Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to malware
MalwareUsed by 2 actors

SoullessRAT

SoullessRAT is an obfuscated JavaScript remote access trojan reportedly written using generative AI. It was observed in multi-stage campaigns linked in the reporting to the Versatile Werewolf threat cluster, and also referenced alongside activity associated with Eagle Werewolf. In the described intrusion chain, it was delivered via the fake drone-training installer AlphaFlyInstallV1-2.msi distributed from alphafly-drones[.]com. That chain dropped PowerShell and VBS components, downloaded Node.js if needed, executed an obfuscated JavaScript loader, and retrieved the final SoullessRAT payload from newfolder[.]click, including the URL pattern hxxps://newfolder[.]click/?cid=9ebeb834a451460e&mod=main. Reported capabilities include remote command execution, file upload and download, screenshot capture, system information harvesting and reconnaissance, module loading, Outlook data theft, logical volume enumeration, directory and file listing, and self-termination. The surrounding campaigns primarily targeted government or state organizations, military personnel, industrial entities, and individuals involved in drone manufacturing, engineering, or UAV-related activity, consistent with espionage objectives. Known associated delivery artifacts and lures include AlphaFlyInstallV1-2.msi and the fake AlphaFly installer infrastructure at alphafly-drones[.]com, with payload delivery from newfolder[.]click.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Versatile Werewolf

This final stage payload is an obfuscated JavaScript RAT created using generative AI. We named this trojan SoullessRAT.

Eagle Werewolf

Malware Family SoullessRAT Delivered via fake AlphaFly installer in Eagle Werewolf multi-stage attack chain

via cyber security newscybersecuritynews.com
MITRE ATT&CK

Techniques & procedures

23 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

3 techniques
T1189Drive-by CompromiseEvidence1

The attack chain begins with a malicious MSI installer, disguised as a legitimate software application, delivered to targeted users through deceptive websites mimicking real developer tools.

T1566PhishingEvidence1

A separate espionage campaign linked to the Eagle Werewolf cluster used Iraqi hosting on Regxa infrastructure to deploy multiple remote access tools via phishing lures based on Starlink registration and drone training themes.

T1566.002Spearphishing LinkEvidence1

used Iraqi hosting on Regxa infrastructure to deploy multiple remote access tools via phishing lures based on Starlink registration and drone training themes.

Execution

6 techniques
T1059Command and Scripting InterpreterEvidence1

The loader then fetches the Node.js interpreter (if it is not present in the system) and the next stage obfuscated JS script. Upon downloading all the components, the Node.js interpreter executes the JS script.

T1059.001PowerShellEvidence3

run-script.ps1, a PowerShell script to load and execute code via PowerShell. The file contains: powershell -w hidden -ep bypass -c "I''E''X...DOWNLOADDaTa(...)"

T1059.005Visual BasicEvidence2

helper.vbs, a VBS file ... that executes run-script.ps1.

T1059.007JavaScriptEvidence4

Alongside the Fondue.exe-based attack path, the same threat cluster also deployed a separate JavaScript-based remote access trojan named SoullessRAT against other targets.

T1204User ExecutionEvidence1

Upon execution, StarDebug_1.0.1.msi creates the directory %LOCALAPPDATA%\Star and extracts the following three files to it...

T1204.002Malicious FileEvidence3

The URL hxxps://battleflight[.]org/download/installer hosted the executable BattleFlight-Install-v11.0.3.exe, a C# dropper disguised as an installer for a drone pilot training simulator.

Stealth

4 techniques
T1027Obfuscated Files or InformationEvidence3

The appwiz.cpl applet is packed with UPX and obfuscated with Oreans Code Virtualizer.

T1027.013Encrypted/Encoded FileEvidence1

The dropper contains the EchoGather payload, which is Base64-encoded and XOR-encrypted.

T1036MasqueradingEvidence4

The attack chain begins with a malicious MSI installer, disguised as a legitimate software application, delivered to targeted users through deceptive websites mimicking real developer tools.

T1140Deobfuscate/Decode Files or InformationEvidence1

the C# dropper contains the EchoGather payload, which is Base64-encoded and XOR-encrypted.

Discovery

2 techniques
T1082System Information DiscoveryEvidence4

SoullessRAT was reportedly written using generative AI, and it supports a broad range of espionage capabilities including remote command execution, file uploads to the attacker’s server, screenshot capture, and harvesting of system information.

T1083File and Directory DiscoveryEvidence2

ScanFiles ... The following fields are sent to the endpoint /clients/files: fileName relativePath fullPath fileSize createdDate modifiedDate

Collection

3 techniques
T1005Data from Local SystemEvidence2

Files, uploads a directory/file from the host to the C2 server.

T1113Screen CaptureEvidence4

SoullessRAT was reportedly written using generative AI, and it supports a broad range of espionage capabilities including remote command execution, file uploads to the attacker’s server, screenshot capture, and harvesting of system information.

T1114Email CollectionEvidence1

Key capabilities of SoullessRAT ... downloads and runs modules for self-destruction, SSH, and data harvesting from the Outlook mail client

Command and Control

4 techniques
T1071Application Layer ProtocolEvidence1

more than 1,350 active command-and-control (C2) servers were identified across 98 infrastructure providers in the region within just three months.

T1071.001Web ProtocolsEvidence3

The C2 server is queried every 15 seconds.

T1105Ingress Tool TransferEvidence4

The initial MSI installer drops a PowerShell script, a VBS helper file, and a .NET loader, which work together to download and execute the next-stage payload without triggering obvious alerts.

T1219Remote Access ToolsEvidence1

Once loaded into the memory space of Fondue.exe, the rogue control panel file deploys a Sliver post-exploitation framework implant. Sliver is an open-source adversary simulation tool that gives attackers a powerful foothold on the infected machine, allowing them to issue remote commands and move through compromised networks with ease.

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence2

SoullessRAT was reportedly written using generative AI, and it supports a broad range of espionage capabilities including remote command execution, file uploads to the attacker’s server, screenshot capture, and harvesting of system information.

INDICATORS OF COMPROMISE

IOCs tracked for this family

12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
5 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
4 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
3 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app9 days ago
domain●●●●●●●●●●●●View more in app9 days ago
domain●●●●●●●●●●●●View more in app9 days ago
domain●●●●●●●●●●●●View more in app9 days ago
hash.sha256●●●●●●●●●●●●View more in app9 days ago
hash.sha256●●●●●●●●●●●●View more in app9 days ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching12

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping23

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.