🕵️ RESEARCH & DEEP DIVES
- Core Werewolf Uses CoreRAT to Take Over Russian Windows Systems
Core Werewolf is deploying the CoreRAT remote-access trojan against Russian organizations.- Russia’s public-sector and defense organizations are targeted.
- CoreRAT is a previously undocumented C++ RAT for Windows systems.
- Telegram phishing delivers military- or government-themed documents with hidden payloads.
- 7z self-extracting archives and a Rust dropper install PDF decoys alongside CoreRAT.
- CoreRAT fingerprints victims, exfiltrates system data over HTTPS, executes commands, downloads files, and self-deletes; sample SHA-256s include 604ffe14ab558bf79f00adbf050760ba5d0156ad7326586013c5d3fb3d7ef2f7 and 6ccfd6b2964f564ab1b308b1c6b4d78f994ec1e975f4e848620ebb302d3e70ac.
📎 Coverage: cybersecuritynews.com · 👁 via Cyber Security News