Werewolves is a financially motivated ransomware and double-extortion group known for targeting Russian organizations. The group has been observed using a version of the leaked LockBit ransomware and operating a leak site to pressure victims through publication threats and additional coercive tactics centered on analysis of stolen data. Its extortion messaging has included claims that exfiltrated information is subjected to criminal-legal, commercial, and insider-information assessment to increase leverage over victims. Observed intrusion activity indicates initial access via phishing emails and malicious attachments, including exploitation of CVE-2017-11882. Post-compromise tradecraft has included deployment of Cobalt Strike Beacon and Meterpreter, use of remote administration software such as AnyDesk, and network reconnaissance with tools such as NetScan. The group’s operations therefore span initial access, reconnaissance, post-exploitation, persistence, credentialed remote access, and data exfiltration, followed by ransomware deployment and leak-site-based extortion. Werewolves is distinct from other similarly named Russia-focused clusters such as Paper Werewolf, Sapphire Werewolf, Silent Werewolf, Rare Werewolf, and Fairy Wolf. Available reporting supports classification of Werewolves as a cybercriminal ransomware actor rather than a state-sponsored espionage group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operations using phishing lures and a consistent toolchain (remote admin, post-exploitation frameworks) with double extortion; uses Office exploit CVE-2017-11882 in delivery.
Double-extortion ransomware activity targeting Russian companies using a variant derived from leaked LockBit ransomware.
Ransomware operator claiming to analyze stolen data for legal/commercial/insider-information value to increase leverage and reputational harm against victims.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.