Russian industrial enterprises face a renewed cyber threat from the threat actor Arcane Werewolf, also known as Mythic Likho, which intensified its operations throughout October and November 2025.
According to BI.ZONE Threat Intelligence, the group continues to target Russian manufacturing companies with updated malware, now featuring the Loki 2.1 implant compatible with the Mythic and Havoc post-exploitation frameworks.
The threat actor relied on phishing campaigns to deliver malicious archives. These emails typically impersonated legitimate organizations or regulators, using company logos and document-style filenames to boost authenticity.
Once recipients clicked the malicious link, they were redirected to spoofed company domains closely resembling legitimate ones, such as npo-[redacted].ru and electropriborzavod[.]ru.
Technical Attack Chain
In October 2025, BI.ZONE tracked a campaign where phishing emails distributed ZIP archives containing LNK shortcut files and image decoys.
Opening the .pdf.lnk file triggered a cmd command that fetched a disguised executable (icon2.png) from a fake company server.
The download function invoked PowerShell, which retrieved and launched the file using conhost.exe, effectively bypassing user suspicion.
This executable, a Go-based dropper, contained two embedded Base64 payloads, a decoy PDF, and a malicious loader named chrome_proxy.pdf.
The loader served as Loki 2.0, responsible for gathering host details, including OS version, IP address, and username.
The data was AES-encrypted and Base64-encoded before being sent via HTTPS to a C2 server disguised as a document repository.
In November 2025, Arcane Werewolf shifted to using a new C++ dropper to deliver Loki 2.1. The dropper embedded its payload within the resource section and wrote it to disk as C:\Windows\Temp\csrss64.exe.
It simultaneously opened a PDF decoy related to an “internal investigation” to maintain cover. The dropper then executed the Loki 2.1 loader using native Windows API calls like CreateProcessW.
The upgraded Loki 2.1 loader not only fetched implants remotely but also carried a local embedded implant.
This version replaced the earlier djb2 hash-based command mapping with an ordinal-number mapping, simplifying execution of C2 commands such as file uploads, process injection, token manipulation, and system discovery.
Communication with its servers at CDN. electropriborzavod[.]ru was encrypted using AES and encoded in Base64.
BI.ZONE researchers attributed this campaign to Arcane Werewolf due to code similarities, domain infrastructure, and operational patterns observed in previous attacks.
Analysts emphasize that early-detection tools, such as EDR systems and threat-intelligence integration, can help industrial organizations defend against evolving threats like Loki.
Follow us on Google News , LinkedIn and X to Get More Instant Updates, Set Cyberpress as a Preferred Source in Google.