HomeSecurityCavalry Werewolf: Attack on Russian companies with FoalShell & StallionRAT

Cavalry Werewolf: Attack on Russian companies with FoalShell & StallionRAT

A threat actor known for its connections to the hacking group YoroTrooperhas been observed targeting the Russian public sector with malware such as FoalShell and StallionRAT. Cybersecurity firm BI.ZONE is tracking the malicious activity under the name “Cavalry Werewolf.” According to experts, it shares common elements with groups also monitored as SturgeonPhisher, Silent Lynx, Comrade Saiga, ShadowSilk, and Tomiris.

Cavalry Werewolf FoalShell & StallionRAT

“ To gain initial access, the attackers sent targeted phishing emails, which were presented as official correspondence from Kyrgyz government officials ,” BI.ZONE reported . “ The main targets of the attacks were Russian state agencies, as well as energy, mining and manufacturing companies .”

See also: Cybercriminals imitate well-known brands to scam users

Cavalry Werewolf: Connecting with other groups

In August 2025, Group-IB uncovered attacks by ShadowSilk targeting government agencies in Central Asia and the Asia-Pacific (APAC) region, using reverse proxy tools and remote access trojans.

Cavalry Werewolf's ties to Tomiris are significant, as they reinforce the case that this is a threat actor linked to Kazakhstan. In a report late last year, Microsoft attributed the Tomiris backdoor to a Kazakhstan-based threat actor, tracked as Storm-0473.

Cavalry Werewolf's latest phishing attacks, observed between May and August 2025, involved sending emails using fake addresses and impersonating Kyrgyz government officials to distribute RAR files delivering FoalShell or StallionRAT.

In at least one case, the threat actor allegedly compromised a legitimate email address associated with the Kyrgyz Republic's regulatory authorityand sent the messages to the victims from that address.

See also: Hundreds of free VPN apps leak user data

Distribution of FoalShell and StallionRAT malware

FoalShell is a lightweight reverse shell that appears in Go, C++, and C# versions, allowing operators to execute arbitrary commands using cmd.exe.

Cavalry Werewolf: Attack on Russian companies with FoalShell & StallionRAT

StallionRAT is a similar malware (written in Go, PowerShell, and Python) that allows attackers to execute arbitrary commands, upload additional files, and extract collected data using a Telegram bot. Some of the commands supported by the bot include:

– /list: to get a list of compromised computers (DeviceID and computer name) connected to the command and control (C2) server
– /go [DeviceID] [command]: to execute the given command with Invoke-Expression
– /upload [DeviceID]: to upload a file to the victim’s device

Tools such as ReverseSocks5Agent and ReverseSocks5 are also run on compromised computers , as well as commands to collect device information .

The Russian cybersecurity firm said it also discovered various file names in English and Arabic, suggesting that Cavalry Werewolf's targeting may be broader than previously assumed.

See also: Hackers use WhatsApp to distribute SORVEPOTEL malware

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

“Cavalry Werewolf is actively experimenting with expanding its arsenal,” BI.ZONE reported. “This underscores the importance of quickly understanding the tools used by the cluster, otherwise it would be impossible to maintain up-to-date measures to prevent and detect such attacks.”

Cavalry Werewolf: Attack on Russian companies with FoalShell & StallionRAT

The revelation comes shortly after the company announced breaches at at least 500 companies in Russia over the past year. Most of these attacks involved the commerce, finance, education and entertainment sectors.

“In 86% of cases, attackers published data stolen from compromised public web applications,” he noted. “After gaining access to the public application, the attackers installed gs-netcat on the compromised server to ensure persistent access. Sometimes, the attackers loaded additional web shells. They also used legitimate tools such as Adminer, phpMiniAdmin, and mysqldump to extract data from databases.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS