Vortex Werewolf Cyber Espionage Targets Russian Organizations with Remote Access Tools

Vortex Werewolf Cyber Espionage Targets Russian Organizations with Remote Access Tools

First seen 9 Feb 2026, 16:04 UTC CybersecuritynewsGbhackers 32.7

Article Content

Browse articles
ThreatCluster

The Vortex Werewolf cyber espionage group has been actively targeting Russian government and defense organizations since at least December 2025. This group utilizes social engineering and legitimate software utilities to establish covert remote access via Tor-enabled protocols such as RDP, SMB, SFTP, and SSH.

Ask AI about this cluster

Timeline

2025-12-01
Vortex Werewolf begins targeting Russian organizations
2026-02-09
GBHackers and Cybersecuritynews report on Vortex Werewolf