New CoreRAT Malware Grants Full Control to Core Werewolf Hackers
Key Takeaways The Core Werewolf threat group is deploying a new custom remote access trojan (RAT) named CoreRAT. CoreRAT grants attackers extensive control over compromised Windows systems, including...
Key Takeaways
- The Core Werewolf threat group is deploying a new custom remote access trojan (RAT) named CoreRAT.
- CoreRAT grants attackers extensive control over compromised Windows systems, including data exfiltration and arbitrary command execution.
- Initial campaigns, observed between June and July 2026, primarily targeted Russia’s public sector and defense industry.
- The malware is delivered via Telegram phishing messages containing weaponized documents disguised as official government or military files.
- CoreRAT replaces the group’s prior use of legitimate remote access software, signaling a shift to more agile and evasive custom tooling.
Core Werewolf Unleashes CoreRAT, Escalating Threat to Russian Sectors
The Core Werewolf threat group has significantly upgraded its operational capabilities with the introduction of CoreRAT, a novel remote access trojan (RAT) designed to provide comprehensive control over infected Windows environments. This new malware marks a strategic evolution in the group’s arsenal, moving away from off-the-shelf tools to a bespoke solution.
Table Of Content
Observed in active campaigns from June to July 2026, and with evidence suggesting activity since March, CoreRAT represents a notable expansion of Core Werewolf’s attack toolkit. The group’s focus appears to be on entities within Russia’s public sector and defense industries.
Sophisticated Delivery Mechanisms
The infection chain typically begins with sophisticated phishing messages distributed via Telegram. These messages leverage highly convincing lures, often presenting themselves as official military or government documents. When a target opens these seemingly legitimate attachments, a decoy PDF is displayed to mask the simultaneous, covert installation of the CoreRAT malware.
Analysts at BI.ZONE said in a report that they identified this previously undocumented tool. Its deployment signifies a critical shift from Core Werewolf’s earlier reliance on legitimate remote access software, such as UltraVNC. The adoption of custom malware like CoreRAT offers the attackers greater flexibility, allowing for rapid modifications, enhanced stealth, and tailored functionality to suit their evolving objectives.
The delivery mechanisms employed by Core Werewolf include self-extracting 7z archives and a Rust-based dropper. Both methods are engineered to plant the CoreRAT payload alongside a benign decoy, ensuring the initial phase of the attack appears innocuous to the victim.
CoreRAT’s Advanced Functionality
CoreRAT, engineered in C++, incorporates robust obfuscation techniques, including the encryption of its internal text strings and command-and-control (C2) server addresses. A key feature of the malware is its anti-analysis capability: prior to execution, it actively scans for indicators of virtual test environments, such as system details, recent shortcut activity, and network adapter identifiers. If it detects a sandbox or virtual machine, CoreRAT terminates, preventing its behavior from being analyzed by researchers.
Upon successful execution on a legitimate target, CoreRAT initiates a reconnaissance phase, collecting critical system information. This includes the computer name, BIOS data, a list of running processes, desktop files, and network adapter details. This collected intelligence is then encoded, packaged, and exfiltrated over HTTPS to the group’s C2 server, providing the operators with an initial assessment of the compromised system’s value and potential for further exploitation.
The capabilities of CoreRAT extend beyond initial data collection. It can enumerate directories, inspect active processes, gather network configuration and ARP table data, and scrutinize active TCP connections. Furthermore, the RAT possesses the ability to execute arbitrary commands or processes, download and decrypt additional malicious files, and launch them. This comprehensive functionality transforms a successful infection into a launchpad for data theft, prolonged surveillance, or broader network intrusions.
CoreRAT also includes a self-deletion routine, designed to erase its presence after completing specified tasks. This process involves renaming the executable, creating a temporary batch file, and then deleting both components. This evasive tactic, coupled with encrypted configuration data, underscores the critical need for rapid incident response, forensic log preservation, and swift evidence collection during a suspected compromise.
Phishing Lures and Evasion Tactics
The 7z-based delivery chain strategically places a decoy PDF and the CoreRAT executable into distinct user directories before simultaneously opening both files. The Rust-based dropper unpacks a ZIP archive into a temporary directory, displays a decoy document, and employs a “ping” command to introduce a delay before executing the malware. This technique mirrors tactics seen in other campaigns, such as the MostereRAT Windows RAT, where seemingly harmless documents conceal remote access infections.
