Intezer Uncovers Sophisticated AI-Powered Malware Campaign
Israeli cybersecurity firm Intezer uncovered a sophisticated AI-powered cyber-espionage campaign by Paper Werewolf, deploying EchoGather malware via malicious.
Jerusalem, 31 December, 2025 (TPS-IL) — Israeli cybersecurity firm Intezer has uncovered a sophisticated AI-powered cyber-espionage campaign targeting organizations worldwide. The operation, linked to the group Paper Werewolf (also known as GOFFEE), deployed malicious Excel add-ins (XLL files) to install a custom backdoor called EchoGather, capable of stealing files and executing commands.
Attackers also used AI-generated Russian-language decoy documents to trick recipients into enabling the malware. Unlike traditional Office exploits, this method bypasses standard security controls, raising concerns about AI’s role in enhancing social engineering. Intezer stressed the need for advanced forensic analysis to detect low-signal threats often missed by conventional security systems.























