Rare Werewolf, also known as Librarian Ghouls and formerly Rare Wolf, is a threat actor associated with targeted intrusion activity against organizations in Russia, Belarus, and Kazakhstan. Its victims have included industrial, engineering, aerospace, and aviation organizations, including Russian aerospace entities. The group has used spear-phishing lures themed as business correspondence or invoices, including Russian-language impersonation content, to deliver password-protected archives and malicious installers. Rare Werewolf favors legitimate and dual-use software over conspicuous custom malware. Observed operations have deployed portable AnyDesk configured for unattended remote access, WinRAR or other archive utilities, 4t Tray Minimizer to conceal application windows, and Blat or similar command-line SMTP tooling. The actor establishes persistence with Windows Task Scheduler, including logon-triggered tasks designed to restore concealed remote-access capability. It has collected and exfiltrated remote-access configuration material in password-protected archives through email-based channels, and has deleted scripts, logs, archives, executables, and decoy documents after installation to reduce forensic visibility. The group’s tradecraft demonstrates initial access through phishing, persistence, defense evasion, and data exfiltration. Some activity attributed to Rare Werewolf has also been associated with cryptomining, although mining was not observed in the documented aerospace-focused campaigns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
68 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducts phishing-led intrusions using malicious archive attachments and legitimate tools to extract payloads, conceal application windows, establish remote access and persistence, collect and exfiltrate data.
Using unattended AnyDesk deployment for access and exfiltrating configuration data.
Conducting a targeted spear-phishing campaign using a fake aerospace-related business invoice delivered via a spoofed domain to deploy malware that configures AnyDesk for unattended remote access and persistence, while abusing living-off-the-land tools such as AnyDesk, Blat, WinRAR, and Tray Minimizer to maintain long-term access and reduce visibility.
Espionage-oriented phishing campaign using invoice lures to deploy and configure AnyDesk for unattended remote access, establish scheduled-task persistence, exfiltrate configuration data, and delete artifacts to maintain long-term covert access.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.