Researchers investigating the campaign noted several irregularities in the decoy documents, including unusual phrasing for official communications, evidence of document editing, and forged signatures. One particular PDF bore similarities to a file previously used by the Vortex Werewolf group, though insufficient evidence prevented a definitive link to shared infrastructure or group affiliation. These inconsistencies are often subtle, designed specifically to bypass casual scrutiny and lower a recipient’s guard.
What You Should Do
- Enhance Email and Messaging Security: Implement advanced threat protection solutions that scan incoming messages for malicious attachments and suspicious links, particularly on platforms like Telegram.
- Strengthen User Awareness Training: Conduct regular training sessions to educate employees about phishing tactics, the dangers of opening unexpected attachments, and how to identify forged documents or unusual phrasing.
- Implement Endpoint Detection and Response (EDR): Deploy EDR solutions to monitor endpoints for suspicious file names, hashes, and unexplained outbound HTTPS traffic, enabling rapid detection and response to potential compromises.
- Block Known Indicators of Compromise (IoCs): Integrate the provided SHA-256 and MD5 hashes, as well as the C2 domains and IP addresses, into your security information and event management (SIEM) systems, firewalls, and endpoint protection platforms to block known malicious entities.
- Isolate and Contain: In the event of a suspected compromise, immediately isolate affected devices from the network, reset potentially exposed credentials, and perform a thorough review of adjacent hosts for similar indicators of compromise.
- Preserve Forensic Evidence: Ensure that all logs and artifacts are quickly collected and preserved for detailed analysis following any suspected incident to understand the full scope of the breach and improve future defenses.
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | 604ffe14ab558bf79f00adbf050760ba5d0156ad7326586013c5d3fb3d7ef2f74661735db0f33dd567d29b2a056a967bb3762f831eb3678b27c4ffb06dbb8ec1465913946d4985ab60899ed2b7bc779ea83d08683c041d0e33b496358b684106b40b8978430ebbcbe8101ec51409fef86798d88e24287a1173fde2a106fd0d76d34eb87981cd144c0916b1e720b94dc22b52924b3358c32350a235925e7dfa7e |
7zSFX dropper samples |
| SHA-256 | 6ccfd6b2964f564ab1b308b1c6b4d78f994ec1e975f4e848620ebb302d3e70ac085db99b37298266b48dba20749c1567f99895b5ae3f60d3ea08047d3903542d |
Rust dropper samples |
| SHA-256 | 07956ee6bbd628bcaaefe36c4b01f3fe146b87df16bbbb6d884c5e5ab16088587a489dc1e1dc13ec35fb94b4faedcb294879c7fe3597888aec7ad3f516c1cc2002933405aac6676fd892ff311418877185bbaadc7151807f54a3bc3d6b75241d1402053d6edb096b59d8df3b81d56d5a30e6577f9022ef9b5dae910f328d0401909dfb4388334d66877debcb46d36c7d0a5a75c231241aa4c989ff0cafacc8f9722e7b896d5c6026af26ac368de2aed93ff341128478a6cd57849549abf773d2ea9600c3d62d807c07055f0951d08db03725417b9342a76e62410e26940500336f04ceb8d83ceb8b160314ac1829fba7054464006990e47a1493faf1185c2daba4f21177027e07280edf929adfd1403e0f4e7eb1892ca38069d45a9cd06e2929fe2cc8991ec22325283cd246856f7869caae0ff8b4d90cbbb734593b5b3d99ed |
CoreRAT payload samples |
| SHA-256 | 31ef487ed72e96d3d8ce50459e2d63786f51925b6e7fc4ede372e26ea7709a1cd447e296f7da71a05d38077ae27295151d56b6cd44ca272e731d702f7fe638925168fa34fb8e823f7329fb775b6c2cc3b41767524fc639452e93ec5c360e19a1491258e5d0131b0bb237c7221016c737af79961427c1f2fed9f80d75787b37c5dd94fbda84bd1dc9122dc7f6b2df1469f9e757f7ca577ba82d3ab4bc13d081641001dd82ed4e7ad59dfc4e5f4d9c6cd9937d47a6e59931d382926c0632de3be8a351d80e15c6ae88dd566939600162375441c538ee61be36bb81c93da182f |
