Core Werewolf Deploys New CoreRAT Malware Against Russian Targets
ID: a471589b-555b-5544-8261-2e716de263c9
STIX ID: report--a471589b-555b-5544-8261-2e716de263c9
Feed Name: securityonline.info
Threat Score
BI.ZONE observed a mid-2026 campaign attributed to the suspected Core Werewolf cluster that delivered a custom remote access trojan, CoreRAT, via 7zSFX and Rust droppers sent primarily through Telegram phishing; the trojan performs reconnaissance, hides strings with AES, checks for sandboxes/VMs, beacons to HTTPS C2, and enables remote file/command operations, with recommended mitigations including blocking untrusted attachments and monitoring Links/Temp folders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
