Cavalry Werewolf APT Targets Russian Agencies with FoalShell and StallionRAT
Cavalry Werewolf, an advanced persistent threat (APT) group with reported overlaps to YoroTrooper and other clusters such as SturgeonPhisher, Silent Lynx, Comrade Saiga, ShadowSilk, and Tomiris, has been actively targeting Russian state agencies and critical industries. The group has been observed deploying custom malware families, notably FoalShell and StallionRAT, in a series of sophisticated cyberattacks. According to cybersecurity vendor BI.ZONE, the attackers initiated their campaigns by sending highly targeted phishing emails that masqueraded as official correspondence from Kyrgyz government officials. These emails were crafted to deceive recipients within Russian government agencies, as well as organizations in the energy, mining, and manufacturing sectors. In some instances, the attackers compromised legitimate email accounts belonging to the Kyrgyz Republic's regulatory authority, increasing the credibility and effectiveness of their phishing attempts. The phishing emails typically contained RAR archive attachments, which, when opened, delivered the FoalShell or StallionRAT malware payloads to the victims' systems. FoalShell is a lightweight reverse shell available in Go, C++, and C# versions, enabling attackers to execute arbitrary commands via cmd.exe on compromised machines. StallionRAT, written in Go, PowerShell, and Python, provides similar capabilities, including command execution, file loading, and data exfiltration. The campaign was observed between May and August 2025, indicating a sustained and coordinated effort to infiltrate Russian public sector networks. The technical sophistication of the malware, including its multi-language implementations, suggests a well-resourced and adaptable threat actor. The use of Telegram as a command-and-control (C2) channel has also been reported, allowing the attackers to maintain covert communications and control over infected hosts. The group’s ties to Tomiris, which Microsoft has linked to a Kazakhstan-based actor known as Storm-0473, further suggest a regional nexus and possible state sponsorship. Previous related attacks by ShadowSilk targeted government entities in Central Asia and the Asia-Pacific region, using similar remote access trojans and reverse proxy tools. The ongoing campaign highlights the persistent threat posed by Cavalry Werewolf to Russian governmental and industrial targets, as well as the broader regional implications of their operations. Security researchers emphasize the importance of monitoring for phishing attempts impersonating government officials and the deployment of custom malware families like FoalShell and StallionRAT. The attacks underscore the need for robust email security, user awareness training, and advanced endpoint detection to mitigate the risk from such sophisticated APT campaigns. The incident also demonstrates the evolving tactics of threat actors in leveraging both social engineering and technical innovation to achieve their objectives. Organizations in the targeted sectors are advised to review their security postures and implement proactive threat hunting measures. The campaign serves as a reminder of the complex and dynamic nature of cyber threats facing government and critical infrastructure entities in the region.
Jun 29, 2026