Clubfoot Wolf is a financially motivated threat cluster associated with large-scale phishing operations targeting organizations in Russia, with additional targeting observed in Belarus. Reported victim sectors include manufacturing, retail, e-commerce, agriculture, information technology, transportation, health care, and science, with a particular emphasis on wholesale distributors of chemical products. The cluster relies on phishing for initial access, typically sending messages that impersonate prospective buyers and use invoice, quotation, or procurement-themed lures. Delivery commonly involves archive attachments containing decoy documents alongside a malicious shortcut file. Execution of the shortcut triggers concealed PowerShell activity that retrieves and runs additional stages directly in memory, reflecting a fileless infection chain designed to reduce visibility. The operators have also used shortened links to obscure downstream infrastructure and complicate analysis and detection. A notable characteristic of Clubfoot Wolf activity is the abuse of NetSupport Manager, a legitimate remote administration tool, as the final payload for post-compromise access. Observed tradecraft includes staging the tool under a benign-looking application directory name, launching it through scripted PowerShell loaders, and attempting persistence through a user startup mechanism. The cluster has also used decoy content and junk files to build victim trust, distract users, and vary delivered artifacts. The activity indicates ongoing experimentation with delivery methods, infection chains, and masking techniques. Attribution beyond the Clubfoot Wolf cluster designation remains limited.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
70 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated cluster conducting large-scale phishing campaigns against Russian firms, using fake purchase-order lures and malicious shortcut files to deploy NetSupport Manager for remote access and persistence.
Conducting a large-scale phishing-led intrusion campaign against Russian organizations, especially wholesale chemical distributors, and some Belarusian organizations, using NetSupport Manager as the primary payload for remote access and follow-on malicious activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.