tools such as AnyDesk, Blat, WinRAR, and Tray Minimizer to maintain long-term access and reduce visibility.
Espionage-oriented phishing campaign using invoice lures to deploy and configure AnyDesk for unattended remote access, establish scheduled-task persistence, exfiltrate configuration data, and delete artifacts to maintain long-term covert access.
Uses legitimate remote access software during intrusions, specifically AnyDesk.
Targets Russian and CIS entities; emphasizes living-off-the-land/legitimate third-party tools over custom malware development.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.