Squid Werewolf cyber spies masquerade as recruiters

2025-03-12 Bi Zone

https://bi.zone/eng/expertise/blog/sotni-tysyach-rubley-za-vashi-sekrety-kibershpiony-squid-werewolf-maskiruyutsya-pod-rekruterov

Thumbnail for Squid Werewolf cyber spies masquerade as recruiters

BI.ZONE attributes a December 2024 recruiter-themed phishing campaign against an industrial organization to Squid Werewolf, also known as APT37, Ricochet Chollima, ScarCruft, and Reaper. The lure used a password-protected job-offer ZIP containing an LNK file that extracted embedded Base64 data, copied dfsvc.exe into the Startup folder as d.exe, wrote a .NET configuration file and DomainManager.dll, and opened a decoy PDF. The DomainManager loader used AppDomainManager side loading, obfuscation, a 10-minute anti-sandbox delay, timeapi.io connectivity checks, and AES-encrypted payload handling through DomainManager.conf or Hostwinds-hosted C2 paths. The campaign shows APT37 moving from document-heavy lures toward archive, shortcut, and executable chains for espionage access.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 20dd93441c5e78b7adc7764c92719be… 2025-03-12 2025-03-12
HASH 0601426a6da40ec9b47bab54e4ec149… 2025-03-12 2025-03-12
HASH 49a2ed08930ed20cbf859ca2fe3113e… 2025-03-12 2025-03-12
URL https://www.timeapi.io/api/time… 2025-03-12 2025-03-12
URL https://hwsrv-1253398.hostwinds… 2025-03-12 2025-03-12
URL https://hwsrv-1253398.hostwinds… 2025-03-12 2025-03-12
DOMAIN hwsrv-1253398.hostwindsdns.com 2025-03-12 2025-03-12

Related Actors

« Back