Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
NVIDIA NemoCLAW Critical Flaw Lets Attackers Hijack AI Agents
August 26, 2026
Google Chrome 127.0.6533.73 Patches 10 Critical Vulnerabilities
August 26, 2026
28,000 Git Repositories Exposed API Keys, Bank Details
August 26, 2026
Home/CyberSecurity News/New CoreRAT Malware Grants Full Control to Core Werewolf Hackers
CyberSecurity News

New CoreRAT Malware Grants Full Control to Core Werewolf Hackers

Key Takeaways The Core Werewolf threat group is deploying a new custom remote access trojan (RAT) named CoreRAT. CoreRAT grants attackers extensive control over compromised Windows systems, including...

Emy Elsamnoudy
Emy Elsamnoudy
August 26, 2026 5 Min Read
2 0

Key Takeaways

  • The Core Werewolf threat group is deploying a new custom remote access trojan (RAT) named CoreRAT.
  • CoreRAT grants attackers extensive control over compromised Windows systems, including data exfiltration and arbitrary command execution.
  • Initial campaigns, observed between June and July 2026, primarily targeted Russia’s public sector and defense industry.
  • The malware is delivered via Telegram phishing messages containing weaponized documents disguised as official government or military files.
  • CoreRAT replaces the group’s prior use of legitimate remote access software, signaling a shift to more agile and evasive custom tooling.

Core Werewolf Unleashes CoreRAT, Escalating Threat to Russian Sectors

The Core Werewolf threat group has significantly upgraded its operational capabilities with the introduction of CoreRAT, a novel remote access trojan (RAT) designed to provide comprehensive control over infected Windows environments. This new malware marks a strategic evolution in the group’s arsenal, moving away from off-the-shelf tools to a bespoke solution.

Table Of Content

  • Key Takeaways
  • Core Werewolf Unleashes CoreRAT, Escalating Threat to Russian Sectors
  • Sophisticated Delivery Mechanisms
  • CoreRAT’s Advanced Functionality
  • Phishing Lures and Evasion Tactics
  • What You Should Do

Observed in active campaigns from June to July 2026, and with evidence suggesting activity since March, CoreRAT represents a notable expansion of Core Werewolf’s attack toolkit. The group’s focus appears to be on entities within Russia’s public sector and defense industries.

Sophisticated Delivery Mechanisms

The infection chain typically begins with sophisticated phishing messages distributed via Telegram. These messages leverage highly convincing lures, often presenting themselves as official military or government documents. When a target opens these seemingly legitimate attachments, a decoy PDF is displayed to mask the simultaneous, covert installation of the CoreRAT malware.

Analysts at BI.ZONE said in a report that they identified this previously undocumented tool. Its deployment signifies a critical shift from Core Werewolf’s earlier reliance on legitimate remote access software, such as UltraVNC. The adoption of custom malware like CoreRAT offers the attackers greater flexibility, allowing for rapid modifications, enhanced stealth, and tailored functionality to suit their evolving objectives.

The delivery mechanisms employed by Core Werewolf include self-extracting 7z archives and a Rust-based dropper. Both methods are engineered to plant the CoreRAT payload alongside a benign decoy, ensuring the initial phase of the attack appears innocuous to the victim.

CoreRAT’s Advanced Functionality

CoreRAT, engineered in C++, incorporates robust obfuscation techniques, including the encryption of its internal text strings and command-and-control (C2) server addresses. A key feature of the malware is its anti-analysis capability: prior to execution, it actively scans for indicators of virtual test environments, such as system details, recent shortcut activity, and network adapter identifiers. If it detects a sandbox or virtual machine, CoreRAT terminates, preventing its behavior from being analyzed by researchers.

Upon successful execution on a legitimate target, CoreRAT initiates a reconnaissance phase, collecting critical system information. This includes the computer name, BIOS data, a list of running processes, desktop files, and network adapter details. This collected intelligence is then encoded, packaged, and exfiltrated over HTTPS to the group’s C2 server, providing the operators with an initial assessment of the compromised system’s value and potential for further exploitation.

The capabilities of CoreRAT extend beyond initial data collection. It can enumerate directories, inspect active processes, gather network configuration and ARP table data, and scrutinize active TCP connections. Furthermore, the RAT possesses the ability to execute arbitrary commands or processes, download and decrypt additional malicious files, and launch them. This comprehensive functionality transforms a successful infection into a launchpad for data theft, prolonged surveillance, or broader network intrusions.

CoreRAT also includes a self-deletion routine, designed to erase its presence after completing specified tasks. This process involves renaming the executable, creating a temporary batch file, and then deleting both components. This evasive tactic, coupled with encrypted configuration data, underscores the critical need for rapid incident response, forensic log preservation, and swift evidence collection during a suspected compromise.

Phishing Lures and Evasion Tactics

The 7z-based delivery chain strategically places a decoy PDF and the CoreRAT executable into distinct user directories before simultaneously opening both files. The Rust-based dropper unpacks a ZIP archive into a temporary directory, displays a decoy document, and employs a “ping” command to introduce a delay before executing the malware. This technique mirrors tactics seen in other campaigns, such as the MostereRAT Windows RAT, where seemingly harmless documents conceal remote access infections.

