Recon 2026

Nicole Fishbein

Nicole Fishbein is a security researcher and malware analyst. Prior to Intezer, she was an embedded researcher in the Israel Defense Forces (IDF) Intelligence Corps. Nicole has been part of research that led to the discovery of previously unseen APT malware and novel attacks on Linux-based cloud environments. Her current research focuses on the use of non-standard languages like .NET, Go, and Rust by advanced threat actors.


Session

06-20
15:00
30min
Paper Werewolf's Toolbox: Reversing XLL Delivery, EchoGather, and a WinRAR Exploit Chain Targeting Russia
Nicole Fishbein

Most threat intelligence treats Russia as a source of attacks. This talk examines Russia as a target. Paper Werewolf (aka GOFFEE) is a cyberespionage group with a sustained focus on Russian defense-industry and government organizations, and despite the group's activity level, it still flies under the radar. This talk presents a full technical teardown of a recent campaign, from the initial delivery mechanism to the implant, the exploitation chain, and the infrastructure that ties it to prior Paper Werewolf operations.

The loading mechanism is an XLL add-in, a delivery format that is not new but is rarely dissected in public research. We walk through the loader's DLL export structure, its time-delay sandbox evasion logic, and the unpacking chain leading to EchoGather, a backdoor we uncovered. We reverse EchoGather's XOR-encrypted string handling, C2 protocol, and command handler architecture. A parallel delivery chain exploits CVE-2025-8088, a WinRAR path traversal bug that abuses NTFS alternate data streams to silently drop a persistence script into the Windows Startup folder.

Beyond the binaries, the campaign has two details worth examining in their own right. The decoy documents impersonating the Russian Ministry of Industry and Trade contain clear AI-generated artifacts, offering a fingerprinting angle on how threat actors are incorporating generative AI into their operations. And to accelerate our own infrastructure analysis, we built a lightweight script on top of the Validin API using Claude Code, turning a manual correlation process into a systematic one. We will share the script, the methodology, and previously undisclosed indicators discovered after our public blog post.

Grand Salon Opera