New CoreRAT Malware Gives Core Werewolf Hackers Full Control of Compromised Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

A new remote access trojan called CoreRAT is giving the Core Werewolf threat group a way to take over infected Windows systems.

The malware appeared in campaigns observed from June through July 2026, though evidence shows it has been active since at least March. Its arrival marks an expansion of the group’s toolkit.

The attackers used phishing messages on Telegram to reach targets, then relied on files dressed up as official military or government documents.

Victims who opened the attachments received a PDF decoy while a hidden program installed the malware. The operation is believed to have focused on Russia’s public sector and defense industry.

BI.ZONE analysts identified the previously undocumented tool and said it replaced the group’s earlier use of legitimate UltraVNC remote access software.

This change matters because custom malware can be altered quickly, made harder to spot, and adapted to the attackers’ needs.

BI.ZONE said in a report shared with Cyber Security News (CSN) that CoreRAT is the group’s first fully functional remote access trojan. The campaign shows how familiar documents can turn routine communication into a security risk.

Decoy FOhf6.pdf (Source - Bi.Zone)
Decoy FOhf6.pdf (Source – Bi.Zone)

Core Werewolf used two delivery programs, including a self-extracting 7z archive and a Rust-based dropper. Both planted a decoy alongside the payload, helping the attack look harmless when it begins.

New CoreRAT Malware

CoreRAT is written in C++ and encrypts its internal text and command-and-control addresses. Before it runs, it looks for signs that it is inside a virtual test machine, checking system details, recent shortcut activity, and network adapter identifiers.

If it suspects analysis, it shuts down instead of revealing its behavior. On a real victim machine, the malware collects the computer name, BIOS data, running processes, desktop files, and network adapter information.

It packages the results, encodes them, and sends them over HTTPS to its command server. That gives operators an early picture of the system and its likely value to the attackers. The data can help attackers decide what to steal or run next.

The tool can list folders, inspect processes, collect network configuration and ARP data, and review active TCP connections.

In addition, it can run a supplied command or process, download additional files, decrypt them, and launch them. This means a successful infection can become a starting point for theft, surveillance, or a wider intrusion.

Decoy avth.gGAT.pdf (Source - Bi.Zone)
Decoy avth.gGAT.pdf (Source – Bi.Zone)

CoreRAT can also delete itself after completing a task. Its removal routine renames the executable, creates a temporary batch file, and erases both pieces once the removal is complete.

That behavior, combined with encrypted configuration data, reinforces why teams investigating a suspected compromise should preserve logs and collect evidence quickly.

Telegram Lures Mask Delivery

The 7z-based delivery chain copied a decoy PDF and the CoreRAT executable into different user folders before opening both.

The Rust version unpacked a ZIP archive into the temporary directory, displayed a document, and delayed execution using a ping command. This approach resembles the MostereRAT Windows RAT campaign, where an apparent document conceals a remote-access infection.

Researchers found several decoys that carried wording unusual for official communications, traces of document editing, and forged signatures.

One PDF also resembled a file used by Vortex Werewolf, but the evidence was not sufficient to confirm a shared group or infrastructure. The documents were designed to lower a recipient’s suspicion.

Organizations should treat unexpected document files, especially executables made to resemble official notices, as potential threats.

Security teams should block network indicators, monitor endpoints for file names and hashes, and investigate unexplained outbound HTTPS traffic.

User awareness also remains important, as shown by the LinkedIn remote access campaign, which used trusted messaging to push weaponized archives.

Fast detection and containment are central to limiting harm. Teams should isolate affected devices, reset credentials where exposure is possible, review nearby hosts for the same indicators, and retain artifacts for analysis.

Defenders can also apply lessons from the Google Cloud Remcos campaign, while court-themed lures in the covert RAT court campaign underline why every claimed official document needs scrutiny.

