Rare Werewolf, also known as Librarian Ghouls and formerly Rare Wolf, is a threat actor associated with targeted intrusions against organizations in Russia, Belarus, and Kazakhstan. Reported targeting has included industrial, engineering, aerospace, and aviation entities, with observed campaigns specifically focusing on Russian aerospace organizations. The actor appears to prioritize stealthy, long-term access and operational concealment, relying heavily on legitimate third-party software, living-off-the-land techniques, and off-the-shelf utilities rather than conspicuous custom malware. Observed intrusion chains have used spear-phishing with invoice-themed lures and spoofed sender infrastructure to gain initial access. In documented campaigns, the actor delivered password-protected archives and decoy documents, then installed and silently configured remote administration software for unattended access. Rare Werewolf has used scheduled tasks for persistence, hidden remote-access sessions from users, packaged configuration material for collection, and exfiltrated data through legitimate mail utilities. Cleanup routines have deleted scripts, logs, archives, and other artifacts to reduce forensic visibility. The actor’s tradecraft is characterized by abuse of legitimate remote-access and administrative tools, persistence through scheduled execution, exfiltration of victim configuration data, and defense evasion through artifact deletion and reduced on-screen visibility. Related reporting notes that some campaigns attributed to the same actor have involved cryptomining after persistence was established, although such activity was not observed in every intrusion. Based on the documented victimology and emphasis on sustained covert access, Rare Werewolf is best characterized as an espionage-oriented threat actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
35 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Using unattended AnyDesk deployment for access and exfiltrating configuration data.
Conducting a targeted spear-phishing campaign using a fake aerospace-related business invoice delivered via a spoofed domain to deploy malware that configures AnyDesk for unattended remote access and persistence, while abusing living-off-the-land tools such as AnyDesk, Blat, WinRAR, and Tray Minimizer to maintain long-term access and reduce visibility.
Espionage-oriented phishing campaign using invoice lures to deploy and configure AnyDesk for unattended remote access, establish scheduled-task persistence, exfiltrate configuration data, and delete artifacts to maintain long-term covert access.
Uses legitimate remote access software during intrusions, specifically AnyDesk.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.