New “Cavalry Werewolf” Attack Hits Russian Agencies with FoalShell and StallionRAT

Oct 3, 2025

A threat actor that’s known to share overlaps with a hacking group called YoroTrooper has been observed targeting the Russian public sector with malware families such as FoalShell and StallionRAT.
Cybersecurity vendor BI.ZONE is tracking the activity under the moniker Cavalry Werewolf. It’s also assessed to have commonalities with clusters tracked as SturgeonPhisher, Silent Lynx, Comrade Saiga,

Get Free Report & Network Analysis

Please check your email for the free report.