Indicators of compromise (IoCs):-

Type Indicator Description
SHA-256 604ffe14ab558bf79f00adbf050760ba5d0156ad7326586013c5d3fb3d7ef2f7
4661735db0f33dd567d29b2a056a967bb3762f831eb3678b27c4ffb06dbb8ec1
465913946d4985ab60899ed2b7bc779ea83d08683c041d0e33b496358b684106
b40b8978430ebbcbe8101ec51409fef86798d88e24287a1173fde2a106fd0d76
d34eb87981cd144c0916b1e720b94dc22b52924b3358c32350a235925e7dfa7e
7zSFX dropper samples
SHA-256 6ccfd6b2964f564ab1b308b1c6b4d78f994ec1e975f4e848620ebb302d3e70ac
085db99b37298266b48dba20749c1567f99895b5ae3f60d3ea08047d3903542d
Rust dropper samples
SHA-256 07956ee6bbd628bcaaefe36c4b01f3fe146b87df16bbbb6d884c5e5ab1608858
7a489dc1e1dc13ec35fb94b4faedcb294879c7fe3597888aec7ad3f516c1cc20
02933405aac6676fd892ff311418877185bbaadc7151807f54a3bc3d6b75241d
1402053d6edb096b59b8df3b81d56d5a30e6577f9022ef9b5dae910f328d0401
909dfb4388334d66877debcb46d36c7d0a5a75c231241aa4c989ff0cafacc8f9
722e7b896d5c6026af26ac368de2aed93ff341128478a6cd57849549abf773d2
ea9600c3d62d807c07055f0951d08db03725417b9342a76e62410e2694050033
6f04ceb8d83ceb8b160314ac1829fba7054464006990e47a1493faf1185c2dab
a4f21177027e07280edf929adfd1403e0f4e7eb1892ca38069d45a9cd06e2929
fe2cc8991ec22325283cd246856f7869caae0ff8b4d90cbbb734593b5b3d99ed
CoreRAT payload samples
SHA-256 31ef487ed72e96d3d8ce50459e2d63786f51925b6e7fc4ede372e26ea7709a1c
d447e296f7da71a05d38077ae27295519151d56b6cd44ca272e731d702f7fe63
8925168fa34fb8e823f7329fb775b6c2cc3b41767524fc639452e93ec5c360e1
9a1491258e5d0131b0bb237c7221016c737af79961427c1f2fed9f80d75787b3
7c5dd94fbda84bd1dc9122dc7f6b2df1469f9e757f7ca577ba82d3ab4bc13d08
1641001dd82ed4e7ad59dfc4e5f4d9c6cd9937d47a6e59931d382926c0632de3
be8a351d80e15c6ae88dd566939600162375441c538ee61be36bb81c93da182f
Decoy PDF files
SHA-256 c907b15b60fe77e42d3c37932f545e5d094370d5b709966a2fb572c5a6799660 Related Vortex Werewolf decoy PDF, Scan_125992145_TLG_na_perepodgotovku_dsp.pdf
MD5 1c69c262000994ac06ec153469eab55b
dc8dc902852fff973c9c51cef62bb4ba
a29ba2ff5388d667cc353730075fba4b
f34f4b89e95084d3a9b00b9c878fdfca
b8d7886ca654a5e6feb3f9a56fa40b75
7228b3f08edb7754dec4d4e555fe8539
Decoy PDF hashes checked by CoreRAT before execution
MD5 09f192018e1a42f577d0f136b59e2888
b90f78b83282a7c7ccf8b6f61ab4af4d
6dbb3abbd19859c6f2771d7e32029818
7c3754bb07904de3708f1fae02bb9d0c
ad5f31bb0f53662c5ad659a3de2df2d0
d4af404ee8b55fc40b3ef620d90396aa
af7ad3dbf7666a88e19d076efe858f49
9b4f048ec84b13d5138d937109f2cdb6
73a8ef0d8fb7960ce6a29c38190aec6d
f4a647575c4fd3cb3c29b2a69c3aa6fe
907988b8337495e5245f3a01fd6fd121
808157c74ecd47961c7d2d6f934d706f
3cbb25f5f3a9ac6908d93cc58909536d
729598a8473203c1938b69995d816c31