Researchers investigating the campaign noted several irregularities in the decoy documents, including unusual phrasing for official communications, evidence of document editing, and forged signatures. One particular PDF bore similarities to a file previously used by the Vortex Werewolf group, though insufficient evidence prevented a definitive link to shared infrastructure or group affiliation. These inconsistencies are often subtle, designed specifically to bypass casual scrutiny and lower a recipient’s guard.

What You Should Do

  • Enhance Email and Messaging Security: Implement advanced threat protection solutions that scan incoming messages for malicious attachments and suspicious links, particularly on platforms like Telegram.
  • Strengthen User Awareness Training: Conduct regular training sessions to educate employees about phishing tactics, the dangers of opening unexpected attachments, and how to identify forged documents or unusual phrasing.
  • Implement Endpoint Detection and Response (EDR): Deploy EDR solutions to monitor endpoints for suspicious file names, hashes, and unexplained outbound HTTPS traffic, enabling rapid detection and response to potential compromises.
  • Block Known Indicators of Compromise (IoCs): Integrate the provided SHA-256 and MD5 hashes, as well as the C2 domains and IP addresses, into your security information and event management (SIEM) systems, firewalls, and endpoint protection platforms to block known malicious entities.
  • Isolate and Contain: In the event of a suspected compromise, immediately isolate affected devices from the network, reset potentially exposed credentials, and perform a thorough review of adjacent hosts for similar indicators of compromise.
  • Preserve Forensic Evidence: Ensure that all logs and artifacts are quickly collected and preserved for detailed analysis following any suspected incident to understand the full scope of the breach and improve future defenses.
Type Indicator Description
SHA-256 604ffe14ab558bf79f00adbf050760ba5d0156ad7326586013c5d3fb3d7ef2f7
4661735db0f33dd567d29b2a056a967bb3762f831eb3678b27c4ffb06dbb8ec1
465913946d4985ab60899ed2b7bc779ea83d08683c041d0e33b496358b684106
b40b8978430ebbcbe8101ec51409fef86798d88e24287a1173fde2a106fd0d76
d34eb87981cd144c0916b1e720b94dc22b52924b3358c32350a235925e7dfa7e
7zSFX dropper samples
SHA-256 6ccfd6b2964f564ab1b308b1c6b4d78f994ec1e975f4e848620ebb302d3e70ac
085db99b37298266b48dba20749c1567f99895b5ae3f60d3ea08047d3903542d
Rust dropper samples
SHA-256 07956ee6bbd628bcaaefe36c4b01f3fe146b87df16bbbb6d884c5e5ab1608858
7a489dc1e1dc13ec35fb94b4faedcb294879c7fe3597888aec7ad3f516c1cc20
02933405aac6676fd892ff311418877185bbaadc7151807f54a3bc3d6b75241d
1402053d6edb096b59d8df3b81d56d5a30e6577f9022ef9b5dae910f328d0401
909dfb4388334d66877debcb46d36c7d0a5a75c231241aa4c989ff0cafacc8f9
722e7b896d5c6026af26ac368de2aed93ff341128478a6cd57849549abf773d2
ea9600c3d62d807c07055f0951d08db03725417b9342a76e62410e2694050033
6f04ceb8d83ceb8b160314ac1829fba7054464006990e47a1493faf1185c2dab
a4f21177027e07280edf929adfd1403e0f4e7eb1892ca38069d45a9cd06e2929
fe2cc8991ec22325283cd246856f7869caae0ff8b4d90cbbb734593b5b3d99ed
CoreRAT payload samples
SHA-256 31ef487ed72e96d3d8ce50459e2d63786f51925b6e7fc4ede372e26ea7709a1c
d447e296f7da71a05d38077ae27295151d56b6cd44ca272e731d702f7fe63
8925168fa34fb8e823f7329fb775b6c2cc3b41767524fc639452e93ec5c360e1
9a1491258e5d0131b0bb237c7221016c737af79961427c1f2fed9f80d75787b3
7c5dd94fbda84bd1dc9122dc7f6b2df1469f9e757f7ca577ba82d3ab4bc13d08
1641001dd82ed4e7ad59dfc4e5f4d9c6cd9937d47a6e59931d382926c0632de3
be8a351d80e15c6ae88dd566939600162375441c538ee61be36bb81c93da182f
Decoy PDF files
SHA-256 c907b15b60fe77e42d3c37932f545e5d094370d5b709966a2fb572c5a6799660 Related Vortex Werewolf decoy PDF, Scan_125992145_TLG_na_perepodgotovku_dsp.pdf
