The Awaken Likho APT group, also known as Core Werewolf and PseudoGamaredon, has targeted Russian government agencies and industrial entities.
Kaspersky researchers discovered a new campaign by Awaken Likho from June to August 2024, in which they shifted from UltraVNC to MeshCentral for remote access.
The group utilized a new implant delivered through phishing emails, transitioning from UltraVNC to MeshAgent.
Awaken Likho has been active since the Russo-Ukrainian conflict, continuously refining their techniques and showing ongoing development in their latest malware version.