Silent Werewolf
Silent Werewolf is a threat actor tracked under the alias Silent Werewolf. Reporting in 2025 describes it conducting malware campaigns against organizations in Russia and Moldova, with additional historical targeting of organizations in Russia, Belarus, Ukraine, Moldova, and Serbia since at least 2011. Reported victim sectors in Russia include nuclear, aircraft, instrumentation, and mechanical engineering, and one campaign was described as targeting Eastern European governmental entities, with at least one confirmed target in the Minsk region. Artifacts also suggested interest in Russian retail, financial institutions, large insurance companies, and governmental postal services. The group is reported to rely on phishing-based initial access. In March 2025 campaigns, it used phishing emails or phishing links delivering ZIP archives containing LNK files and nested ZIP archives. The delivery chain included a decoy PDF, a legitimate renamed executable, and a malicious DLL that was sideloaded, including use of DeviceMetadataWizard.exe with a C# loader named d3d9.dll. BI.ZONE also associated Silent Werewolf with DLL sideloading in campaigns against Moldovan and Russian companies. The malware and tooling associated with Silent Werewolf in the provided reporting include XDigo, XDSpy, and DSDownloader, with XDigo assessed as the likely payload in the March 2025 activity. The sideloaded DLL in that chain was described as a first-stage downloader dubbed ETDownloader, likely intended to deploy XDigo. XDigo is a Go-based implant that can harvest files, extract clipboard contents, capture screenshots, execute commands or binaries retrieved from a remote server via HTTP GET, and exfiltrate data via HTTP POST. The content does not directly attribute Silent Werewolf to a nation state, but its targeting and long-running activity indicate an espionage-oriented threat actor focused on Eastern Europe and especially Russian- and Moldovan-linked organizations.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
2 malware families attributed to this actor across reporting.
Associated vulnerabilities
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Phishing-led intrusions in Russia/Moldova using LNK/ZIP chains and DLL sideloading to run a loader that fetches a second-stage payload (likely XDigo).
Activity cluster tracked by BI.ZONE associated with the same LNK/ZIP multi-stage infection chain used to compromise Moldovan and Russian companies, delivering downloader/stealer tooling consistent with the XDSpy ecosystem described in the report.
Silent Werewolf is a cyber espionage group active since at least 2011, targeting organizations in Russia, Belarus, Ukraine, Moldova, and Serbia with phishing campaigns delivering malware such as XDSpy, XDigo, and DSDownloader.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.