HellHounds
- First seen
- 2019-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- team
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:16:14
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:ru
Context
Hellhounds is an APT group targeting organizations in Russia, using a modified version of Pupy RAT called Decoy Dog. They gain initial access through vulnerable web services and trusted relationships, with a focus on the public sector and IT companies. The group has been active since at least 2019, maintaining covert presence inside compromised organizations by modifying open-source projects to evade detection. Hellhounds have successfully targeted at least 48 victims, including a telecom operator where they disrupted services.
Reports & references
- ptsecurity.com — Hellhounds Operation Lahat Part 2 (report)
- ics-cert.kaspersky.com — Apt And Financial Attacks On Industrial Organizations In H2 2023 (report)