{"id":8454,"date":"2025-11-06T13:35:43","date_gmt":"2025-11-06T13:35:43","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=8454"},"modified":"2025-11-06T13:35:43","modified_gmt":"2025-11-06T13:35:43","slug":"cavalry-werewolf-hit-russian-authorities-with-new-shellnet-backdoor-hackread-cybersecurity-information-information-breaches-tech-ai-crypto-and-extra","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=8454","title":{"rendered":"Cavalry Werewolf Hit Russian Authorities with New ShellNET Backdoor \u2013 Hackread \u2013 Cybersecurity Information, Information Breaches, Tech, AI, Crypto and Extra"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"has-drop-cap\">Cybersecurity researchers at Physician Internet have found a focused assault in opposition to a Russian government-owned organisation carried out by a hacker group generally known as Cavalry Werewolf. <\/p>\n<p>The operation, which surfaced in July 2025, started after the organisation observed <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/google-tech-blocks-gmail-phishing-spam-emails\/\" data-type=\"post\" data-id=\"54045\" target=\"_blank\" rel=\"noreferrer noopener\">spam emails<\/a> being despatched from its personal company deal with, a crimson flag that led to an in-depth inside investigation.<\/p>\n<p>Physician Internet\u2019s researchers linked the incident to a phishing marketing campaign that used password-protected archives posing as respectable paperwork. Evaluation of these information revealed an unknown new backdoor, now tracked as <code>BackDoor.ShellNET.1<\/code>.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/11\/cavalry-werewolf-russia-government-shellnet-backdoor-2.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"474\" src=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/11\/cavalry-werewolf-russia-government-shellnet-backdoor-2-1024x474.png\" alt=\"Cavalry Werewolf Hit Russian Government with New ShellNET Backdoor\" class=\"wp-image-136883\" srcset=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/11\/cavalry-werewolf-russia-government-shellnet-backdoor-2-1024x474.png 1024w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/11\/cavalry-werewolf-russia-government-shellnet-backdoor-2-300x139.png 300w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/11\/cavalry-werewolf-russia-government-shellnet-backdoor-2-768x355.png 768w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/11\/cavalry-werewolf-russia-government-shellnet-backdoor-2-1536x711.png 1536w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/11\/cavalry-werewolf-russia-government-shellnet-backdoor-2-2048x948.png 2048w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/11\/cavalry-werewolf-russia-government-shellnet-backdoor-2-380x176.png 380w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/11\/cavalry-werewolf-russia-government-shellnet-backdoor-2-800x370.png 800w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/11\/cavalry-werewolf-russia-government-shellnet-backdoor-2-1160x537.png 1160w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/11\/cavalry-werewolf-russia-government-shellnet-backdoor-2.png 2120w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\"\/><\/a><figcaption class=\"wp-element-caption\">The phishing e mail used within the marketing campaign. The Russian-language screenshot was shared by Physician Internet, whereas the English model was translated by Hackread.com utilizing AI.<\/figcaption><\/figure>\n<\/div>\n<p>The backdoor, as per Physician Internet\u2019s technical <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.drweb.com\/show\/?i=15078&amp;lng=en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">report<\/a>, is predicated on open-source Reverse-Shell-CS code. As soon as executed, the malware opened a reverse shell connection, permitting attackers to run instructions remotely and deploy additional instruments.<\/p>\n<p>Researchers additional famous that the attackers used Home windows\u2019 built-in <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/bits\/bitsadmin-tool\" target=\"_blank\" rel=\"noreferrer noopener\">BITSAdmin<\/a> utility to obtain extra payloads, together with the <code>Trojan.FileSpyNET.5<\/code> infostealer. That device collected paperwork, spreadsheets, textual content information, and pictures from contaminated methods earlier than importing them to an exterior server. One other part, <code>BackDoor.Tunnel.41<\/code>, created a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/en.wikipedia.org\/wiki\/SOCKS\" target=\"_blank\" rel=\"noreferrer noopener\">SOCKS5 tunnel<\/a> for covert communication and distant management.