Also known as: Lone Wolf, Moonshine Trickster, APT28, tracked as, congenital talipes equinovarus, Head Mare, 21, 2026, Kyrgyzstan, Kazakhstan, defense industries, Awaken Likho, Bearlyfy, Librarian Ghouls, Librarian Likho, Rezet, Core Werewolf, Ratopak Spider, UAC-0008, Romania, Fancy Bear, UAC-0001, its NATO allies, Outrider Tiger, Fishing Elephant, Earth Vetala, MERCURY, Mango Sandstorm, Static Kitten, including diplomatic, maritime, financial, telecom entities, Archer RAT, RUSTRIC, detects installed security software, establishes contact with a, CHAR, Olalampo, Storm-0842, DUNE, Red Sandstorm, Bloody Wolf, SkyCloak, laboo.boo, Void Arachne, Watch Wolf, Forest Blizzard, TA450, MuddyWater, Banished Kitten, HOPPINGANT by researchers, Yorotrooper, Tomiris, Popa, Bouquet, Spencer, Jordan, Patchwork, Strigoi Master
In May and June 2026, the Clubfoot Wolf cluster executed a large-scale phishing campaign targeting Russian organizations across manufacturing, retail, e-commerce, agriculture, IT, transportation, healthcare, and science sectors, with primary focus on wholesale distributors of chemical products. Several Belarusian organizations were also compromised. The adversary sent phishing emails disguised as invoices or purchase requests, containing ZIP archives with decoy documents and malicious LNK files. Upon execution, a PowerShell script downloaded and installed NetSupport Manager, a legitimate remote administration tool, which was then used for malicious activities. The attackers employed URL shorteners to hide infrastructure and used multiple decoy files to build victim trust. The campaign demonstrated continuous evolution in delivery methods and infection chains.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Clubfoot Wolf is a threat actor targeting key sectors such as manufacturing, retail, transportation, and healthcare, primarily in Belarus and Russia. The group has executed large-scale phishing campaigns, using malicious emails and payloads to compromise organizations. Their tactics include the use of legitimate remote administration tools for malicious activities and demonstrate an ability to evolve their methods over time.
Goals & Targeting
Clubfoot Wolf appears to target sectors with high economic value, such as manufacturing, retail, transportation, and healthcare, likely seeking financial gain or disruptive impact. The focus on wholesale distributors of chemical products suggests a possible interest in supply chain sabotage or theft of sensitive industrial information. The targeting of Belarusian and Russian organizations may indicate a regional focus or state-affiliated activity.
Enhanced Description
Clubfoot Wolf is a financially motivated threat actor attributed to a significant phishing campaign in May and June 2026, targeting Russian and Belarusian organizations across multiple sectors. The group sent phishing emails disguised as invoices or purchase requests, which contained ZIP archives with decoy documents and malicious LNK files. Upon execution, a PowerShell script downloaded and installed NetSupport Manager, a legitimate remote administration tool repurposed for malicious activities. To avoid detection, Clubfoot Wolf employed URL shorteners to mask their command-and-control (C2) infrastructure and used multiple decoy files to build trust with victims. This campaign highlighted the group's ability to continuously evolve their delivery methods and infection chains.
Key Capabilities
Software / Tooling
Campaigns & Victims
Clubfoot Wolf operates with a focus on large-scale campaigns, targeting multiple sectors and geographies. The group shows persistence in compromising victims through sophisticated phishing techniques and demonstrates the ability to adapt their methods over time. Notable operations include the 2026 campaign against Russian and Belarusian organizations.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low confidence in Clubfoot Wolf's details due to limited available intelligence linkages. The absence of explicitly linked MITRE ATT&CK techniques, associated tools, or specific campaign details beyond the May-June 2026 timeframe limits the depth of analysis.
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
0
Techniques
44
Tools
0
Campaigns
56
IOCs
0
Observed Data
0
Tactics