According to reports from Wu, the cybersecurity company Kaspersky revealed that the hacker group Librarian Ghouls has been attacking hundreds of Russian devices since December 2024 through malicious phishing emails disguised as official documents.
The organization specifically targets industrial enterprises and engineering schools, affecting Belarus and Kazakhstan, disabling security systems through remote connections, and running cryptocurrency mining software between 1 AM and 5 AM.
They utilize the devices' RAM, CPU, and GPU to optimize mining. Kaspersky speculates they may be hacktivists, as they rely on legitimate third-party software rather than homemade malware.