logo

New CoreRAT Malware Lets Core Werewolf Hackers Take Full Control of Compromised Systems

ID: 6cb9b378-7207-5d46-8e54-f32da618f36a

STIX ID: report--6cb9b378-7207-5d46-8e54-f32da618f36a

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

Author: Varshini

...
...

Core Werewolf is targeting Russian public-sector and defense organizations with a new custom C++ remote access trojan called CoreRAT delivered via phishing using 7z self-extracting and Rust-based droppers that display decoy PDFs. CoreRAT performs extensive reconnaissance, command execution, file transfer, network discovery, anti-VM/sandbox checks, AES-CBC-encrypted strings and C2, and uses HTTPS POST to exfiltrate Base58-encoded JSON; the report includes defanged domain IOCs and notes increased attacker capability compared to prior backdoors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.