Cavalry Werewolf APT Hackers Attacking Multiple Industries with FoalShell and StallionRAT
## Cybersecurity: Cavalry Werewolf APT Campaign Overview
Cybersecurity: Cavalry Werewolf APT Campaign Overview
A sophisticated cyber campaign has targeted Russia's public sector and critical industries from May to August 2025. The group, known as Cavalry Werewolf APT, YoroTrooper, and Silent Lynx, has employed custom-built malware toolsets via targeted phishing operations exploiting trusted governmental relationships.
Targeted Industries and Attack Methods
The campaign mainly focuses on energy, mining, and manufacturing sectors, utilizing two primary malware families for persistent access and command execution. Spear-phishing emails, posing as official correspondence from Kyrgyz government entities like the Ministry of Economy and Commerce, are used to distribute RAR archives containing either FoalShell reverse shell or StallionRAT remote access trojan. These filenames mimic genuine official documents to deceive recipients.
Evidence suggests potential breaches of real official email accounts to enhance operational credibility. The malicious archives are typically downloaded to the %LocalAppData%\Microsoft\Windows\INetCache\Content.Outlook directory, offering a detection opportunity for security teams monitoring Outlook cache activity.
The campaign incorporates multi-language malware implementations, demonstrating technical versatility and a commitment to operational security. Malware variants have been developed in C#, C++, Go, PowerShell, and Python, each designed to evade detection while maintaining core command-and-control functionality.
A sophisticated cyber campaign has targeted Russia's public sector and critical industries from May to August 2025.
Desktop artifacts indicate potential expansion beyond Russian targets, with files in Tajik language suggesting interest in Tajikistan and Arabic-named documents pointing toward potential Middle Eastern reconnaissance. The discovery of AsyncRAT installer files highlights the group's evolving toolkit and ambitious operational scope.
FoalShell is a reverse shell designed to provide attackers with command-line access through cmd.exe on compromised systems. The C# variant establishes TCP connections to command-and-control servers, maintaining stealth through hidden window styles, while the C++ version employs sophisticated evasion techniques via shellcode loading mechanisms.
The Go implementation uses its networking stack to connect to C2 server 62.113.114.209 on port 443, running cmd.exe processes in hidden window states. This multi-language approach complicates detection for traditional signature-based security solutions.
For further details, visit the Picus Security blog .
Based on reporting by Cyber Security News.
