Cavalry Werewolf, an advanced persistent threat (APT) group with reported overlaps to YoroTrooper and other clusters such as SturgeonPhisher, Silent Lynx, Comrade Saiga, ShadowSilk, and Tomiris, has been actively targeting Russian state agencies and critical industries. The group has been observed deploying custom malware families, notably FoalShell and StallionRAT, in a series of sophisticated cyberattacks. According to cybersecurity vendor BI.ZONE, the attackers initiated their campaigns by sending highly targeted phishing emails that masqueraded as official correspondence from Kyrgyz government officials. These emails were crafted to deceive recipients within Russian government agencies, as well as organizations in the energy, mining, and manufacturing sectors. In some instances, the attackers compromised legitimate email accounts belonging to the Kyrgyz Republic's regulatory authority, increasing the credibility and effectiveness of their phishing attempts. The phishing emails typically contained RAR archive attachments, which, when opened, delivered the FoalShell or StallionRAT malware payloads to the victims' systems. FoalShell is a lightweight reverse shell available in Go, C++, and C# versions, enabling attackers to execute arbitrary commands via cmd.exe on compromised machines. StallionRAT, written in Go, PowerShell, and Python, provides similar capabilities, including command execution, file loading, and data exfiltration. The campaign was observed between May and August 2025, indicating a sustained and coordinated effort to infiltrate Russian public sector networks. The technical sophistication of the malware, including its multi-language implementations, suggests a well-resourced and adaptable threat actor. The use of Telegram as a command-and-control (C2) channel has also been reported, allowing the attackers to maintain covert communications and control over infected hosts. The group’s ties to Tomiris, which Microsoft has linked to a Kazakhstan-based actor known as Storm-0473, further suggest a regional nexus and possible state sponsorship. Previous related attacks by ShadowSilk targeted government entities in Central Asia and the Asia-Pacific region, using similar remote access trojans and reverse proxy tools. The ongoing campaign highlights the persistent threat posed by Cavalry Werewolf to Russian governmental and industrial targets, as well as the broader regional implications of their operations. Security researchers emphasize the importance of monitoring for phishing attempts impersonating government officials and the deployment of custom malware families like FoalShell and StallionRAT. The attacks underscore the need for robust email security, user awareness training, and advanced endpoint detection to mitigate the risk from such sophisticated APT campaigns. The incident also demonstrates the evolving tactics of threat actors in leveraging both social engineering and technical innovation to achieve their objectives. Organizations in the targeted sectors are advised to review their security postures and implement proactive threat hunting measures. The campaign serves as a reminder of the complex and dynamic nature of cyber threats facing government and critical infrastructure entities in the region.

See the actors and campaigns active against you right now.
5 events from the most recent confirmed update back to the earliest known activity.
BI.ZONE publicly disclosed that Cavalry Werewolf had targeted Russian agencies and adjacent sectors using FoalShell, with reporting also highlighting Telegram-based command-and-control. The disclosure consolidated details on the campaign's targeting, malware, and infrastructure.
Based on the 2025 campaign analysis, BI.ZONE assessed that Cavalry Werewolf activity has ties to Tomiris, which Microsoft previously attributed to the Kazakhstan-linked actor Storm-0473. This supported BI.ZONE's hypothesis that the operation is affiliated with Kazakhstan.
During the May–August 2025 campaign, Cavalry Werewolf deployed the FoalShell and StallionRAT malware families against Russian agencies. The malware enabled remote command execution, while StallionRAT also supported data exfiltration through a Telegram bot and use of reverse proxy tools such as ReverseSocks5Agent/ReverseSocks5.
Between May and August 2025, the threat actor tracked as Cavalry Werewolf targeted the Russian public sector and adjacent industries with phishing emails impersonating Kyrgyz government officials. In at least one case, the attackers used a compromised legitimate Kyrgyz regulatory authority email account to deliver malicious RAR archives.
BI.ZONE said its analysis of Telegram and underground forum postings over the previous year indicated that at least 500 Russian companies were compromised. The intrusions commonly involved attacks on public-facing web applications, persistence via gs-netcat, and database theft using tools such as Adminer, phpMiniAdmin, and mysqldump.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.