Versatile Werewolf
Versatile Werewolf is a threat cluster tracked in campaigns using Starlink- and drone-themed lures to distribute malware, with targeting focused primarily on government organizations, military personnel, and individuals involved in drone manufacturing and engineering, consistent with espionage objectives. Known aliases in the provided content: versatile_werewolf / Versatile Werewolf. The cluster used malicious MSI installers masquerading as legitimate applications, including StarDebug_1.0.1.msi presented as an alternative Starlink terminal management application and AlphaFlyInstallV1-2.msi presented as a drone pilot training application. Distribution infrastructure directly mentioned in the content includes stardebug[.]app and alphafly-drones[.]com; the AlphaFly site mimicked betaflight.com and reused media from obriy[.]airforce. One observed intrusion chain used a multi-stage loader involving PowerShell, VBS, and a .NET loader, followed by an inner Inno Setup installer, to stage Fondue.exe together with a malicious APPWIZ.cpl in a hidden %PROGRAMDATA% directory. The actor abused the legitimate Windows utility Fondue.exe for DLL side-loading, causing it to load the rogue APPWIZ.cpl. The malicious APPWIZ.cpl was described as packed with UPX and protected with Oreans Code Virtualizer. When loaded, it deployed a Sliver implant in memory. The Sliver implant communicated with curtainbeatdisturbance[.]com, created the mutex MediumTurquoiseBeige, and established persistence via a scheduled task named in the format MicrosoftEdgeUpdateTaskMachineUA{GUID} that executed fondue.exe every minute. A second observed chain used the fake AlphaFly installer to drop a PowerShell loader and VBS launcher, display a decoy installation error, download Node.js if needed, and execute an obfuscated JavaScript loader that retrieved the final payload from newfolder[.]click. That payload was SoullessRAT, a JavaScript-based RAT previously linked in the content to the same cluster and reportedly written using generative AI. SoullessRAT capabilities directly mentioned in the content include remote command execution, file upload and download, screenshot capture, system information harvesting, Outlook data theft, directory or file listing, logical volume enumeration, module loading, and self-termination. The content explicitly links Versatile Werewolf to the Fondue.exe side-loading campaign and to SoullessRAT delivery, and notes the cluster has been observed using generative AI to accelerate development of its attack tools.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Government & Administration
- Military
- Capital Goods
Tradecraft
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
2 malware families attributed to this actor across reporting.
Observables
20 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a multi-stage espionage campaign that abuses the legitimate Windows binary Fondue.exe to side-load a malicious APPWIZ.cpl, deploy a Sliver implant, maintain persistence via scheduled tasks, and in parallel deploy SoullessRAT using fake Starlink and drone-themed applications as lures against sensitive targets.
Uses fake Starlink terminal management and drone training applications to deliver Sliver implants and SoullessRAT through MSI installers, PowerShell/VBS/.NET loaders, DLL side-loading, and staged JavaScript payloads.
Runs Starlink- and drone-themed malware campaigns using malicious MSI installers, PowerShell/VBS/.NET loaders, DLL side-loading, Sliver implants, and JS-based SoullessRAT delivery.
Операции по распространению вредоносных MSI-установщиков, маскируемых под ПО для управления терминалами Starlink и обучения пилотированию БПЛА, с доставкой Sliver и SoullessRAT через многостадийные PowerShell/JS-цепочки.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.