HeartlessSoul, also known as Versatile Werewolf, is a cyberespionage threat group active since at least September 2025. It has targeted Russian government agencies, individual users, industrial enterprises, and aviation-sector organizations, with apparent interest in sensitive geographic information system data that can expose terrain, infrastructure, engineering networks, and strategic facilities. The group has also used lures themed around FPV drone simulators and tools purported to bypass satellite-internet restrictions, indicating interest in military-adjacent personnel such as UAV operators and communications specialists. HeartlessSoul primarily gains access through phishing emails carrying malicious archives, malicious advertising, and impersonated software-download sites. It distributes spyware disguised as legitimate software, including via legitimate software-hosting services. Its malware can collect local documents, images, GIS and geospatial files, screenshots, keystrokes, browser data, messaging-platform credentials, and device-location data, then exfiltrate the collected information. HeartlessSoul has been assessed as operationally linked to GOFFEE (Paper Werewolf), although the nature and extent of that relationship remain unresolved.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A related APT group assessed with medium confidence to be operated by the same attackers as GOFFEE, although its toolset differs substantially.
Mentioned as using AI-generated stagers and a generative-AI-built RAT in the same quarter as part of the broader trend of AI-assisted offensive activity.
Cyber-espionage group targeting Russian government agencies and aviation-related organizations to steal sensitive geospatial/GIS data and other confidential information.
Conducting phishing and malware delivery campaigns using fake FPV simulator and Starlink-blocking bypass themed lures, likely targeting military-adjacent victims such as UAV units, communications personnel, and supporters; the malware steals documents, images, and GIS/geospatial files.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.