GOFFEE, also known as Paper Werewolf, is an espionage-focused APT group active since at least early 2022. It has principally targeted organizations in Russia and expanded observed targeting to Belarus, with victims including technology companies, government entities, engineering and manufacturing organizations, media, telecommunications, construction, and energy-sector organizations. GOFFEE primarily obtains access through targeted phishing, including malicious archives and document lures that use macros or remote-template injection. It has also been associated with exploitation of CVE-2025-8088 through phishing-delivered malicious archives. The group uses custom malware and Mythic agents, including PowerTaskel, PowerModul, WarpRAT/EchoGather, and binary Mythic implants. Its operations include in-memory execution, obfuscated PowerShell, JavaScript and HTA execution chains, use of modified legitimate Windows binaries, and use of legitimate administration and download utilities. GOFFEE has used persistence mechanisms including malicious services and startup execution, and has performed privilege escalation and lateral movement using remote administration and Windows management technologies. Post-compromise activity includes host and process discovery, collection of user and filesystem information, searches for credentials and configurations associated with remote-access, VPN, messaging, and database-administration software, and theft of files from removable media. The group has exfiltrated collected information over web traffic and used campaign-separated infrastructure and reverse proxies to conceal command-and-control systems. GOFFEE has also been observed operating a Mythic agent within a Linux container through fileless execution, indicating activity against containerized environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
59 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
16 malware families attributed to this actor across reporting.
11 additional families tracked in Mallory.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
Analysis of the compromised environments revealed that the attackers gained initial access in most cases by exploiting the ProxyShell vulnerability in Microsoft Exchange, which allows for full server compromise.
In this blog post, I’ll be diving into the technical details of the WinRAR vulnerability, identified as CVE-2025-8088. This vulnerability carries a high severity score of 8.4 and affects WinRAR on Windows operating systems due to a path traversal flaw.
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...delivering RAR files that also took advantage of CVE-2025-6218, a different WinRAR flaw patched in June 2025.
209 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Кибершпионская APT-группа, проводящая длительные, скрытные и тщательно таргетированные кампании преимущественно против российских государственных и промышленных организаций. В кампании марта 2026 года применяла целевой фишинг с PDF-приманками, доставлявшими WarpRAT, а также PowerTaskel v2 — модифицированный PowerShell-агент Mythic. Группа регулярно меняет C2-инфраструктуру и инструментарий для отдельных кампаний.
Using legitimate utilities and the Mythic agent for reconnaissance, credential access, and follow-on activity in container environments.
Referenced as using likely LLM-generated modules in operations targeting Russian defense enterprises.
Conducting phishing-led intrusions primarily against Russian IT companies, with expanded targeting into Belarus. The group uses malformed-looking lure documents to trigger remote template loading and macro execution, followed by in-memory payload delivery, hands-on-keyboard post-exploitation, living-off-the-land tooling, and stealthy exfiltration including data sent via the HTTP User-Agent header. The campaign also includes use of a Mythic agent inside a Linux container.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.