Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors clubfoot wolf

Also known as: Lone Wolf, Moonshine Trickster, APT28, tracked as, congenital talipes equinovarus, Head Mare, 21, 2026, Kyrgyzstan, Kazakhstan, defense industries, Awaken Likho, Bearlyfy, Librarian Ghouls, Librarian Likho, Rezet, Core Werewolf, Ratopak Spider, UAC-0008, Romania, Fancy Bear, UAC-0001, its NATO allies, Outrider Tiger, Fishing Elephant, Earth Vetala, MERCURY, Mango Sandstorm, Static Kitten, including diplomatic, maritime, financial, telecom entities, Archer RAT, RUSTRIC, detects installed security software, establishes contact with a, CHAR, Olalampo, Storm-0842, DUNE, Red Sandstorm, Bloody Wolf, SkyCloak, laboo.boo, Void Arachne, Watch Wolf, Forest Blizzard, TA450, MuddyWater, Banished Kitten, HOPPINGANT by researchers, Yorotrooper, Tomiris, Popa, Bouquet, Spencer, Jordan, Patchwork, Strigoi Master

Description

In May and June 2026, the Clubfoot Wolf cluster executed a large-scale phishing campaign targeting Russian organizations across manufacturing, retail, e-commerce, agriculture, IT, transportation, healthcare, and science sectors, with primary focus on wholesale distributors of chemical products. Several Belarusian organizations were also compromised. The adversary sent phishing emails disguised as invoices or purchase requests, containing ZIP archives with decoy documents and malicious LNK files. Upon execution, a PowerShell script downloaded and installed NetSupport Manager, a legitimate remote administration tool, which was then used for malicious activities. The attackers employed URL shorteners to hide infrastructure and used multiple decoy files to build victim trust. The campaign demonstrated continuous evolution in delivery methods and infection chains.

Goals & Targeting

Targeted Sectors

Manufacturing
Retail
Transportation
Healthcare
Government
Financial services
Chemical
Energy
Defense
Food agriculture
Education
Construction
Telecommunications
Critical infrastructure
Maritime
Aerospace
Aviation
Gaming
Utilities
Nuclear
Media
Mining
Hospitality
Pharmaceutical
Non profit

Targeted Countries / Regions

Belarus
Russian Federation
RU
US
BY
KZ
PL
AE
UA
BR
IL
ES
TR
RO
PK
GB
NG
SA
MX
IT
DE
IN
NL
CN
JP
VN

AI Analysis

· 1 week ago

Executive Summary

Clubfoot Wolf is a threat actor targeting key sectors such as manufacturing, retail, transportation, and healthcare, primarily in Belarus and Russia. The group has executed large-scale phishing campaigns, using malicious emails and payloads to compromise organizations. Their tactics include the use of legitimate remote administration tools for malicious activities and demonstrate an ability to evolve their methods over time.

Goals & Targeting

Clubfoot Wolf appears to target sectors with high economic value, such as manufacturing, retail, transportation, and healthcare, likely seeking financial gain or disruptive impact. The focus on wholesale distributors of chemical products suggests a possible interest in supply chain sabotage or theft of sensitive industrial information. The targeting of Belarusian and Russian organizations may indicate a regional focus or state-affiliated activity.

Enhanced Description

Clubfoot Wolf is a financially motivated threat actor attributed to a significant phishing campaign in May and June 2026, targeting Russian and Belarusian organizations across multiple sectors. The group sent phishing emails disguised as invoices or purchase requests, which contained ZIP archives with decoy documents and malicious LNK files. Upon execution, a PowerShell script downloaded and installed NetSupport Manager, a legitimate remote administration tool repurposed for malicious activities. To avoid detection, Clubfoot Wolf employed URL shorteners to mask their command-and-control (C2) infrastructure and used multiple decoy files to build trust with victims. This campaign highlighted the group's ability to continuously evolve their delivery methods and infection chains.

Key Capabilities

  • Phishing campaigns with malicious email attachments
  • Use of legitimate tools like NetSupport Manager for malicious purposes
  • Evolved infection techniques including PowerShell scripting
  • Employment of URL shorteners to mask C2 infrastructure

Software / Tooling

NetSupport Manager
PowerShell

Campaigns & Victims

Clubfoot Wolf operates with a focus on large-scale campaigns, targeting multiple sectors and geographies. The group shows persistence in compromising victims through sophisticated phishing techniques and demonstrates the ability to adapt their methods over time. Notable operations include the 2026 campaign against Russian and Belarusian organizations.

IOC Patterns

  • Spear-phishing emails with invoice/purchase request themes
  • ZIP archives containing decoy documents
  • LNK files as payload delivery mechanisms
  • Use of URL shorteners for C2 infrastructure

Recommended Actions

  • Enhance email filtering and phishing detection capabilities
  • Monitor for异常 use of legitimate remote admin tools like NetSupport Manager
  • Implement strict controls on execution of LNK files
  • Monitor PowerShell activity for suspicious script executions
  • Educate employees on recognizing phishing attempts

Suggested Tags

Phishing
Financially-Motivated
APT
Belarus/Russia Focus
Evolved TTPs

Confidence Assessment

Low confidence in Clubfoot Wolf's details due to limited available intelligence linkages. The absence of explicitly linked MITRE ATT&CK techniques, associated tools, or specific campaign details beyond the May-June 2026 timeframe limits the depth of analysis.

ATT&CK Techniques

No techniques linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 5 URL 12 SHA-256 Hash 3

References

  1. ics-cert.kaspersky.com — Cited by web research for: APT28
  2. bi-zone.medium.com — Cited by web research for: URL shorteners
  3. thehackernews.com — Cited by web research for: Dark
  4. securityarsenal.com — Cited by web research for: C2 infrastructure
  5. bi.zone — Cited by web research for: curl
  6. bi-zone.medium.com — Cited by web research for: Strigoi Master

Intel Summary

0

Techniques

44

Tools

0

Campaigns

56

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
Critical Infrastructure
Phishing
Financially-Motivated
APT
Belarus/Russia Focus
Evolved TTPs

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Iran (IR)
Confidence
55%
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.