Decoy PDF files |
| SHA-256 | c907b15b60fe77e42d3c37932f545e5d094370d5b709966a2fb572c5a6799660 |
Related Vortex Werewolf decoy PDF, Scan_125992145_TLG_na_perepodgotovku_dsp.pdf |
| MD5 | 1c69c262000994ac06ec153469eab55bdc8dc902852fff973c9c51cef62bb4baa29ba2ff5388d667cc353730075fba4bf34f4b89e95084d3a9b00b9c878fdfcab8d7886ca654a5e6feb3f9a56fa40b757228b3f08edb7754dec4d4e555fe8539 |
Decoy PDF hashes checked by CoreRAT before execution |
| MD5 | 09f192018e1a42f577d0f136b59e2888b90f78b83282a7c7ccf8b6f61ab4af4d6dbb3abbd19859c6f2771d7e320298187c3754bb07904de3708f1fae02bb9d0cad5f31bb0f53662c5ad659a3de2df2d0d4af404ee8b55fc40b3ef620d90396aaaf7ad3dbf7666a88e19d076efe858f499b4f048ec84b13d5138d937109f2cdb673a8ef0d8fb7960ce6a29c38190aec6df4a647575c4fd3cb3c29b2a69c3aa6fe907988b8337495e5245f3a01fd6fd121808157c74ecd47961c7d2d6f934d706f3cbb25f5f3a9ac6908d93cc58909536d729598a8473203c1938b69995d816c311406fb20fce3c82bd55616e7949e7aca6813c4f5170125d134a38ea2af45da97b6a7dc31b3e1059b227e032f35727ebd09c659fa24c98ba0f65c7a0369649903a5be3e5a8bd37feee8bcff7b5d4a4dba9e372e0f2356edd059af47e70044830ab3eef6b2ecb165e50d057e1e210d6558c2af530aff5108ab953eec30ec2399e70aaeb5c679e8f42e160248d5ef9e1d83bd128b66eb000fd08ada754ed9ceba2e3da4b2eaa2359e55bc33cca7468792ad65a9da2d23cf0baae86bd0be8d97ed03eee77075b5077c5abf03a9e09567ca082304e7a62565f45db890a341fb7a7d70305b6e15b0209a0684fc6d8352b4983965d112c2e2673d5fa5b22deb1b4a430e5bef05f58d53791fc49ee8d66f2cb652a2ef7d18d943af3c9dc6e9960f26ccbdbb7eae1628af407ed9fc0240e92eccfeb1410e77bfee794f52adc29e0ef9aed6d98ed128086144ef699ef7584f858aa1bc0608ca923518bb05bc00b608f377eb04028f5fd20a6fa60694962ae72bb96f4ced3337ca412a638a504e697caa954f3454030cd9b40280f1a0e7e585c0f639761f92ed3f949daa790b2cc96d2efbd50d003702bec166aec8f3869d53ccf89f9705d2d1c30b0ae4c4a50c6acb3a9dc83215f75e96dad896f961e13a23c5d17f3efbb378747d3e7d96d077ec6afefbc763ae279bcfc0babcab0539f44b97c76a800076766e58c0f4cfd8a929865a6c9e92d4dabf7348b0dad11c1295b030611dbf17c89f315e0b11a812a87783417c0f4b0c15b864b643c3a4ab38360c7c027afa3948732fef4f81dbc13102db6f641fa59c46d04b6274de33093e6d9f62f3348d4900aed87db884e183145d2a56ea92720e4c35995f95413d9d3d7ebe57d88f7c3835a540173253460763b19a4565fa |
Hashes used by Rust-dropper-linked CoreRAT samples to validate expected files |
| Domain | teambusiness-mail[.]ru:443xakklinkprik[.]ru:443dezinsekciya-top[.]ru:443ahmetgurses[.]net:443msgntfsys[.]link:443arendelle[.]ru:443sgpsib[.]ru:443 |
CoreRAT command-and-control infrastructure |
| IP address | 185.102.139[.]30:443130.49.181[.]212:443138.124.76[.]77:44395.81.125[.]145:443178.253.39[.]45:443104.128.129[.]184:44395.215.108[.]140:44345.128.150[.]49:443195.47.250[.]173:44391.212.150[.]141:4435.101.88[.]7:443194.190.153[.]182:44394.232.248[.]34:443 |
CoreRAT command-and-control infrastructure |
| File name | Scan_437_ТЛГ_на_переподготовку.exeисх1051_от_20.04.2026_сл паспорт.exeУказания-[redacted]_9f36b79847.exeУказания по [redacted]_498 от 15.06.2026_47.exe |
Malicious executable names used for delivery |
| File name | Firepoin.exeBaresl.exebrhost.exeBiostars.exeLiteEdit.exeintegrated.exeatrocity.exe |
CoreRAT payload names observed on victim hosts |
| File name | CyzG.pdfVppq.pdfEY5Tm.pdfr0po.pdfH5nY.pdfFOhf6.pdfavth.gGAT.pdf |
Decoy document file names used in the infection chain |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.