Eagle Werewolf is a threat cluster tracked under the name Eagle Werewolf and assessed as active since at least May 2023. The cluster primarily targets state organizations, industrial companies, and individuals involved in drone/UAV manufacturing and engineering. Reported activity is espionage-focused. The cluster has been linked to Starlink device registration and drone training themed lures, including phishing and abuse of compromised UAV- or drone-focused Telegram channels to distribute malware. In February 2026, Eagle Werewolf activity was associated with a Starlink registration campaign in which a ZIP archive containing a Rust dropper was distributed. Reported tooling associated with the cluster includes Rust and Go droppers, the Rust RAT AquilaRAT, and Go2Tunnel for reverse SSH tunneling. Described behaviors include host registration with command-and-control infrastructure, victim data collection, creation of hidden local user accounts, attempts to add those accounts to the Administrators group, installation of AquilaRAT as the MicrosoftOfficeUpdate service, and establishment of reverse SSH tunnels for persistent remote access. AquilaRAT is described as a previously undocumented Rust RAT used by the cluster. Reported capabilities include heartbeat/check-in behavior, command execution, file upload, and file scanning while polling command-and-control infrastructure at regular intervals. Go2Tunnel was used to register tunnel parameters with command-and-control infrastructure, write authorized_keys entries, and launch reverse SSH tunnels exposing local SSH access. Infrastructure hosted on Regxa Company for Information Technology Ltd. in Iraq was identified as hosting command-and-control associated with a February 2026 Eagle Werewolf espionage campaign targeting state and industrial entities using Starlink registration and drone training lures. The content also states that Kaspersky observed possible overlaps between Eagle Werewolf and the separately tracked Armored Likho activity. Specifically, Armored Likho was assessed to share similarities with Eagle Werewolf in tooling, persistence, tasking logic, and command-and-control patterns, and Armored Likho’s operations were said to appear to overlap with Eagle Werewolf activity. No additional confirmed aliases or sub-groups are directly provided beyond Eagle Werewolf itself.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
45 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
117 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an activity cluster whose operations appear to overlap with Armored Likho.
A threat cluster possibly overlapping with Armored Likho, known for targeting government and defense organizations, including UAV development and manufacturing, using droppers, RATs, SSH tunneling utilities, and compromised Telegram channels for malware distribution.
Espionage campaign using Iraqi Regxa hosting to deploy multiple RATs through phishing lures themed around Starlink registration and drone training.
Espionage campaign targeting state and industrial entities using Starlink registration and drone training lures, supported by C2 infrastructure hosted on Regxa.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.