Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors eagle werewolf, energetic bear, velvet tempest, apt28, graycharlie

eagle werewolf, energetic bear, velvet tempest, apt28, graycharlie

TLP:CLEAR
Active

Also known as: tracked as

Description

Between February and May 2026, over 1,350 active command-and-control servers were identified across 98 infrastructure providers spanning 14 Middle Eastern countries. Saudi Arabia's STC hosted 981 C2 servers, representing 72.4% of all regional malicious infrastructure, the largest concentration globally. C2 infrastructure dominated at 96.8% of detected activity, with IoT-focused botnets like Hajime, Mozi, and Mirai, alongside offensive frameworks including Tactical RMM, Cobalt Strike, and Sliver representing the primary malware families. The infrastructure supported diverse operations from state-sponsored espionage campaigns like Eagle Werewolf targeting state entities, to Malware-as-a-Service platforms, cryptomining operations, and destructive attacks such as DYNOWIPER. Key providers included SERVERS TECH FZCO in UAE, OMC in Israel, Türk Telekom, and Regxa in Iraq, demonstrating how telecommunications giants and specialized hosting services enable both commodity cybercrime and advanced persistent threat op...

Goals & Targeting

Targeted Sectors

Energy
Government

AI Analysis

· 1 week ago

Executive Summary

The threat actor identified as Eagle Werewolf, Energetic Bear, Velvet Tempest, APT28, and Graycharlie is a nation-state actor known for sophisticated cyber espionage activities. Between February and May 2026, over 1,350 command-and-control (C2) servers were identified across 98 infrastructure providers in 14 Middle Eastern countries, with Saudi Arabia hosting the largest concentration of malicious infrastructure. This actor is linked to state-sponsored campaigns targeting energy and government sectors, utilizing advanced malware frameworks like Cobalt Strike and Sliver.

Goals & Targeting

Eagle Werewolf's primary strategic objectives appear to focus on state-sponsored espionage and disruption of critical national infrastructure. The actor's targeting profile reflects a deliberate focus on energy and government sectors, likely to gather sensitive information, disrupt operations, or cause physical and economic damage. The concentration of malicious infrastructure in Middle Eastern countries suggests a regional focus, possibly aligned with geopolitical interests or conflicts. Typical victims include state entities, energy companies, and organizations that serve as critical infrastructure nodes.

Enhanced Description

Eagle Werewolf, also known as Energetic Bear, Velvet Tempest, APT28, and Graycharlie, is a nation-state cyber threat actor engaged in high-profile espionage campaigns. The group has demonstrated significant operational capacity, leveraging extensive C2 infrastructure to support diverse activities, including state-sponsored espionage, destructive attacks such as DYNOWIPER, cryptomining, and malware-as-a-service (MaaS) operations. Between February and May 2026, over 1,350 active C2 servers were identified across 98 providers in 14 Middle Eastern countries. The majority of these servers were hosted by major telecommunications companies such as SERVERS TECH FZCO in the UAE and OMC in Israel, highlighting the use of high-profile hosting services to facilitate large-scale malicious activities. The actor's toolkit includes advanced frameworks like Cobalt Strike, Sliver, and Tactical RMM, as well as IoT-focused botnets such as Hajime, Mozi, and Mirai. This combination of capabilities allows Eagle Werewolf to target critical infrastructure sectors, including energy and government entities, with precision and persistence.

Key Capabilities

  • Sophisticated nation-state-level cyber espionage capabilities
  • Extensive command-and-control infrastructure
  • IoT botnet operations (Hajime, Mozi, Mirai)
  • Advanced persistent threat frameworks (Cobalt Strike, Sliver)
  • Destructive malware operations (e.g., DYNOWIPER)
  • Malware-as-a-Service (MaaS) capabilities

MITRE ATT&CK Tactics

RECON
ESPOionage
INFRA Disruption

ATT&CK Techniques

T1055
T1216
T1074
T1139

Software / Tooling

Cobalt Strike
Tactical RMM
Sliver
Hajime
Mozi
Mirai

Campaigns & Victims

Eagle Werewolf has been involved in several high-profile campaigns, including state-sponsored espionage targeting Middle Eastern governments and energy companies. The use of extensive C2 infrastructure indicates a high operational tempo and resource availability. Notable past operations include the deployment of DYNOWIPER malware for destructive attacks and the establishment of MaaS platforms. Campaign patterns suggest a preference for long-term persistence, modular toolsets, and regional targeting to maximize impact.

IOC Patterns

  • Spear-phishing campaigns with malicious Office documents
  • C2 infrastructure hosted by major telecommunications providers
  • IoT botnet activity (Hajime, Mozi, Mirai)
  • Destructive malware deployments

Recommended Actions

  • Monitor for C2 traffic originating from known malicious infrastructure providers
  • Implement strong perimeter defenses and network segmentation in critical sectors
  • Conduct regular threat hunting exercises focusing on nation-state APT indicators
  • Use threat intelligence feeds to block malicious domains and IP addresses
  • Enhance incident response capabilities to detect and mitigate destructive malware

Suggested Tags

APT
espionage
nation-state
energy-sector
government-targeting
destructive-malware

Confidence Assessment

High confidence in the actor's nation-state origin and targeting profile, based on extensive C2 infrastructure and known campaign patterns. The identification of specific malware frameworks and hosting providers further supports this assessment. However, gaps exist regarding the long-term strategic objectives and potential collaboration with other APT groups.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

1

IOCs

0

Observed Data

0

Tactics

Tags

APT
Backdoor / C2
DDoS
Wiper / Destructive
espionage
nation-state
energy-sector
government-targeting
destructive-malware

Details

Type
Nation-State
Primary Motivation
Espionage
Confidence
55%
Added
May 26, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.