WereWolves is a Russian-speaking ransomware group that emerged in May 2023, using a modified LockBit 3 (Black) encryptor, operating an unusual public website that actively recruits new members and offers a bug-bounty program with rewards up to $1 million, with at least 26 victims across Russia, the US, and Europe. Known victims: 26
Objectives
Executive Summary
WereWolves is a Russian-speaking ransomware group that emerged in May 2023, using a modified LockBit 3 (Black) encryptor. The group operates an unusual public website recruiting members and offering a bug-bounty program with rewards up to $1 million. With at least 26 victims across Russia, the US, and Europe, WereWolves is targeting industries for financial gain through ransomware.
Goals & Targeting
WereWolves' primary goal is financial gain through ransomware activities. Their targeting strategy focuses on sectors with high potential for financial payout, such as energy, healthcare, and technology. By recruiting new members and offering significant rewards, they aim to expand their operational capacity. The group's victims are typically organizations in Russia, the US, and Europe, suggesting either regional focus or where English and Russian-speaking markets are more lucrative.
Enhanced Description
WereWolves represents a new criminal ransomware group that emerged in May 2023, leveraging the LockBit 3 (Black) encryptor. The group notably operates a public-facing website, which serves as an unusual recruitment hub for potential members and offers bounties of up to $1 million for reported vulnerabilities. This approach suggests both financial incentives and operational ambition. WereWolves has targeted organizations across various sectors—specifically energy, healthcare, technology, and finance—as these industries offer higher data value and vulnerability points. The group's geographic reach includes Russia, the United States, and regions in Europe.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
WereWolves' campaign patterns include active recruitment of new members through their public website and the use of a bug-bounty program to identify vulnerabilities in targets. Their operational tempo is steady, with persistent attacks across multiple regions and sectors. Notable past operations have targeted energy and healthcare organizations, indicating a focus on critical infrastructure. The group's marketing tactics—such as promoting its recruitment initiative—suggest an effort to build a brand presence while expanding their attack capabilities.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in the data due to available information about their emergence, ransomware toolset, and recruitment tactics. Limited visibility into specific campaigns or techniques used by WereWolves creates gaps in understanding their full operational scope.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics