BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Cavalry Werewolf Cyberattack Targets Russian Public Sector Agencies

  • A threat actor called Cavalry Werewolf has targeted Russian public sector entities with Malware.
  • They use phishing emails impersonating Kyrgyz government officials to distribute FoalShell and StallionRAT malware.
  • The group has links to other Hacker clusters and may be affiliated with Kazakhstan.
  • StallionRAT uses a Telegram bot for commands like file upload and data exfiltration.
  • Analysis found at least 500 Russian companies compromised in the past year, mainly via public web applications.

A threat group known as Cavalry Werewolf has targeted Russian state agencies and enterprises in sectors like energy and mining with malware attacks from May to August 2025. The attackers used phishing emails disguised as official messages from Kyrgyz government officials to send malicious RAR archives containing FoalShell and StallionRAT malware.

- Advertisement -

Cybersecurity firm BI.ZONE said the attackers impersonated Kyrgyzstan government employees and in one case used a compromised legitimate email address linked to the Kyrgyz Republic’s regulatory authority. FoalShell is a lightweight reverse shell available in Go, C++, and C# versions that lets attackers run commands on infected systems via cmd.exe.

StallionRAT, also written in Go, PowerShell, and Python, allows operators to execute commands, upload files, and steal data using a Telegram bot interface. Commands include listing compromised hosts, running commands remotely, and uploading files. The attackers also deployed tools named ReverseSocks5Agent and ReverseSocks5 to gather device information.

BI.ZONE tracks Cavalry Werewolf as related to other clusters like SturgeonPhisher, Silent Lynx, Comrade Saiga, ShadowSilk, and Tomiris. The link to Tomiris supports the idea that the group may be Kazakhstan-affiliated. Earlier, Group-IB reported ShadowSilk attacks against government targets in Central Asia and Asia-Pacific using reverse proxy tools and remote access trojans written in Python and PowerShell.

The malware files carried English and Arabic filenames, suggesting a broader target range. BI.ZONE noted, “Cavalry Werewolf is actively experimenting with expanding its arsenal.” The firm emphasized the need to quickly identify new tools to defend against these evolving attacks.

- Advertisement -

Separately, BI.ZONE analyzed Hacking activity on Telegram and underground forums over the past year, finding at least 500 Russian companies compromised. Most victims were in commerce, finance, education, and entertainment sectors. In 86% of cases, attackers exploited public-facing web applications to gain access. They then installed tools like gs-netcat for persistent access and used legitimate database management utilities to extract data.

For more details, see the original BI.ZONE report and the related analysis on hacked Russian companies Russia-and-cis/”>here.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Ex-FTX engineer Nishad Singh fined $3.7 million

Former FTX head of engineering Nishad Singh settled a Commodity Futures Trading Commission (CFTC)...

Tether’s Jesse Spiro to Chair $100M Crypto Super PAC

Tether's Head of Government Affairs, Jesse Spiro, will chair the crypto-funded Fellowship PAC ahead...

CERT-UA Impersonated, New RAT Attack Hits Ukraine

The Computer Emergency Response Team of Ukraine (CERT-UA) was impersonated in a phishing campaign...

Binance Launches Oil and Gas Futures with 100x Leverage

Binance has officially launched trading for oil and natural gas futures contracts, completing its...

Franklin Templeton Buys 250 Digital to Launch Crypto Unit

Franklin Templeton is establishing a dedicated crypto unit, Franklin Crypto, through the acquisition of...

Must Read

The Best Bitcoin Casinos of 2025: An Expert’s Data-Driven Guide

Key TakeawaysA Deep Dive into the Top Bitcoin Casinos of 2025Bitcoin Casino Comparison Table1. Stake.com: Best for Variety & Integrated Sports Betting2. BC.Game: Best...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading