At a glance
| Actor / group | Core Werewolf (suspected cyberespionage cluster) |
| Activity type | Phishing, remote access trojan, data theft |
| Targets / victims | Russian public sector and defense industry (assessed) |
| Scale | Campaign observed June to July 2026; CoreRAT active since at least March 2026 |
| Status | Active; no public arrests or charges |
| Source | BI.ZONE Threat Intelligence |
TL;DR
Core Werewolf built its own remote access trojan, CoreRAT malware. The group used it against Russian defense and government targets from June to July 2026. BI.ZONE says the tool marks a step up in the cluster’s skills.
What happened
BI.ZONE Threat Intelligence tracked a fresh Core Werewolf campaign in mid-2026. The attackers spread CoreRAT malware through two droppers. One used the 7zSFX format, while the other was written in Rust.
Both droppers carried a decoy PDF and the trojan. First, the dropper opened a fake document. Then, it quietly launched CoreRAT in the background. The malware landed in folders like the user’s Links or Temp directory.
The phishing came mainly through Telegram messages. Files posed as refresher training orders and passport paperwork. As a result, busy staff had reason to open them.
Fake military documents
The decoy PDFs looked like official military and government letters. However, BI.ZONE found clear signs of fakery. The researchers noted wording “atypical of official government communications”, plus edited artifacts and forged signatures.
One decoy matched a file tied to another cluster, Vortex Werewolf. That overlap hints the two groups may share tools or people. Still, BI.ZONE says the data cannot confirm this link yet.
Inside the infection chain
The 7zSFX dropper copies its decoy to the desktop or downloads folder. Next, it drops the trojan into the user’s Links folder under names like Firepoin.exe. Then it starts both files, so the victim sees only the PDF.
The Rust dropper works a little differently. It unpacks a ZIP into the Temp folder. After that, it pings the loopback address to stall, then runs CoreRAT. This short delay helps the malware blend into normal activity.
Who is behind it
BI.ZONE attributes the activity to Core Werewolf. Attribution confidence is moderate, and the targeting is an assessment, not a proven fact. The group has hit Russian defense bodies since 2021.
This campaign shows growth. The cluster swapped the legitimate UltraVNC tool for its own trojan. As BI.ZONE puts it, CoreRAT was “its first fully operational RAT”. Earlier, the crew relied on smaller custom backdoors.
Impact and scale
CoreRAT hands operators wide control of an infected PC. The C++ trojan hides its strings with AES encryption. It also runs checks to spot sandboxes and virtual machines before it acts.
Once active, the malware collects the computer name, running processes, and network details. Then it beacons to its command servers over HTTPS. Operators can list files, read network tables, run commands, and drop more payloads.
How to stay protected
The rise of CoreRAT malware shows a clear trend. Groups now build custom trojans to dodge detection longer. Therefore, defenders need layered controls.
Treat unexpected Telegram files with care, even official-looking ones. Never run an executable sent as a “scan” or “instruction.” In addition, block untrusted attachments at the email gateway.
Security teams should watch for odd processes in Links and Temp folders. Monitor outbound HTTPS to unfamiliar domains. Finally, use threat intelligence feeds to catch the latest indicators early.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!