Feral Wolf exploits enterprise software to hit Russian companies
From May through August 2026, Russian organizations across key economic sectors, from retail to manufacturing, faced targeted attacks by Feral Wolf. During the investigation, our threat intelligence team analyzed the actor’s tools and uncovered a wide range of techniques, including the exploitation of critical vulnerabilities in popular enterprise software and the compromise of systems through contractors. The ultimate goal was to disrupt the targets’ operations using ransomware.
The incident analysis revealed multiple methods of gaining initial access. The main vectors included exploiting vulnerabilities in Atlassian Confluence to gain unauthorized remote access and using contractor infrastructures as a “weak link.” The adversaries also abused 1C misconfigurations to inject malicious code and access databases.
In addition to these techniques, our team discovered Feral Wolf’s unique set of tools to covertly control compromised systems. The attackers used backdoors to leverage legitimate application layer protocols, helping them remain undetected on victim networks. To move laterally and bypass network restrictions, the group employed proxying tools that redirected traffic through remote desktop channels.
In the final stage of the attacks, the adversaries run the GenieLocker ransomware to encrypt critical data, effectively crippling the business operations of the affected organizations.
According to our data, manufacturing accounted for 11% of all attacks in the first half of 2026, followed by retail at 8%, IT companies at 5%, and construction at 3%. Despite differences among these sectors, financial motivation remained the primary driver of adversary activity in all observed cases.