Versatile Werewolf is an espionage-oriented threat cluster associated with malware campaigns themed around Starlink terminal management tools and drone pilot training software. The actor has targeted government organizations, military personnel, and individuals involved in drone manufacturing and engineering, indicating a focus on state and defense-adjacent intelligence collection. The cluster is known for distributing malicious MSI installers masquerading as legitimate applications, including fake Starlink-related utilities and UAV training software. Its intrusion chains use multiple staged components, including PowerShell, VBScript, .NET loaders, and JavaScript, to deploy payloads while blending into normal Windows activity. One documented tradecraft pattern abuses the legitimate Windows utility Fondue.exe to side-load a malicious APPWIZ.cpl file, resulting in in-memory deployment of a Sliver implant. This provides remote command execution and post-compromise access, and is paired with persistence through scheduled tasks designed to resemble legitimate Microsoft update activity. Versatile Werewolf has also deployed SoullessRAT, a JavaScript-based remote access trojan reportedly developed with assistance from generative AI. SoullessRAT supports command execution, file transfer, screenshot capture, Outlook data harvesting, directory and volume enumeration, and broader host reconnaissance. Across observed campaigns, the actor has demonstrated defense evasion through use of trusted binaries, side-loading, obfuscation, and packed components, as well as persistence and post-exploitation capability through implants and scheduled task creation. Known lures and infrastructure themes include StarDebug and AlphaFly. The cluster has been tracked distinctly from other similarly named Werewolf clusters such as Paper Werewolf and Eagle Werewolf.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
20 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a multi-stage espionage campaign that abuses the legitimate Windows binary Fondue.exe to side-load a malicious APPWIZ.cpl, deploy a Sliver implant, maintain persistence via scheduled tasks, and in parallel deploy SoullessRAT using fake Starlink and drone-themed applications as lures against sensitive targets.
Uses fake Starlink terminal management and drone training applications to deliver Sliver implants and SoullessRAT through MSI installers, PowerShell/VBS/.NET loaders, DLL side-loading, and staged JavaScript payloads.
Runs Starlink- and drone-themed malware campaigns using malicious MSI installers, PowerShell/VBS/.NET loaders, DLL side-loading, Sliver implants, and JS-based SoullessRAT delivery.
Операции по распространению вредоносных MSI-установщиков, маскируемых под ПО для управления терминалами Starlink и обучения пилотированию БПЛА, с доставкой Sliver и SoullessRAT через многостадийные PowerShell/JS-цепочки.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.