Also known as: tracked as
Between February and May 2026, over 1,350 active command-and-control servers were identified across 98 infrastructure providers spanning 14 Middle Eastern countries. Saudi Arabia's STC hosted 981 C2 servers, representing 72.4% of all regional malicious infrastructure, the largest concentration globally. C2 infrastructure dominated at 96.8% of detected activity, with IoT-focused botnets like Hajime, Mozi, and Mirai, alongside offensive frameworks including Tactical RMM, Cobalt Strike, and Sliver representing the primary malware families. The infrastructure supported diverse operations from state-sponsored espionage campaigns like Eagle Werewolf targeting state entities, to Malware-as-a-Service platforms, cryptomining operations, and destructive attacks such as DYNOWIPER. Key providers included SERVERS TECH FZCO in UAE, OMC in Israel, Türk Telekom, and Regxa in Iraq, demonstrating how telecommunications giants and specialized hosting services enable both commodity cybercrime and advanced persistent threat op...
Targeted Sectors
Executive Summary
The threat actor identified as Eagle Werewolf, Energetic Bear, Velvet Tempest, APT28, and Graycharlie is a nation-state actor known for sophisticated cyber espionage activities. Between February and May 2026, over 1,350 command-and-control (C2) servers were identified across 98 infrastructure providers in 14 Middle Eastern countries, with Saudi Arabia hosting the largest concentration of malicious infrastructure. This actor is linked to state-sponsored campaigns targeting energy and government sectors, utilizing advanced malware frameworks like Cobalt Strike and Sliver.
Goals & Targeting
Eagle Werewolf's primary strategic objectives appear to focus on state-sponsored espionage and disruption of critical national infrastructure. The actor's targeting profile reflects a deliberate focus on energy and government sectors, likely to gather sensitive information, disrupt operations, or cause physical and economic damage. The concentration of malicious infrastructure in Middle Eastern countries suggests a regional focus, possibly aligned with geopolitical interests or conflicts. Typical victims include state entities, energy companies, and organizations that serve as critical infrastructure nodes.
Enhanced Description
Eagle Werewolf, also known as Energetic Bear, Velvet Tempest, APT28, and Graycharlie, is a nation-state cyber threat actor engaged in high-profile espionage campaigns. The group has demonstrated significant operational capacity, leveraging extensive C2 infrastructure to support diverse activities, including state-sponsored espionage, destructive attacks such as DYNOWIPER, cryptomining, and malware-as-a-service (MaaS) operations. Between February and May 2026, over 1,350 active C2 servers were identified across 98 providers in 14 Middle Eastern countries. The majority of these servers were hosted by major telecommunications companies such as SERVERS TECH FZCO in the UAE and OMC in Israel, highlighting the use of high-profile hosting services to facilitate large-scale malicious activities. The actor's toolkit includes advanced frameworks like Cobalt Strike, Sliver, and Tactical RMM, as well as IoT-focused botnets such as Hajime, Mozi, and Mirai. This combination of capabilities allows Eagle Werewolf to target critical infrastructure sectors, including energy and government entities, with precision and persistence.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Eagle Werewolf has been involved in several high-profile campaigns, including state-sponsored espionage targeting Middle Eastern governments and energy companies. The use of extensive C2 infrastructure indicates a high operational tempo and resource availability. Notable past operations include the deployment of DYNOWIPER malware for destructive attacks and the establishment of MaaS platforms. Campaign patterns suggest a preference for long-term persistence, modular toolsets, and regional targeting to maximize impact.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the actor's nation-state origin and targeting profile, based on extensive C2 infrastructure and known campaign patterns. The identification of specific malware frameworks and hosting providers further supports this assessment. However, gaps exist regarding the long-term strategic objectives and potential collaboration with other APT groups.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
1
IOCs
0
Observed Data
0
Tactics