Russian government agencies and industrial entities are the focus of an ongoing cyberattack campaign dubbed Awaken Likho, according to a recent report by Kaspersky.
The attackers have shifted their tactics, now using the agent for the legitimate MeshCentral platform instead of the previously employed UltraVNC module to gain remote access to systems. This new campaign, which started in June 2024, continued through at least August, primarily targeting Russian government agencies, their contractors, and industrial enterprises.
Awaken Likho, also known as Core Werewolf or PseudoGamaredon, was first uncovered by BI.ZONE in June 2023. It had been tied to cyberattacks on defense and critical infrastructure sectors. The group has reportedly been active since at least August 2021.
One of the group's main methods of attack is spear-phishing, using malicious executables disguised as Microsoft Word or PDF documents. These files are often given deceptive double extensions like "doc.exe," ".docx.exe," or ".pdf.exe" so that users only see the familiar parts of the extension. When the files are opened, the attack triggers the installation of UltraVNC, granting attackers full control over the infected system.
Earlier attacks by Core Werewolf have also targeted a Russian military base in Armenia and a Russian research institute involved in weapons development, according to findings from F.A.C.C.T. earlier this May.
One notable change in the group’s recent campaigns is the use of self-extracting archives (SFX) to covertly install UltraVNC. These archives also display decoy documents to keep targets unsuspecting.
Kaspersky's latest findings reveal a new attack chain that utilizes an SFX archive created with 7-Zip. When opened, this archive executes a file named "MicrosoftStores.exe," which unpacks an AutoIt script. This script ultimately runs the MeshAgent, an open-source remote management tool.
The attackers then persist in the compromised system by creating a scheduled task that executes a command file. This file, in turn, launches the MeshAgent, establishing a connection with the MeshCentral server, thereby allowing continued remote access and control.