Awaken Likho, also known as Core Werewolf, is an espionage-focused APT cluster active since at least 2021 that primarily targets organizations in Russia and Belarus. Reported victimology centers on government institutions and their contractors, with additional targeting of the energy sector and defense-industrial organizations. The group is assessed to be Russian-speaking and is known for document theft and broader collection of user and system data. Awaken Likho commonly gains initial access through targeted phishing using Russian-language lures and self-extracting archives that present decoy documents to the victim while launching malware. Earlier operations relied heavily on legitimate remote administration and transfer tools such as UltraVNC, MeshCentral or MeshAgent, and Rclone. More recent activity shows a shift toward custom malware development, reducing dependence on third-party tooling while preserving the group’s established delivery patterns. Custom tooling attributed to the group includes an AutoIt-based lightweight backdoor or loader and the C++ backdoors TokenBuoy and TokenBuoySH. The AutoIt implant executes through a legitimate AutoIt interpreter, opens a decoy document, inventories desktop files, communicates with command-and-control infrastructure over HTTP, executes shell commands, and can download follow-on payloads. TokenBuoy serves as a first-stage manually operated backdoor that performs host reconnaissance, collects process, host, network, and file information, and retrieves operator commands for execution. TokenBuoySH functions as a more advanced second-stage implant with per-victim configuration, host validation, telemetry collection, command execution, file transfer, and optional SSH-based backdoor and proxy capabilities. Both malware families incorporate stealth-oriented features such as self-deletion, environment-aware behavior, and tailored victim checks. The group has demonstrated reconnaissance, post-compromise remote administration, data collection, and exfiltration. Rclone has been used to steal documents from compromised systems after deployment through later-stage tooling. Awaken Likho has also been observed abusing MeshAgent for reconnaissance, exfiltration, and further malware deployment. Some reporting additionally associates the cluster with destructive activity through use of the Goodbye-wiper after data theft. Known aliases include Core Werewolf. Awaken Likho is also part of the broader Likho activity cluster and has been noted as closely resembling related Likho-associated operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
68 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Using an AutoIt backdoor in operations targeting Russia and Belarus.
Conducting phishing-led intrusions against Russian and Belarusian government organizations, using custom backdoors TokenBuoy and TokenBuoySH for system reconnaissance, command execution, telemetry collection, file theft, and exfiltration, alongside Rclone and previously legitimate remote administration tools.
Conducting cyber-espionage campaigns primarily against organizations in Russia and Belarus, especially government institutions and contractors, using targeted phishing, self-extracting 7-Zip archives, AutoIt-based implants, and previously legitimate remote administration tools such as UltraVNC.
Espionage-focused group targeting government, energy, and defense sectors; also conducts destructive follow-on activity using a custom wiper after exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.