CORE Werewolf, a suspected cyberespionage group, deployed a remote access trojan (RAT) named CoreRAT against Russian defense and public sector entities from June to July 2026. The attackers utilized two droppers to spread CoreRAT, disguised as military documents, which tricked victims into executing the malware. The campaign marks a significant evolution in Core Werewolf's capabilities, transitioning from using basic backdoors to a fully operational trojan.
CoreRAT allows extensive control over infected systems, including file listing and command execution. To mitigate risks, security teams should monitor for unusual activity in directories and block untrusted attachments in communications.