216.73.217.22

Werewolf raids Russia's public sector with trusted relationship attacks

· Published 02/10/2025 09:42 · Modified 02/10/2025 13:15

Export JSON

Essential information

Published
02/10/2025 09:42
Modified
02/10/2025 13:15
Tags
2025-10-02 asyncrat energy foalshell government kyrgyzstan manufacturing mining phishing rat reverse shell russia stallionrat telegram
Related entities
1 intrusion sets (apt), 13 techniques (mitre), 3 malware, 6 others

Description

Cavalry Werewolf, a malicious actor group, targeted Russian state agencies and enterprises in the , , and sectors from May to August 2025. The attackers used targeted emails, posing as Kyrgyz officials, to gain initial access. They employed custom malware, including reverse shells and , controlled via . The group impersonated or compromised real email accounts from Kyrgyz agencies. Their arsenal includes various versions of (Go, C++, C#) and (Go, PowerShell, Python). The attackers executed commands for system reconnaissance, file uploads, and SOCKS5 proxying. Evidence suggests potential expansion to targets in Tajikistan and Middle Eastern countries.

External references