Squid Werewolf cyber spies masquerade as recruiters
2025-03-12 • Bi Zone •
BI.ZONE attributes a December 2024 recruiter-themed phishing campaign against an industrial organization to Squid Werewolf, also known as APT37, Ricochet Chollima, ScarCruft, and Reaper. The lure used a password-protected job-offer ZIP containing an LNK file that extracted embedded Base64 data, copied dfsvc.exe into the Startup folder as d.exe, wrote a .NET configuration file and DomainManager.dll, and opened a decoy PDF. The DomainManager loader used AppDomainManager side loading, obfuscation, a 10-minute anti-sandbox delay, timeapi.io connectivity checks, and AES-encrypted payload handling through DomainManager.conf or Hostwinds-hosted C2 paths. The campaign shows APT37 moving from document-heavy lures toward archive, shortcut, and executable chains for espionage access.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 20dd93441c5e78b7adc7764c92719be… | 2025-03-12 | 2025-03-12 |
| HASH | 0601426a6da40ec9b47bab54e4ec149… | 2025-03-12 | 2025-03-12 |
| HASH | 49a2ed08930ed20cbf859ca2fe3113e… | 2025-03-12 | 2025-03-12 |
| URL | https://www.timeapi.io/api/time… | 2025-03-12 | 2025-03-12 |
| URL | https://hwsrv-1253398.hostwinds… | 2025-03-12 | 2025-03-12 |
| URL | https://hwsrv-1253398.hostwinds… | 2025-03-12 | 2025-03-12 |
| DOMAIN | hwsrv-1253398.hostwindsdns.com | 2025-03-12 | 2025-03-12 |