Silent Werewolf is an espionage-oriented threat actor active since at least 2011 that has targeted organizations in Eastern Europe, with a sustained focus on Russia and Moldova and additional activity affecting Belarus, Ukraine, and Serbia. The group has been associated with campaigns against governmental entities and Russian industrial organizations, including nuclear, aircraft, instrumentation, and mechanical engineering sectors. Reporting also links its activity to targeting interests in retail, financial institutions, insurance, and governmental postal services. Silent Werewolf commonly relies on phishing for initial access, using email lures or links to archives that deliver multi-stage malware chains. Observed delivery methods include ZIP archives containing crafted Windows shortcut files, nested archives, decoy documents, legitimate renamed executables, and malicious DLLs used for DLL sideloading. In documented 2025 campaigns, the actor used a sideloading chain involving a legitimate Windows binary to launch a downloader assessed to deploy XDigo, a Go-based implant associated with data collection and remote tasking. The actor has been linked to malware including XDSpy, XDigo, DSDownloader, and ETDownloader. XDigo supports file theft, clipboard collection, screenshot capture, remote command execution, and HTTP-based exfiltration, indicating a mature post-compromise collection capability. Silent Werewolf’s tradecraft is consistent with long-running cyber espionage operations centered on stealthy malware delivery, collection from compromised hosts, and abuse of legitimate executables for defense evasion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Phishing-led intrusions in Russia/Moldova using LNK/ZIP chains and DLL sideloading to run a loader that fetches a second-stage payload (likely XDigo).
Activity cluster tracked by BI.ZONE associated with the same LNK/ZIP multi-stage infection chain used to compromise Moldovan and Russian companies, delivering downloader/stealer tooling consistent with the XDSpy ecosystem described in the report.
Silent Werewolf is a cyber espionage group active since at least 2011, targeting organizations in Russia, Belarus, Ukraine, Moldova, and Serbia with phishing campaigns delivering malware such as XDSpy, XDigo, and DSDownloader.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.