The emergence of CoreRAT, a new remote access trojan, has provided the Core Werewolf hacking group with the ability to fully control compromised Windows systems. This malware was detected in operation between June and July 2026, with indications of activity dating back to March, marking a significant expansion in the group’s capabilities.
Phishing Tactics and Target Sectors
Using Telegram as a platform, the attackers distributed phishing messages that seemed legitimate, with files masquerading as official documents from military or government entities. Upon opening these files, victims were presented with a decoy PDF while the hidden malware was installed. The primary targets of these operations were within Russia’s public sector and defense industries.
BI.ZONE analysts have identified CoreRAT as a novel tool within the group’s arsenal, replacing previous use of legitimate remote access software like UltraVNC. The shift to custom malware such as CoreRAT enables hackers to modify it rapidly, evading detection and tailoring it to specific attacks.
Technical Analysis of CoreRAT
Developed in C++, CoreRAT encrypts its command-and-control addresses and internal text, which complicates analysis. Before executing, it checks for virtual environments, shutting down if detected to prevent analysis. On genuine systems, it gathers extensive data, including computer names, BIOS data, and network information, sending this encrypted data to its command server.
This malware’s capabilities extend to listing directories, inspecting processes, and collecting network configurations, allowing attackers to decide on subsequent actions, such as data theft or further compromise.
Delivery Methods and Deception
CoreRAT employs two delivery methods: a self-extracting 7z archive and a Rust-based dropper. Both techniques involve a decoy document to disguise the malicious activity. Such methods are reminiscent of the MostereRAT campaign, where benign-looking documents concealed remote access threats.
Decoy documents often contained unusual language and forged signatures, crafted to lower suspicion among recipients. Some files resembled those used by other hacking groups, yet lacked sufficient evidence of collaboration.
Preventive Measures and Recommendations
Organizations are advised to treat unexpected documents, especially those mimicking official notices, as potential threats. Security measures should include blocking suspicious network activities, monitoring endpoints for known file indicators, and scrutinizing outbound HTTPS traffic. Education and awareness are also crucial, as demonstrated by previous campaigns using trusted communication channels to disseminate malware.
Rapid detection and response are vital in minimizing damage. Affected devices should be isolated, credentials reset, and nearby hosts examined for similar indicators. Retaining evidence for further analysis is also crucial. Lessons from past campaigns underline the importance of scrutinizing all purported official documents.
