HellHounds

First seen
2019-01-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
team
Actor type
nation-state
Profile updated
2026-07-07 12:16:14

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:ru

Context

Hellhounds is an APT group targeting organizations in Russia, using a modified version of Pupy RAT called Decoy Dog. They gain initial access through vulnerable web services and trusted relationships, with a focus on the public sector and IT companies. The group has been active since at least 2019, maintaining covert presence inside compromised organizations by modifying open-source projects to evade detection. Hellhounds have successfully targeted at least 48 victims, including a telecom operator where they disrupted services.

Reports & references

  • ptsecurity.com — Hellhounds Operation Lahat Part 2 (report)
  • ics-cert.kaspersky.com — Apt And Financial Attacks On Industrial Organizations In H2 2023 (report)

External references