{"id":535,"date":"2025-02-28T11:03:53","date_gmt":"2025-02-28T11:03:53","guid":{"rendered":"https:\/\/familiebuckens.nl\/?p=535"},"modified":"2025-02-28T11:03:53","modified_gmt":"2025-02-28T11:03:53","slug":"sticky-werewolf-uses-undocumented-implant-to-deploy-lumma-stealer-in-russia-and-belarus","status":"publish","type":"post","link":"https:\/\/familiebuckens.nl\/index.php\/2025\/02\/28\/sticky-werewolf-uses-undocumented-implant-to-deploy-lumma-stealer-in-russia-and-belarus\/","title":{"rendered":"Sticky Werewolf Uses Undocumented Implant to Deploy Lumma Stealer in Russia and Belarus"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The threat actor known as&nbsp;<strong>Sticky Werewolf<\/strong>&nbsp;has been linked to targeted attacks primarily in Russia and Belarus with the aim of delivering the Lumma Stealer malware by means of a previously undocumented implant.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cybersecurity company Kaspersky is tracking the activity under the name Angry Likho, which it said bears a &#8220;strong resemblance&#8221; to&nbsp;<a href=\"https:\/\/thehackernews.com\/2025\/01\/gamacopy-mimics-gamaredon-tactics-in.html\" rel=\"noreferrer noopener\" target=\"_blank\">Awaken Likho<\/a>&nbsp;(aka Core Werewolf, GamaCopy, and PseudoGamaredon).<\/p>\n\n\n<a class=\"wp-block-read-more\" href=\"https:\/\/familiebuckens.nl\/index.php\/2025\/02\/28\/sticky-werewolf-uses-undocumented-implant-to-deploy-lumma-stealer-in-russia-and-belarus\/\" target=\"_self\"><a href=\"https:\/\/thehackernews.com\/2025\/02\/sticky-werewolf-uses-undocumented.html\">Sticky Werewolf Uses Undocumented Implant to Deploy Lumma Stealer in Russia and Belarus<\/a><span class=\"screen-reader-text\">: Sticky Werewolf Uses Undocumented Implant to Deploy Lumma Stealer in Russia and Belarus<\/span><\/a>\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The threat actor known as&nbsp;Sticky Werewolf&nbsp;has been linked to targeted attacks primarily in Russia and Belarus with the aim of delivering the Lumma Stealer malware by means of a previously undocumented implant. Cybersecurity company Kaspersky is tracking the activity under the name Angry Likho, which it said bears a &#8220;strong&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,17],"tags":[40,10],"class_list":["post-535","post","type-post","status-publish","format-standard","hentry","category-geopolitics","category-vulnerability","tag-40","tag-ukraine"],"_links":{"self":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/535","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/comments?post=535"}],"version-history":[{"count":1,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/535\/revisions"}],"predecessor-version":[{"id":536,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/535\/revisions\/536"}],"wp:attachment":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/media?parent=535"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/categories?post=535"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/tags?post=535"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}