Fairy Wolf, also referred to as Unicorn, is a financially motivated cybercrime actor associated with stealer malware distribution. The group has been observed using phishing-style delivery chains in which archive files contain HTA-based droppers that install the Unicorn stealer. Reporting also notes the actor’s use of Telegram as a distribution vector, indicating adaptation of commodity messaging platforms for malware delivery and operator control workflows. High-confidence public reporting in the supplied material is limited, but Fairy Wolf is linked specifically to credential and information theft activity rather than espionage or destructive operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.