Hackers Use VNIIR-Themed Phishing Email to Install AnyDesk for Persistent Remote Access

Categories:

Threat actors are leveraging a sophisticated spear-phishing campaign to establish covert, long-term access within Russian aerospace and aviation networks.

Discovered by the Seqrite Threat Research Team, this operation uses a fake invoice from a prominent research institute to trick victims into installing legitimate remote access software.

Evidence strongly suggests this activity belongs to the Rare Werewolf threat group, also known as Librarian Ghouls. Instead of using custom malware, the attackers rely on a living-off-the-land strategy to remain undetected.

Their ultimate goal is to quietly deploy AnyDesk for persistent remote control of the compromised systems.

VNIIR Phishing Installs AnyDesk

The attack begins with a spear-phishing email that impersonates the Federal Budgetary Institution “VNIIR.”

Attackers registered a disposable lookalike domain rather than using the institute’s established government domain. The emails contain a subject line referencing a payment invoice or supply contract.

Infection Chain (Source: seqrite)
Infection Chain (Source: seqrite)

To distribute the lure widely, the operators hide the recipient list using an undisclosed recipients field, indicating a mass-mailing approach.

The email also features the official logo of the Russian Ministry of Industry and Trade to appear more credible to the target.

To bypass security scanners, the attackers attach a password-protected RAR archive to the email. They place the required password directly in the message body, ensuring the victim can open it.

At the same time, automated email gateways cannot inspect the contents. Once the victim extracts the archive, they launch an executable file built with Smart Install Maker.

This dropper opens a decoy PDF document to lower the victim’s suspicion while silently creating multiple temporary files in the background.

Phishing email with password-protected archive (Source: seqrite)
Phishing email with password-protected archive (Source: seqrite)

The dropper uses command-line techniques to create temporary text files and rename them into batch command scripts. One of these scripts reaches out to an attacker-controlled server to download a secondary malicious RAR file.

A subsequent command extracts this new archive, revealing a toolkit composed entirely of legitimate utilities. The attackers intentionally avoid traditional malware, opting instead for tools that blend easily into normal network traffic and bypass basic antivirus checks.

MITRE ATT&CK Mapping 

Tactic Technique Name Technique ID 
Initial Access Phishing: Spearphishing Attachment T1566.001 
Execution User Execution: Malicious File T1204.002 

After the delay, the script configures AnyDesk for unattended access by supplying a hardcoded password, Seqrite said.

By stealing the AnyDesk configuration data, the operators can connect to the compromised host at any time. The combination of unattended access, hidden windows, and scheduled tasks grants them complete, stealthy control over the environment.

This operational tradecraft aligns perfectly with previous Rare Werewolf campaigns. Ultimately, the attackers achieve their objectives using trusted software, making detection and removal significantly more challenging for network defenders.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories