HeartlessSoul, also known as Versatile Werewolf, is a cyber-espionage threat group active since at least September 2025. The group has targeted Russian organizations and individual users, with reporting indicating a particular focus on Russian government entities, industrial enterprises, and aviation-related organizations. Available evidence also indicates interest in military-adjacent targets, including UAV operators, communications personnel, and other users likely connected to wartime support functions. HeartlessSoul relies primarily on phishing and social-engineering-driven delivery. Observed lures have impersonated aviation software, FPV drone simulators, and tools advertised as bypasses for Starlink restrictions. The group has also abused legitimate software distribution platforms to host trojanized applications masquerading as benign software. These campaigns use fake or imitation software sites and malicious archives to trigger infection. Malware associated with HeartlessSoul has been described as spyware or a JavaScript-based trojan with broad collection capabilities. Reported functions include theft of documents, images, browser data, screenshots, keystrokes, Telegram credentials, local files, and device location data. A notable aspect of the group’s collection profile is its apparent emphasis on GIS and geospatial data, including formats used for maps, terrain models, engineering networks, and other spatial information that can reveal infrastructure and strategic objects. This targeting profile is consistent with intelligence collection against government, industrial, and military-support environments. HeartlessSoul has also been linked in reporting to Goffee, also known as Paper Werewolf. The relationship remains ambiguous, but overlaps have been noted in infrastructure, lure themes, and targeting patterns, including FPV simulator and Starlink-themed campaigns. Some reporting attributed related infrastructure to Goffee while other analysis associated delivered malware with HeartlessSoul, suggesting possible coordination, shared infrastructure, or partially overlapping operations rather than a fully resolved attribution split. The group’s dominant activity is espionage-oriented collection rather than disruptive or financially motivated operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as using AI-generated stagers and a generative-AI-built RAT in the same quarter as part of the broader trend of AI-assisted offensive activity.
Cyber-espionage group targeting Russian government agencies and aviation-related organizations to steal sensitive geospatial/GIS data and other confidential information.
Conducting phishing and malware delivery campaigns using fake FPV simulator and Starlink-blocking bypass themed lures, likely targeting military-adjacent victims such as UAV units, communications personnel, and supporters; the malware steals documents, images, and GIS/geospatial files.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.