logo

Vortex Werewolf Targets Organizations With Tor-Enabled RDP, SMB, SFTP, and SSH Backdoors

ID: a396f752-49f7-5a8d-b003-d52f5fe183c5

STIX ID: report--a396f752-49f7-5a8d-b003-d52f5fe183c5

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-02-09

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Vortex Werewolf (SkyCloak) is an APT campaign targeting Russian government and defense organizations that uses Telegram-themed phishing to steal session credentials and deliver LNK/PowerShell droppers; the payload installs a Tor-hidden OpenSSH backdoor, obfs4 proxy, and scheduled tasks to maintain covert, persistent remote access. The report provides a technical deep dive into the infection chain, infrastructure (GitHub Pages, Cloudflare), TTPs, and seven file-hash indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.