Sapphire Werewolf is a cybercriminal intrusion cluster tracked for phishing-led theft of information from organizations in Russia’s fuel and energy sector. Public reporting associates the group with campaigns delivering Amethyst Stealer, including updated variants protected with .NET obfuscation, to harvest data from messaging applications, web browsers, SSH clients, and VPN software. The group appears financially motivated, with operations centered on credential and information theft rather than destructive or disruptive effects. Observed tradecraft is consistent with targeted spearphishing using malicious attachments or payloads disguised as benign documents, including decoys masquerading as PDF files. After execution, the malware focuses on collecting locally stored credentials, session data, and other user-accessible information from enterprise workstations. The activity fits a broader pattern of Russian-language phishing campaigns against critical and industrial organizations that rely on social engineering, commodity loaders or stealers, and stealth through packing or obfuscation rather than highly novel exploitation. Sapphire Werewolf is primarily associated with attacks against fuel and energy companies in Russia. High-confidence public details remain limited beyond its use of Amethyst Stealer and phishing-based delivery. No widely established aliases or confirmed sub-groups are currently available from the provided reporting.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
APT targeting the fuel and energy sector using Amethyst Stealer to collect data from Telegram, browsers, SSH, and VPN clients.
Mentioned only as a comparative example of another group with similar execution chains.
Credential/data theft via phishing-delivered .NET downloader that deploys Amethyst Stealer to exfiltrate browser, Telegram, VPN/RDP, and document data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.