Core Werewolf gears up with custom remote access trojan

Core Werewolf gears up with custom remote access trojan

The espionage cluster created a remote access trojan (RAT) to attack Russia’s public sector and defense industry
August 18, 2026

From June to July 2026, the BI.ZONE Threat Intelligence team analyzed the new campaign by Core Werewolf targeting Russian organizations. Our experts detected previously undocumented CoreRAT that the threat actor had used since March 2026.

To gain initial access, the attackers, presumably, distributed the 7zSFX and Rust droppers via phishing emails and Telegram messages. Upon startup, the dropper unpacked and saved on the victim’s device CoreRAT and a decoy PDF disguised as official government communications, and then launched the trojan.

The decoys contained atypical wordings, signs of editing, and fake signatures. Once CoreRAT was started, the threat actor gained full control over the compromised system.

The research revealed that the cluster had revamped the toolkit with its own CoreRAT to replace the legitimate UltraVNC remote access software.

Core Werewolf’s primary goal is espionage. According to BI.ZONE Threat Intelligence, about 48% of clusters targeting Russian organizations today are spies. To achieve their goals, threat actors need to remain unnoticed in compromised infrastructures for a long time. For this reason, developing its own RAT is a natural step for Core Werewolf. Custom malware is harder to detect, which helps adversaries stay under the radar for longer periods.
Oleg Skulkin
Head of BI.ZONE Threat Intelligence

Our specialists hypothesized that one of the decoys matched a document previously used by Vortex Werewolf in its attacks. These clusters usually had similar targets and attack regions. This similarity could indicate that the threat actors shared tools, decoys, and expertise. It was also possible that Core Werewolf and Vortex Werewolf were part of the same group with a common development infrastructure. But this assumption required further investigation.

Building an effective cybersecurity strategy against Core Werewolf and similar clusters requires knowledge of the current threat landscape. The BI.ZONE Threat Intelligence portal provides organizations with timely insights into indicators of compromise and adversary toolkits. This information facilitates incident response and helps build corporate defenses against relevant threats.

However, effective protection demands timely detection and containment of attempted intrusions. EDR solutions such as BI.ZONE EDR enable early detection of attacks and immediate incident response—either automated or manual.