View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Core Werewolf Uses CoreRAT to Take Over Russian Windows Systems

🕵️ RESEARCH & DEEP DIVES

  • Core Werewolf Uses CoreRAT to Take Over Russian Windows Systems
    Core Werewolf is deploying the CoreRAT remote-access trojan against Russian organizations.
    • Russia’s public-sector and defense organizations are targeted.
    • CoreRAT is a previously undocumented C++ RAT for Windows systems.
    • Telegram phishing delivers military- or government-themed documents with hidden payloads.
    • 7z self-extracting archives and a Rust dropper install PDF decoys alongside CoreRAT.
    • CoreRAT fingerprints victims, exfiltrates system data over HTTPS, executes commands, downloads files, and self-deletes; sample SHA-256s include 604ffe14ab558bf79f00adbf050760ba5d0156ad7326586013c5d3fb3d7ef2f7 and 6ccfd6b2964f564ab1b308b1c6b4d78f994ec1e975f4e848620ebb302d3e70ac.
      📎 Coverage: cybersecuritynews.com · 👁 via Cyber Security News

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check