HellHounds is an APT group targeting Russian public sector and IT companies using Decoy Dog RAT.
Analyst brief
HellHounds is an APT group targeting the public sector and IT companies in Russia. They gain initial access via vulnerable web services and trusted relationships, deploying a modified Pupy RAT called Decoy Dog for persistence and control. Active since at least 2019, the group maintains a covert presence by altering open-source projects to evade detection. Defenders should focus on anomalous DNS queries, unusual domain connections, and Decoy Dog's C2 beaconing patterns.
HellHounds
unknown
Hellhounds is an APT group targeting organizations in Russia, using a modified version of Pupy RAT called Decoy Dog. They gain initial access through vulnerable web services and trusted relationships, with a focus on the public sector and IT companies. The group has been active since at least 2019, maintaining covert presence inside compromised organizations by modifying open-source projects to evade detection. Hellhounds have successfully targeted at least 48 victims, including a telecom operator where they disrupted services.