Librarian Ghouls is an active threat group also tracked as Rare Werewolf and Rezet. The group has targeted organizations in Russia, the CIS, Belarus, and Kazakhstan, with particularly strong victim concentration in Russia. Observed targeting has included industrial enterprises and engineering schools, and the group has been associated with theft of technical know-how, including engineering documentation and CAD/CAM-related materials. The group primarily relies on spear-phishing for initial access, commonly using password-protected archives and executable lures disguised as legitimate correspondence. Rather than depending mainly on bespoke malware families, Librarian Ghouls is notable for extensive abuse of legitimate third-party software and native scripting, especially command files and PowerShell. Reported tool use includes remote administration software, SMTP mail utilities, security-control-disabling tools, credential-recovery utilities, tunneling tools, monitoring software, and cryptocurrency mining software. Post-compromise activity has included establishing unattended remote access, disabling Microsoft Defender, modifying power settings, and creating scheduled tasks to wake compromised systems during overnight hours and shut them down afterward, creating a predictable window for operator access. The group has also used utilities to minimize visible applications and obscure attacker activity on infected hosts. Collection and theft behavior includes harvesting credentials, cryptocurrency wallet data, seed phrases, and system data, then packaging stolen material into archives and exfiltrating it via SMTP. Reporting also links the group to phishing infrastructure designed to harvest webmail credentials. In addition to espionage-oriented theft, Librarian Ghouls has deployed XMRig cryptocurrency mining software on victim systems, indicating a secondary monetization component alongside information theft. The group’s tradecraft emphasizes living-off-the-land and dual-use tooling, remote access persistence, credential theft, defense evasion, and data exfiltration. Activity attributed to Librarian Ghouls continued through at least May 2025.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
72 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Targeted espionage in Russia/Central Asia via spear-phishing password-protected archives, using legitimate remote/admin tools for access and exfiltration, plus opportunistic cryptomining.
Criminal group targeting Russian and former Soviet-state companies; steals credentials and crypto-wallet data, then deploys crypto miners; uses time-based execution to exfiltrate at night.
Referenced as an example of attackers stealing industrial technical know-how, including 3D/physical models and CAD/CAM designs.
Active APT campaign targeting primarily Russian organizations, using phishing emails with password-protected archives, legitimate third-party tools, PowerShell and batch scripts for remote access, credential theft, data exfiltration, phishing-based email credential harvesting, and deployment of an XMRig crypto miner.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.