Architectural Concept Design Collection

  • CONTACT
  • MARKETCAP
  • BLOG
Finances Investing and Crypto News
  • BOOKMARKS
  • Finance
  • Investment
  • Crypto
    • Bitcoin
    • Blockchain
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
  • News
    • Mining
    • NFT
    • Stocks
Reading: Hacker group Rare Werewolf hijacks Russian devices to mine crypto and steal data
Share
  • bitcoinBitcoin(BTC)$107,356.44
  • ethereumEthereum(ETH)$2,445.59
  • tetherTether USDt(USDT)$1.00
  • rippleXRP(XRP)$2.09
  • binancecoinBNB(BNB)$645.69
  • solanaSolana(SOL)$141.45
  • usd-coinUSDC(USDC)$1.00
  • tronTRON(TRX)$0.271263
  • dogecoinDogecoin(DOGE)$0.161507
  • cardanoCardano(ADA)$0.56
Finances Investing and Crypto NewsFinances Investing and Crypto News
0
Font ResizerAa
  • Finance
  • Investment
  • Crypto
  • Market
  • News
Search
  • Finance
  • Investment
  • Crypto
    • Bitcoin
    • Blockchain
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
  • News
    • Mining
    • NFT
    • Stocks
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
Finances Investing and Crypto News > Blog > Crypto > Hacker group Rare Werewolf hijacks Russian devices to mine crypto and steal data
Crypto

Hacker group Rare Werewolf hijacks Russian devices to mine crypto and steal data

admin
Last updated: 11/06/2025 5:51 Chiều
admin
Published 11/06/2025
Share


A cybercriminal group known as Rare Werewolf is running a targeted phishing campaign against Russian and CIS-based companies, hijacking devices to mine crypto and steal sensitive data.

Kaspersky’s research revealed that the APT group Rare Werewolf, also known as “Librarian Ghouls” and “Rezet,” has remained consistently active through May, carrying out a relentless campaign that targets organizations across Russia and the CIS.

The group uses phishing emails disguised as communications from legitimate organizations to deceive victims into opening malicious attachments. Once these files are executed, the attackers gain remote access to the device, exfiltrate sensitive data (such as credentials and crypto wallet info), and then deploy Monero (XMR) crypto miners to exploit the system’s processing power.” To avoid detection, they schedule the compromised machine to automatically wake up at 1 AM and shut down at 5 AM, ensuring their activities go unnoticed.

Kaspersky reports that the group mainly targets industrial enterprises, with engineering schools also being of particular interest. The phishing emails are written in Russian and typically contain attachments with Russian-language filenames and decoy documents, which suggests that the group’s primary victims are based in Russia or are Russian speakers.

Hacker group Rare Werewolf hijacks Russian devices to mine crypto and steal data - 1
Source: PDF document imitating a payment order | securelist.com

Kaspersky’s investigation also uncovered several domains that might be linked to the Librarian Ghouls campaign, although they have low confidence in this connection. Among the domains still active at the time were users-mail[.]ru and deauthorization[.]online, both of which hosted phishing pages. These pages, created with PHP scripts, were designed to steal login credentials for the popular Russian e-mail service Mail.ru.

Hacker group Rare Werewolf hijacks Russian devices to mine crypto and steal data - 2
Source: Example of a phishing page associated with the APT campaign | securelist.com

As of the release of Kaspersky’s research, the Librarian Ghouls APT campaign remains active, with ongoing attacks observed as recently as last month.

You Might Also Like

Strike hits $10m in BTC-backed loans two days after launch

+ 4.47%, bullish structure builds pressure toward $4,060 breakout

Polyhedra’s ZKJ token plunges 83% after liquidity crisis

Solana price target: Expert predicts $180–$200 breakout

Soneium partners with Square Enix’s SYMBIOGENESIS to provide cross-game NFT rewards

TAGGED:cryptodatadevicesgrouphackerhijacksrareRussianstealWerewolf

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Andrew Tate linked wallet down $600k, influencer promises to ‘make it all back’
Next Article PancakeSwap launches instant cross-chain swaps on Across
Leave a Comment

Để lại một bình luận Hủy

Email của bạn sẽ không được hiển thị công khai. Các trường bắt buộc được đánh dấu *

Follow US

Find US on Socials
FacebookLike
- Advertisement -
Ad image
Popular News
Three reasons why Wormhole could be gearing up for a major rally
Emergency Funds: Importance and How to Build One
Debt Management: Strategies to Pay Off Debt Efficiently
Riot Platforms unloads 475 BTC in its biggest single-month Bitcoin sale to date
Revolut partners with Lightspark to add Bitcoin Lightning for UK and EEA users
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Finances Investing and Crypto News

FICN.net brings you the latest in finance, investment, and crypto. Stay informed with expert insights, market analysis, and beginner guides. Whether you're new or experienced, FICN.net helps you explore opportunities, manage risks, and make smarter financial decisions in a fast-changing world.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

Ad image
© 2024 Finance, Investment, and Crypto News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?