Core Werewolf gears up with custom remote access trojan
From June to July 2026, the BI.ZONE Threat Intelligence team analyzed the new campaign by Core Werewolf targeting Russian organizations. Our experts detected previously undocumented CoreRAT that the threat actor had used since March 2026.
To gain initial access, the attackers, presumably, distributed the 7zSFX and Rust droppers via phishing emails and Telegram messages. Upon startup, the dropper unpacked and saved on the victim’s device CoreRAT and a decoy PDF disguised as official government communications, and then launched the trojan.
The decoys contained atypical wordings, signs of editing, and fake signatures. Once CoreRAT was started, the threat actor gained full control over the compromised system.
The research revealed that the cluster had revamped the toolkit with its own CoreRAT to replace the legitimate UltraVNC remote access software.
Our specialists hypothesized that one of the decoys matched a document previously used by Vortex Werewolf in its attacks. These clusters usually had similar targets and attack regions. This similarity could indicate that the threat actors shared tools, decoys, and expertise. It was also possible that Core Werewolf and Vortex Werewolf were part of the same group with a common development infrastructure. But this assumption required further investigation.
Building an effective cybersecurity strategy against Core Werewolf and similar clusters requires knowledge of the current threat landscape. The BI.ZONE Threat Intelligence portal provides organizations with timely insights into indicators of compromise and adversary toolkits. This information facilitates incident response and helps build corporate defenses against relevant threats.
However, effective protection demands timely detection and containment of attempted intrusions. EDR solutions such as BI.ZONE EDR enable early detection of attacks and immediate incident response—either automated or manual.