Arcane Werewolf, also tracked as Mythic Likho, is a cyber-espionage threat cluster identified in 2025 and observed targeting Russian organizations, including government agencies, telecommunications entities, manufacturing companies, and other industrial enterprises. Available reporting indicates the group’s operations are focused on collecting confidential information rather than overtly destructive effects. The cluster is notable for its use of the Mythic command-and-control ecosystem and Merlin, an open-source post-exploitation agent written in Go that is compatible with Mythic. Researchers also linked the actor to the custom Loki malware family, including Loki 2.0 and a later Loki 2.1 variant. Loki 2.1 has been described as compatible with both Mythic and Havoc, suggesting an effort to increase operational flexibility and post-compromise control. Arcane Werewolf commonly relies on phishing for initial access. Observed delivery chains used socially engineered lures themed as business correspondence or employment-related documents and delivered malicious archives containing shortcut files. Execution chains have involved LNK-triggered PowerShell, staged payload retrieval, decoy document display, and indirect process execution techniques intended to reduce user suspicion and complicate analysis. Later campaigns against Russian manufacturing organizations in late 2025 similarly used phishing emails leading victims to attacker-controlled download pages hosting malicious archives. Post-compromise tooling associated with the cluster supports host profiling and remote tasking. Observed capabilities include collection of system and user information, encrypted communications over web protocols, file upload and exfiltration, code injection, and process termination. Reporting on Loki evolution indicates iterative development, including changes to victim profiling and data transmission behavior between versions. Arcane Werewolf has been associated with the broader Likho naming lineage in some reporting, but public attribution to a known state sponsor or previously established intrusion set remains unconfirmed. The cluster was given a distinct designation because available evidence was insufficient to confidently map the activity to another known actor. High-confidence public characterization therefore supports describing Arcane Werewolf/Mythic Likho as a separately tracked espionage-oriented cluster active against Russian-sector targets, with tradecraft centered on phishing-led intrusion chains and Mythic-compatible malware.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Espionage-focused APT targeting government institutions and telecommunications, using Merlin agent and LNK-file based infection chains.
APT espionage cluster within the Likho family targeting Russian organizations; publicly associated with use of the Mythic C2 framework, with likely phishing delivery and PowerShell-based post-exploitation, though the article notes limited public campaign detail.
Arcane Werewolf is actively conducting targeted phishing campaigns against Russian manufacturing companies, deploying a new version of its custom malware Loki 2.1, which is integrated with the Mythic and Havoc post-exploitation frameworks. The group uses sophisticated phishing techniques and custom malware to gain access, exfiltrate data, and maintain control over compromised systems.
Targeting Russian manufacturing companies with phishing and custom malware for espionage and data theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.