A previously unreported cyber espionage campaign has been uncovered targeting Russian military personnel and defense industry organizations. The campaign, attributed to the group known as Goffee, utilized phishing lures such as fake New Year concert invitations and forged official letters to entice victims into opening malicious XLL files. Once executed, these files deployed a new backdoor named EchoGather, which enabled attackers to collect system information, execute commands, and exfiltrate files to a command-and-control server disguised as a food delivery website. The phishing documents showed signs of artificial generation, including linguistic errors and poorly imitated Russian emblems, suggesting the use of AI-generated decoys to enhance stealth and evade detection.
Researchers from Intezer first identified the malicious XLL file on VirusTotal, with uploads originating from both Ukraine and Russia. The campaign demonstrates the evolving tactics of the Goffee group, which has been active since at least 2022, as they experiment with new methods to bypass security controls. The use of AI-generated content and XLL-based payloads highlights a growing trend in cyber espionage operations, particularly those targeting sensitive sectors such as defense. The full extent of the campaign's success and the specific data sought by the attackers remain unclear, but the operation underscores the persistent threat posed by sophisticated, state-aligned cyber actors.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
Follow-up reporting described the EchoGather campaign as using AI-generated decoy documents and XLL-based stealth techniques to improve lure credibility and evade detection. This added technical detail expanded public understanding of the same espionage operation.
By late December 2025, researchers reported a new Goffee campaign aimed at Russian military personnel and defense-industry organizations. The operation used fake New Year concert invitations and forged letters from Russian officials to deliver a malicious XLL file that installs the EchoGather backdoor.
The cyberespionage group Goffee, also known as Paper Werewolf, has been active since at least 2022. Earlier activity included custom malware use and exploitation of WinRAR vulnerabilities against Russian targets.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.