Vortex Werewolf is a cyber-espionage cluster active since at least December 2025 that targets Russian government and defense organizations, with additional targeting reported in Belarus. The group seeks persistent, covert access to sensitive systems. Its activity has also been tracked in connection with Operation SkyCloak. Vortex Werewolf uses phishing messages impersonating trusted file-sharing or messaging services to direct victims to fraudulent download portals. These portals capture phone numbers and login confirmation codes, enabling session hijacking, then redirect victims to legitimate file-hosting services that deliver malicious archives. The archives contain deceptive Windows shortcut files that execute PowerShell-based payloads. The payloads conduct sandbox-evasion checks, install Tor and OpenSSH, and establish anonymized remote-access and file-transfer channels. The group configures scheduled tasks to persistently start Tor and SSH services, and uses Tor hidden services to obscure command-and-control communications. Its tooling supports remote command execution and transfer through RDP, SMB, SFTP, and SSH. Vortex Werewolf has been assessed as distinct from, but behaviorally similar to, Core Werewolf.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned solely as an unconfirmed possible connection based on a similar decoy document.
Named as an attribution-associated activity cluster in relation to the post-takedown QakBot ecosystem, but the content does not provide operational detail beyond that association.
Targets Russia and Belarus with the goal of establishing persistent remote access by deploying Tor and OpenSSH; campaign also referred to as Operation SkyCloak by Seqrite Labs.
Targets Russia and Belarus with the objective of establishing persistent remote access by deploying Tor and OpenSSH; campaign also referred to as Operation SkyCloak by Seqrite Labs.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.