<\/p>\n<p>Throughout the evaluation, Physician Internet\u2019s researchers additionally discovered that Cavalry Werewolf depends on open-source frameworks and customized backdoors written in C#, C++, and Golang. These instruments had been used for distant command execution, proxy tunnelling, stealing information, and persistence by Home windows registry edits and scheduled duties. <\/p>\n<p>Lots of the implants had been managed through <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/telegram-bots-stealing-one-time-passwords\/\" data-type=\"post\" data-id=\"88104\" target=\"_blank\" rel=\"noreferrer noopener\">Telegram bots<\/a>, an more and more frequent methodology for managing contaminated hosts whereas masking the attacker\u2019s infrastructure. Physician Internet additionally detected trojanized variations of well-liked utilities like WinRAR, 7-Zip, and Visible Studio Code, which had been used to launch secondary malware when opened. <\/p>\n<p>Cavalry Werewolf operators gathered system and consumer info utilizing customary Home windows instructions akin to <code>whoami<\/code>, <code>ipconfig \/all<\/code>, and <code>internet consumer<\/code>. Additionally they examine native information and community settings to plan the following stage of their assault. The researchers consider the hackers\u2019 purpose was to gather confidential info and inside community configurations.<\/p>\n<h3 id=\"who-is-cavalry-werewolf\" class=\"wp-block-heading\"><strong>Who&#8217;s Cavalry Werewolf<\/strong><\/h3>\n<p>Cavalry Werewolf first drew consideration when cybersecurity corporations <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/bi.zone\/eng\/expertise\/blog\/cavalry-werewolf-atakuet-rossiyu-cherez-doveritelnye-otnosheniya-mezhdu-gosudarstvami\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noticed<\/a> a marketing campaign from Might to August 2025 concentrating on Russian state companies and enormous industrial corporations in vitality, mining and manufacturing. The group used spear-phishing emails impersonating Kyrgyz authorities officers, which opened the door to malware deployment and distant entry.<\/p>\n<p>In its previous operations, the group deployed customized backdoors and proxy instruments, for instance, \u201cFoalShell\u201d and \u201cStallionRAT,\u201d for distant execution and information theft capabilities. Analysts additionally be aware overlaps in instruments and infrastructure with different clusters akin to Silent Lynx and YoroTrooper, which suggests Cavalry Werewolf could also be constructed on earlier actor foundations or cooperating with them.<\/p>\n<h3 id=\"look-before-you-leap-or-weep\" class=\"wp-block-heading\"><strong>Look Earlier than You Leap\u2026 or Weep<\/strong><\/h3>\n<p>Though the origins of the Cavalry Werewolf hackers stay unknown, Physician Internet\u2019s report concludes that the group retains including new instruments to its toolkit, reusing previous code and tweaking its malware for each new assault.<\/p>\n<p>The trojanized variations of well-known packages akin to WinRAR, 7-Zip, and Visible Studio Code are one other catastrophe ready to occur if the group shifts its focus from authorities networks to common customers. A single careless obtain might be sufficient at hand over full management of a system.<\/p>\n<p>That\u2019s why you must by no means obtain software program from third-party web sites, regardless of how convincing their opinions could sound. Keep away from putting in video games, mods, or utilities from unverified sources only for comfort. All the time use official platforms, and even then, run new information by <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/virustotal-apps-exploited-hackers-spread-malware\/\" data-type=\"post\" data-id=\"96828\" target=\"_blank\" rel=\"noreferrer noopener\">VirusTotal<\/a> and your antivirus earlier than putting in.<\/p>\n<p>The purpose isn\u2019t to scare you, it\u2019s to maintain you safe.<\/p>\n<p>\n\t\t\t<\/div>\n<p><template id="yYOvfXI4rowYy9Bk7HRF"></template><\/script><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers at Physician Internet have found a focused assault in opposition to a Russian government-owned organisation carried out by a hacker group generally known as Cavalry Werewolf. The operation, which surfaced in July 2025, started after the organisation observed spam emails being despatched from its personal company deal with, a crimson flag that led [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":8456,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[558,5449,6274,662,361,157,2789,6013,2080,121,538,6276,1173,6275],"class_list":["post-8454","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-backdoor","tag-breaches","tag-cavalry","tag-crypto","tag-cybersecurity","tag-data","tag-government","tag-hackread","tag-hit","tag-news","tag-russian","tag-shellnet","tag-tech","tag-werewolf"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/8454","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8454"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/8454\/revisions"}],"predecessor-version":[{"id":8455,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/8454\/revisions\/8455"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/8456"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8454"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8454"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8454"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-07-29 07:58:13 UTC -->