Feral Wolf is a cybercriminal ransomware group that conducted intrusions against Russian retail, construction, manufacturing, and information-technology organizations between May and August 2026. The group gained initial access by exploiting CVE-2023-22515 in externally exposed Atlassian Confluence instances and by abusing insecure, internet-accessible 1C:Enterprise server clusters, including unauthenticated administrative interfaces and debug functionality. In one observed intrusion, Feral Wolf pivoted from a compromised Confluence container to its underlying host through a weak PostgreSQL password. Feral Wolf conducts network and service discovery, creates or abuses administrative accounts, executes operating-system commands through compromised enterprise applications, and uses credential material recovered from Windows memory. It has used MQTTDoor and MatrixDoor Rust backdoors for command-and-control, GSocket for remote access and persistence, and RDPSocksProxy to tunnel traffic through active RDP sessions. The group has also used local privilege-escalation tooling, including PrintSpoofer, and attempted to conceal activity by disguising processes and clearing forensic artifacts with anti-forensic PowerShell tooling. Its observed operations culminated in deployment of GenieLocker ransomware to encrypt victim data. No data-exfiltration or extortion component is confirmed. Known aliases: feral_wolf.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
23 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Groupe cybercriminel menant des intrusions et des opérations de ransomware contre des organisations russes. Il exploite des applications exposées et des configurations faibles de 1C:Enterprise, déploie des portes dérobées et des proxys pour persister et se déplacer, vole des identifiants, efface des traces, puis chiffre les données avec GenieLocker.
Ransomware operation targeting Russian organizations. It gains initial access through exposed and vulnerable business applications, weak credentials, and insecure 1C:Enterprise configurations; conducts network discovery and credential theft; deploys covert MQTT- and Matrix-based backdoors; and ultimately encrypts data with GenieLocker.
Ransomware activity against Russian organizations that combines exploitation of exposed Confluence and insecure 1C:Enterprise clusters, weak or stolen credentials, network discovery, custom backdoors, credential theft, defense evasion, remote-access tunneling, and GenieLocker data encryption.
Conducted intrusions against Russian organizations, obtaining initial access through exploitation of exposed Atlassian Confluence and insecure 1C:Enterprise cluster configurations, as well as contractor infrastructure. The group performed container escape and lateral movement, credential access through LSASS memory-dump collection and analysis, covert C2 over MQTT and Matrix, persistence through disguised services and GSocket deployments, RDP-based SOCKS tunneling, forensic-artifact removal, and data encryption with GenieLocker ransomware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.