Core Werewolf is a tracked threat cluster also known as Awaken Likho and PseudoGamaredon. It has been referenced in connection with cyber-espionage activity and is noted for behavioral similarities with other intrusion sets targeting Russian government and defense entities. High-confidence reporting in this context supports only a limited characterization: Core Werewolf is associated with phishing-led intrusion activity and overlaps in tradecraft with clusters that use social-engineering lures, session hijacking, PowerShell-based execution, persistence, and covert remote-access mechanisms. The available information does not support a fuller attribution, organizational structure, or a definitive country of origin for Core Werewolf itself.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
69 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as overlapping with GamaCopy; no additional operational detail provided in this content excerpt.
Referenced only for behavioral similarity comparison to Vortex Werewolf; no direct campaign details provided in this content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.