Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors werewolves

Description

WereWolves is a Russian-speaking ransomware group that emerged in May 2023, using a modified LockBit 3 (Black) encryptor, operating an unusual public website that actively recruits new members and offers a bug-bounty program with rewards up to $1 million, with at least 26 victims across Russia, the US, and Europe. Known victims: 26

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

WereWolves is a Russian-speaking ransomware group that emerged in May 2023, using a modified LockBit 3 (Black) encryptor. The group operates an unusual public website recruiting members and offering a bug-bounty program with rewards up to $1 million. With at least 26 victims across Russia, the US, and Europe, WereWolves is targeting industries for financial gain through ransomware.

Goals & Targeting

WereWolves' primary goal is financial gain through ransomware activities. Their targeting strategy focuses on sectors with high potential for financial payout, such as energy, healthcare, and technology. By recruiting new members and offering significant rewards, they aim to expand their operational capacity. The group's victims are typically organizations in Russia, the US, and Europe, suggesting either regional focus or where English and Russian-speaking markets are more lucrative.

Enhanced Description

WereWolves represents a new criminal ransomware group that emerged in May 2023, leveraging the LockBit 3 (Black) encryptor. The group notably operates a public-facing website, which serves as an unusual recruitment hub for potential members and offers bounties of up to $1 million for reported vulnerabilities. This approach suggests both financial incentives and operational ambition. WereWolves has targeted organizations across various sectors—specifically energy, healthcare, technology, and finance—as these industries offer higher data value and vulnerability points. The group's geographic reach includes Russia, the United States, and regions in Europe.

Key Capabilities

  • Use of modified LockBit 3 ransomware
  • Public recruitment campaigns with bug-bounty incentives
  • Sophisticated phishing techniques
  • Exfiltration and encryption capabilities
  • Targeting critical sectors for high financial yields

MITRE ATT&CK Tactics

Exfiltration
Credential Access
Lateral Movement
Defense Evasion
Disruption

ATT&CK Techniques

T1078
T1566
T1552
T1021.004
T1040

Software / Tooling

LockBit 3 (Black)

Campaigns & Victims

WereWolves' campaign patterns include active recruitment of new members through their public website and the use of a bug-bounty program to identify vulnerabilities in targets. Their operational tempo is steady, with persistent attacks across multiple regions and sectors. Notable past operations have targeted energy and healthcare organizations, indicating a focus on critical infrastructure. The group's marketing tactics—such as promoting its recruitment initiative—suggest an effort to build a brand presence while expanding their attack capabilities.

IOC Patterns

  • Spear-phishing emails with malicious links or attachments
  • Lateral movement within networks using legitimate tools
  • Use of compromised credentials for access
  • Ransomware deployment targeting critical systems
  • Exfiltration of sensitive data prior to encryption

Recommended Actions

  • Implement multi-factor authentication for all critical accounts
  • Enforce employee training on phishing and malware awareness
  • Monitor public domains and forums for potential recruitment campaigns
  • Conduct regular backups and store them offline securely
  • Leverage endpoint detection and response tools to identify malicious activity

Suggested Tags

APTFamily
Ransomware
FinancialGain
RecruitmentTactics
CryptoRansomware

Confidence Assessment

Moderate confidence in the data due to available information about their emergence, ransomware toolset, and recruitment tactics. Limited visibility into specific campaigns or techniques used by WereWolves creates gaps in understanding their full operational scope.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
APTFamily
FinancialGain
RecruitmentTactics
CryptoRansomware

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
May 18, 2023
Last Seen
Mar 4, 2024
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.