AI-Forged Ministry Invitations Opened a Cyber-Espionage Campaign Against Russian Defence Firms
What happened
In late 2025, a pro-Ukrainian cyber-espionage group known in the security community as Paper Werewolf targeted several Russian defence and technology firms using a method that had become newly practical: AI-generated documents crafted to look like official government communications. The operation was documented by threat intelligence firm Intezer, which traced the campaign through a combination of forged invitations and Excel files embedded with malicious code.
The decoy documents were designed to look like invitations and notices from the Russian Ministry of Industry and Trade, complete with the formatting and language conventions a defence-sector employee would expect to see. Employees at targeted firms were sent these materials, which appeared to invite them to professional events or convey routine government correspondence. Opening the attached files activated the second stage of the attack.
What made this campaign notable was not the technique itself. Social engineering through fake documents has a long history in corporate and state espionage. What changed was the production cost. Before widely available generative AI, producing convincing Russian-language government documents at volume required either native fluency or careful human authorship. Generative tools reduced that barrier significantly, letting attackers produce targeted, contextually credible lures far faster than hand-crafted forgeries would allow.
The outcome of the operation is genuinely unclear. Reports from Reuters in December 2025 and the Intezer analysis note that it is uncertain whether the campaign successfully extracted confidential documents from any of the targeted firms. The apparent goal was intelligence collection on Russian defence supply chains, research processes, and military industry operations, part of a broader pattern of pro-Ukrainian actors seeking informational advantage during the ongoing conflict.
That ambiguity points to a structural problem in how these campaigns get assessed. The tools used to generate the decoy documents leave limited traces of their own. Investigators can identify that AI-assisted forgery was involved, but the content side of the record, which systems were accessed, what was read or copied, by whom and when, depends entirely on what logs the targeted organisations happened to keep. Without a provable record of what a system did and who interacted with it at each step, post-incident analysis can describe a campaign's shape but cannot reliably establish its damage. That gap is not a feature of this particular operation; it is the default condition for any intrusion where AI-generated materials are the entry point and no continuous audit trail exists on either side.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.