GOFFEE, also tracked as Paper Werewolf, is a cyber-espionage threat actor active since at least 2022 that has consistently targeted organizations in the Russian Federation. Reported victim sectors include government, media, telecommunications, construction, and energy, with additional activity intersecting with military-adjacent themes such as Starlink access and UAV or drone training lures. Available reporting characterizes the group as Russia-focused in victimology rather than a broadly distributed global intrusion set. GOFFEE is known primarily for spear-phishing operations using malicious attachments and archive-based delivery chains. Across campaigns, the actor has used decoy documents, double-extension executables, malicious Office documents with VBA macros, HTA and JavaScript launchers, PowerShell downloaders, and shellcode loaders. Earlier operations used a modified Owowa IIS module, while later campaigns introduced patched Windows binaries as loaders and a progression of custom and semi-custom Mythic-compatible implants. A defining feature of GOFFEE activity is its use of Mythic-related tooling. Public reporting links the actor to PowerTaskel, a PowerShell-based Mythic agent, and PowerModul, a distinct PowerShell downloader and tasking component used to retrieve and execute follow-on payloads. Additional malware associated with GOFFEE includes FlashFileGrabber for theft of files from removable media, a USB-propagating worm for spreading via flash drives, Warp RAT in related victim environments, and custom binary Mythic agents used for lateral movement and remote execution. More recent reporting also links Paper Werewolf to EchoGather RAT delivery through themed social-engineering campaigns, and to Linux-focused tooling including the Sauropsida rootkit. The actor’s tradecraft emphasizes post-compromise collection and lateral movement. Reported techniques include abuse of PowerShell, HTA and JScript chains, shellcode execution in memory, use of PsExec for privilege escalation and remote execution, and WinRM-based movement between hosts. GOFFEE has also been observed establishing persistence through user-level autorun mechanisms and using removable-media theft and propagation to expand access and collect sensitive files from connected devices. Collection priorities have included documents and other potentially sensitive data, especially from removable storage. GOFFEE infrastructure and lure themes have evolved over time. In addition to classic phishing, the actor has used Telegram-centered social engineering and fake software distribution tied to Starlink-related services and drone or FPV simulator themes. Some reporting notes thematic and partial infrastructure overlap with other clusters, including HeartlessSoul, though full operational overlap is not firmly established. Separate investigations also found traces of GOFFEE activity in environments involving other pro-Ukrainian or anti-Russian hacktivist clusters, but those links are best treated as coexistence or possible cooperation rather than confirmed unified command. The group has also been reported exploiting WinRAR vulnerabilities including CVE-2025-6218 and CVE-2025-8088 in phishing-led intrusion chains. These campaigns continued GOFFEE’s established pattern of archive-based initial access and targeted delivery against Russian organizations, particularly government entities. Known aliases include Paper Werewolf and GOFFEE. The actor is best understood as a Russia-focused espionage cluster with a mature phishing capability, strong reliance on Mythic-based tooling, frequent use of PowerShell and script-based loaders, and recurring interest in removable-media collection, lateral movement, and stealthy persistence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
54 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 malware families attributed to this actor across reporting.
8 additional families tracked in Mallory.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
Analysis of the compromised environments revealed that the attackers gained initial access in most cases by exploiting the ProxyShell vulnerability in Microsoft Exchange, which allows for full server compromise.
The vulnerability, tracked as CVE-2025-8088, affects all Windows versions of WinRAR up to 7.12 ... a path traversal bug that leverages Window’s alternate data streams (ADS) feature to circumvent normal file extraction safeguards.
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...delivering RAR files that also took advantage of CVE-2025-6218, a different WinRAR flaw patched in June 2025.
64 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
APT targeting government, media, telecom, and energy sectors using PowerTaskel/PowerModul via Mythic, Ebowla packer, and C2 hosted on Russian providers.
Mentioned only as a comparative example of another group using the Mythic platform.
Mentioned only as part of the broader Ukraine-aligned ecosystem; no direct attribution to the incidents covered.
Hacktivist group whose traces were found in the same victim networks as 4BID, suggesting possible operational overlap or ties with other named groups.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.