MD5 1c69c262000994ac06ec153469eab55b
dc8dc902852fff973c9c51cef62bb4ba
a29ba2ff5388d667cc353730075fba4b
f34f4b89e95084d3a9b00b9c878fdfca
b8d7886ca654a5e6feb3f9a56fa40b75
7228b3f08edb7754dec4d4e555fe8539
Decoy PDF hashes checked by CoreRAT before execution
MD5 09f192018e1a42f577d0f136b59e2888
b90f78b83282a7c7ccf8b6f61ab4af4d
6dbb3abbd19859c6f2771d7e32029818
7c3754bb07904de3708f1fae02bb9d0c
ad5f31bb0f53662c5ad659a3de2df2d0
d4af404ee8b55fc40b3ef620d90396aa
af7ad3dbf7666a88e19d076efe858f49
9b4f048ec84b13d5138d937109f2cdb6
73a8ef0d8fb7960ce6a29c38190aec6d
f4a647575c4fd3cb3c29b2a69c3aa6fe
907988b8337495e5245f3a01fd6fd121
808157c74ecd47961c7d2d6f934d706f
3cbb25f5f3a9ac6908d93cc58909536d
729598a8473203c1938b69995d816c31
1406fb20fce3c82bd55616e7949e7aca
6813c4f5170125d134a38ea2af45da97
b6a7dc31b3e1059b227e032f35727ebd
09c659fa24c98ba0f65c7a0369649903
a5be3e5a8bd37feee8bcff7b5d4a4dba
9e372e0f2356edd059af47e70044830a
b3eef6b2ecb165e50d057e1e210d6558
c2af530aff5108ab953eec30ec2399e7
0aaeb5c679e8f42e160248d5ef9e1d83
bd128b66eb000fd08ada754ed9ceba2e
3da4b2eaa2359e55bc33cca7468792ad
65a9da2d23cf0baae86bd0be8d97ed03
eee77075b5077c5abf03a9e09567ca08
2304e7a62565f45db890a341fb7a7d70
305b6e15b0209a0684fc6d8352b49839
65d112c2e2673d5fa5b22deb1b4a430e
5bef05f58d53791fc49ee8d66f2cb652
a2ef7d18d943af3c9dc6e9960f26ccbd
bb7eae1628af407ed9fc0240e92eccfe
b1410e77bfee794f52adc29e0ef9aed6
d98ed128086144ef699ef7584f858aa1
bc0608ca923518bb05bc00b608f377eb
04028f5fd20a6fa60694962ae72bb96f
4ced3337ca412a638a504e697caa954f
3454030cd9b40280f1a0e7e585c0f639
761f92ed3f949daa790b2cc96d2efbd5
0d003702bec166aec8f3869d53ccf89f
9705d2d1c30b0ae4c4a50c6acb3a9dc8
3215f75e96dad896f961e13a23c5d17f
3efbb378747d3e7d96d077ec6afefbc7
63ae279bcfc0babcab0539f44b97c76a
800076766e58c0f4cfd8a929865a6c9e
92d4dabf7348b0dad11c1295b030611d
bf17c89f315e0b11a812a87783417c0f
4b0c15b864b643c3a4ab38360c7c027a
fa3948732fef4f81dbc13102db6f641f
a59c46d04b6274de33093e6d9f62f334
8d4900aed87db884e183145d2a56ea92
720e4c35995f95413d9d3d7ebe57d88f
7c3835a540173253460763b19a4565fa
Hashes used by Rust-dropper-linked CoreRAT samples to validate expected files
Domain teambusiness-mail[.]ru:443
xakklinkprik[.]ru:443
dezinsekciya-top[.]ru:443
ahmetgurses[.]net:443
msgntfsys[.]link:443
arendelle[.]ru:443
sgpsib[.]ru:443
CoreRAT command-and-control infrastructure
IP address 185.102.139[.]30:443
130.49.181[.]212:443
138.124.76[.]77:443
95.81.125[.]145:443
178.253.39[.]45:443
104.128.129[.]184:443
95.215.108[.]140:443
45.128.150[.]49:443
195.47.250[.]173:443
91.212.150[.]141:443
5.101.88[.]7:443
194.190.153[.]182:443
94.232.248[.]34:443
CoreRAT command-and-control infrastructure
File name Scan_437_ТЛГ_на_переподготовку.exe
исх1051_от_20.04.2026_сл паспорт.exe
Указания-[redacted]_9f36b79847.exe
Указания по [redacted]_498 от 15.06.2026_47.exe
Malicious executable names used for delivery
File name Firepoin.exe
Baresl.exe
brhost.exe
Biostars.exe
LiteEdit.exe
integrated.exe
atrocity.exe
CoreRAT payload names observed on victim hosts
File name CyzG.pdf
Vppq.pdf
EY5Tm.pdf
r0po.pdf
H5nY.pdf
FOhf6.pdf
avth.gGAT.pdf
Decoy document file names used in the infection chain

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwarephishingSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical Microsoft SharePoint Flaws Let Attackers Hack Servers Remotely

Next Post

28,000 Git Repositories Exposed API Keys, Bank Details

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
OpenSSL Patches Multiple High-Severity Vulnerabilities
August 26, 2026
Linux at 35: From Hobby Project to Powering Global Cybersecurity
August 26, 2026
CISA Red Team Breaches Critical Infrastructure, Exposes SOC and Cloud Security Gaps
August 25, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us