Fluffy Wolf is a financially motivated cybercriminal threat actor known for phishing-led intrusions against organizations in Russia. Between March and May 2026, the group conducted campaigns against companies in construction, consulting, engineering, retail, e-commerce, manufacturing, and broader industrial sectors. Its lures impersonated routine business communications such as debt notices, reconciliation statements, and legal or financial claims, often posing as partners or contractors. The actor relies heavily on commodity and malware-as-a-service tooling rather than bespoke malware development. Observed delivery chains used malicious archives and links to externally hosted archives to evade email filtering and network defenses. Fluffy Wolf has deployed PureCrypter, Rust-based loaders using Donut shellcode, and a C++ downloader referred to as PowerLoader. PowerLoader operates largely filelessly, launches hidden PowerShell to retrieve additional scripts, and is used to stage subsequent payload delivery. Payloads associated with Fluffy Wolf operations include the Pay2Key ransomware, the PureLogs information stealer, and PureRAT. PureLogs has been used to harvest credentials, cookies, browser history, and other application data, while operators separated exfiltrated data by category for downstream processing. PureRAT activity included use of the PluginRemoteDesktop module, enabling remote desktop surveillance and interaction such as screen capture, active-window monitoring, and mouse and keyboard control. The group has also used process injection into legitimate Windows utilities to blend malicious execution with trusted processes and improve defense evasion. In ransomware incidents, Pay2Key exhibited anti-forensic self-deletion behavior by overwriting its executable before removal, complicating incident response and reverse engineering.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting phishing-led intrusion campaigns against Russian organizations, using deceptive debt/legal-themed emails, GitHub links, malicious RAR attachments, loaders and stealers, and in some cases deploying Pay2Key ransomware for financial extortion.
Conducting phishing-led intrusions against Russian companies across construction, consulting, engineering, retail, e-commerce, and industrial sectors, using MaaS-purchased loaders, stealers, RATs, and ransomware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.