1406fb20fce3c82bd55616e7949e7aca
6813c4f5170125d134a38ea2af45da97
b6a7dc31b3e1059b227e032f35727ebd
09c659fa24c98ba0f65c7a0369649903
a5be3e5a8bd37feee8bcff7b5d4a4dba
9e372e0f2356edd059af47e70044830a
b3eef6b2ecb165e50d057e1e210d6558
c2af530aff5108ab953eec30ec2399e7
0aaeb5c679e8f42e160248d5ef9e1d83
bd128b66eb000fd08ada754ed9ceba2e
3da4b2eaa2359e55bc33cca7468792ad
65a9da2d23cf0baae86bd0be8d97ed03
eee77075b5077c5abf03a9e09567ca08
2304e7a62565f45db890a341fb7a7d70
305b6e15b0209a0684fc6d8352b49839
65d112c2e2673d5fa5b22deb1b4a430e
5bef05f58d53791fc49ee8d66f2cb652
a2ef7d18d943af3c9dc6e9960f26ccbd
bb7eae1628af407ed9fc0240e92eccfe
b1410e77bfee794f52adc29e0ef9aed6
d98ed128086144ef699ef7584f858aa1
bc0608ca923518bb05bc00b608f377eb
04028f5fd20a6fa60694962ae72bb96f
4ced3337ca412a638a504e697caa954f
3454030cd9b40280f1a0e7e585c0f639
761f92ed3f949daa790b2cc96d2efbd5
0d003702bec166aec8f3869d53ccf89f
9705d2d1c30b0ae4c4a50c6acb3a9dc8
3215f75e96dad896f961e13a23c5d17f
3efbb378747d3e7d96d077ec6afefbc7
63ae279bcfc0babcab0539f44b97c76a
800076766e58c0f4cfd8a929865a6c9e
92d4dabf7348b0dad11c1295b030611d
bf17c89f315e0b11a812a87783417c0f
4b0c15b864b643c3a4ab38360c7c027a
fa3948732fef4f81dbc13102db6f641f
a59c46d04b6274de33093e6d9f62f334
8d4900aed87db884e183145d2a56ea92
720e4c35995f95413d9d3d7ebe57d88f
7c3835a540173253460763b19a4565fa
Hashes used by Rust-dropper-linked CoreRAT samples to validate expected files
Domain teambusiness-mail[.]ru:443
xakklinkprik[.]ru:443
dezinsekciya-top[.]ru:443
ahmetgurses[.]net:443
msgntfsys[.]link:443
arendelle[.]ru:443
sgpsib[.]ru:443
CoreRAT command-and-control infrastructure
IP address 185.102.139[.]30:443
130.49.181[.]212:443
138.124.76[.]77:443
95.81.125[.]145:443
178.253.39[.]45:443
104.128.129[.]184:443
95.215.108[.]140:443
45.128.150[.]49:443
195.47.250[.]173:443
91.212.150[.]141:443
5.101.88[.]7:443
194.190.153[.]182:443
94.232.248[.]34:443
CoreRAT command-and-control infrastructure
File name Scan_437_ТЛГ_на_переподготовку.exe
исх1051_от_20.04.2026_сл паспорт.exe
Указания-[redacted]_9f36b79847.exe
Указания по [redacted]_498 от 15.06.2026_47.exe
Malicious executable names used for delivery
File name Firepoin.exe
Baresl.exe
brhost.exe
Biostars.exe
LiteEdit.exe
integrated.exe
atrocity.exe
CoreRAT payload names observed on victim hosts
File name CyzG.pdf
Vppq.pdf
EY5Tm.pdf
r0po.pdf
H5nY.pdf
FOhf6.pdf
avth.gGAT.pdf
Decoy document file names used in the infection chain

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post New CoreRAT Malware Gives Core Werewolf Hackers Full Control of Compromised Systems appeared first on Cyber Security News.