GOFFEE, also tracked as Paper Werewolf, is an espionage-focused threat actor active since at least 2022 and primarily known for sustained operations against organizations in Russia, later expanding to Belarus. The group has targeted government entities, information technology companies, media, telecommunications, construction, and energy organizations. Reporting also places GOFFEE activity against Russian defense enterprises. The actor’s victimology and tradecraft indicate a strong focus on intelligence collection, including theft of documents, configuration data, credentials, and files from removable media. GOFFEE relies heavily on spearphishing for initial access. Observed delivery chains have used malicious RAR archives, disguised executables, and Office documents with macros or remote template injection. Lures have included corrupted-looking documents and business-themed files designed to induce users to enable active content. In later campaigns, the group used multi-stage loaders that progressed through JScript, WMI, and hidden PowerShell execution to load final .NET payloads directly in memory. The actor is associated with custom tooling including PowerModul and PowerTaskel, the latter a Mythic agent used in GOFFEE intrusions since at least 2023. PowerModul has functioned as a downloader and tasking mechanism for additional payloads, including PowerTaskel, FlashFileGrabber, and a USB-propagating worm. FlashFileGrabber was used to steal files from removable media, while the USB worm enabled propagation and collection from attached drives. GOFFEE has also used modified system binaries, HTA and JavaScript chains, shellcode loaders, and custom binary Mythic agents for post-compromise operations. Post-exploitation behavior shows a mix of bespoke malware and hands-on-keyboard activity. GOFFEE has used legitimate administrative and system tools such as PowerShell, WMI, WinRM, PsExec, curl, wget, certutil, InstallUtil, and mshta, including bringing its own copy of mshta to victim environments. The group has performed host and user reconnaissance, searched for remote access, VPN, messaging, and database administration configurations, and modified installed software to redirect communications for command and control. Persistence has included Windows service installation and abuse of user logon execution mechanisms. Exfiltration has included covert transmission of command output through HTTP headers disguised as normal web traffic. GOFFEE has demonstrated lateral movement and privilege escalation through remote execution utilities and administrative protocols, including PsExec and WinRM. The group has also shown defense-evasion tradecraft through in-memory execution, fileless techniques, use of trusted application directories, and container-focused execution. A notable evolution in 2026 was the observation of a GOFFEE Mythic agent operating inside a Linux container, likely launched through a modified service script and executed from anonymous memory without writing an executable to disk. The actor has also been linked in some reporting to phishing and malware campaigns themed around Starlink access and drone-related software under the Paper Werewolf name, including EchoGather delivery and Telegram account phishing. Other reporting notes thematic and partial infrastructure overlap between GOFFEE and HeartlessSoul. Separately, GOFFEE traces have appeared in investigations of broader hacktivist or criminally tinged intrusions alongside groups such as 4BID, Hakerskii Kit, and C.A.S., but the exact nature of those relationships is not fully resolved. Overall, GOFFEE is a capable intrusion set centered on cyber espionage against Russian and Belarusian organizations, distinguished by persistent phishing operations, custom Mythic-based tooling, removable-media theft, living-off-the-land post-exploitation, and ongoing adaptation into newer environments such as containers.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
58 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
14 malware families attributed to this actor across reporting.
9 additional families tracked in Mallory.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
Analysis of the compromised environments revealed that the attackers gained initial access in most cases by exploiting the ProxyShell vulnerability in Microsoft Exchange, which allows for full server compromise.
In this blog post, I’ll be diving into the technical details of the WinRAR vulnerability, identified as CVE-2025-8088. This vulnerability carries a high severity score of 8.4 and affects WinRAR on Windows operating systems due to a path traversal flaw.
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...delivering RAR files that also took advantage of CVE-2025-6218, a different WinRAR flaw patched in June 2025.
150 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as using likely LLM-generated modules in operations targeting Russian defense enterprises.
Conducting phishing-led intrusions primarily against Russian IT companies, with expanded targeting into Belarus. The group uses malformed-looking lure documents to trigger remote template loading and macro execution, followed by in-memory payload delivery, hands-on-keyboard post-exploitation, living-off-the-land tooling, and stealthy exfiltration including data sent via the HTTP User-Agent header. The campaign also includes use of a Mythic agent inside a Linux container.
Conducting phishing-led intrusions primarily against technology-sector organizations, using remote template injection for initial access, custom and public tools for post-exploitation, credential/configuration harvesting, persistence via services, data exfiltration via HTTP User-Agent headers, and expanding operations into Linux container environments with Mythic agents.
APT targeting government, media, telecom, and energy sectors using PowerTaskel/PowerModul via Mythic, Ebowla packer, and C2 hosted on Russian providers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.