Sapphire Werewolf is a cyber threat cluster targeting organizations in Russia’s fuel and energy sector. The group has been reported using phishing emails to deliver Amethyst Stealer, including updated variants protected with .NET obfuscation. Its operations are focused on theft of information from user applications and access tools, including Telegram, web browsers, SSH clients, and VPN clients. Observed tradecraft indicates phishing-based initial access followed by deployment of an infostealer for collection and exfiltration of victim data. The group’s activity aligns with credential and access-material theft rather than destructive or ransomware operations. Public reporting directly associates Sapphire Werewolf with campaigns against Russian fuel and energy companies; broader attribution to a state sponsor or a specific national origin is not established at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
APT targeting the fuel and energy sector using Amethyst Stealer to collect data from Telegram, browsers, SSH, and VPN clients.
Mentioned only as a comparative example of another group with similar execution chains.
Credential/data theft via phishing-delivered .NET downloader that deploys Amethyst Stealer to exfiltrate browser, Telegram, VPN/RDP, and document data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.