Threat Advisory

Fluffy Wolf Spreads Meta Stealer in Corporate Phishing Campaign

Threat: Phishing Campaign
Criticality: High
[subscribe_to_unlock_form]
 

 SUMMARY:[/subscribe_to_unlock_form]

 

 SUMMARY:[emaillocker id="1283"]

The Researchers has uncovered a novel threat cluster, aptly named Fluffy Wolf, who is active from last year. This group employs sophisticated phishing tactics, utilizing password-protected archive attachments masquerading as reconciliation reports in emails. These attachments contain executable files that deploy a range of malicious tools, including Remote Utilities, Meta Stealer, Warzone RAT, and XMRig miner. Notably, phishing remains a prevalent intrusion method, with approximately 5% of corporate employees falling victim to downloading and opening hostile attachments. Moreover, threat actors are continuously innovating, incorporating legitimate remote access software into their arsenal to enhance their capabilities.

Upon execution, the malicious file replicates itself in specific directories and creates registry keys for persistence, enabling it to operate stealthily on compromised systems. The Remote Utilities installer, masked within the legitimate NSIS framework, facilitates complete control over compromised devices, allowing threat actors to monitor user activities, transmit files, and execute commands. Simultaneously, Meta Stealer, a derivative of the notorious RedLine stealer, exfiltrates critical system information, including user credentials, system specifications, installed software, and security solutions. This combination of tools enables threat actors to conduct comprehensive reconnaissance and exfiltration of sensitive data, including cryptocurrency wallet information and VPN credentials, further amplifying the severity of the breach.

The Fluffy Wolf cluster exemplifies the evolving landscape of cyber threats, showcasing the efficacy of relatively simple tools in achieving complex objectives. Despite the sophistication of modern cyber defenses, threat actors continue to adapt and innovate, underscoring the critical role of threat intelligence in early detection and mitigation of malicious activity. By leveraging the latest data and insights, organizations can proactively defend against emerging threats and safeguard their digital assets against potential compromise.

Threat Profile:

References:

The following reports contain further technical details:
https://www.darkreading.com/threat-intelligence/fluffy-wolf-spreads-meta-stealer-in-corporate-phishing-campaign

 

[/emaillocker]
crossmenu