VasyGrek, also referred to as Fluffy Wolf, is a Russian-speaking cybercrime threat actor active since at least 2016. The actor is known for targeting Russian companies and conducting financially motivated intrusions using phishing-delivered malware. Reported operations have involved remote access trojans, stealer malware, Pure malware, and Pay2Key ransomware, indicating an intrusion set spanning initial compromise, persistent access, credential and data theft, and in some cases ransomware deployment. Available reporting characterizes VasyGrek as an e-crime actor rather than a state-backed espionage group. Known aliases include VasyGrek and Fluffy Wolf.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
VasyGrek is a Russian-speaking e-crime actor targeting Russian companies with RATs, stealer malware, and ransomware, including Pay2Key and malware developed by PureCoder.
VasyGrek (Fluffy Wolf) is a Russian-speaking e-crime actor targeting Russian companies, using the Pure malware family.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.