Feral Wolf compromised Russian retail, construction, manufacturing, and IT organizations from May through August 2026, ultimately encrypting data with GenieLocker ransomware. Initial access paths included exploitation of Atlassian Confluence vulnerability CVE-2023-22515, insecure internet-exposed 1C:Enterprise cluster configurations, and compromised contractor infrastructure; the operators also moved from containers to hosts, abused weak PostgreSQL credentials, and dumped LSASS memory to obtain credentials.
BI.ZONE identified three previously unknown Feral Wolf tools: MQTTDoor, MatrixDoor, and RDPSocksProxy. MQTTDoor and MatrixDoor are Rust-based Windows service backdoors that use ostensibly legitimate MQTT and Matrix communications for encrypted command-and-control, with ChaCha20-protected data tied to the victim host's MachineGuid; RDPSocksProxy tunnels traffic through RDP. The group used these tools alongside anti-forensic cleanup to conceal persistence, lateral movement, and data-encryption operations.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
Between May and August 2026, Feral Wolf targeted Russian retail, construction, manufacturing, and IT organizations. The intrusions culminated in encryption of victim data using GenieLocker ransomware.
BI.ZONE identified three previously unknown Feral Wolf tools: the MQTTDoor and MatrixDoor Rust backdoors and the RDPSocksProxy tunneling tool. The tools use MQTT, Matrix, or RDP-based communications to conceal command-and-control and tunneling activity.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 19 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.