Eagle Werewolf — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
6
occurrences
First Seen
May 23, 2026
Last Seen
August 13, 2026

Related Threat Clusters

  • Armored Likho APT Targets Power Grids with BusySnake Stealer Malware

    A newly identified APT group, Armored Likho, is conducting a phishing campaign targeting government agencies and electric power sectors in Russia, Brazil, and Kazakhstan. The group employs a sophisticated infostealer…

    7 articles · Updated July 4, 2026
  • Armored Likho Expands Cyber-Espionage with New Rust Toolkit

    In May 2026, the Armored Likho group, also known as Eagle Werewolf, launched a cyber-espionage campaign targeting private individuals and organizations in Russia, including corporations, government bodies, and…

    2 articles · Updated August 13, 2026
  • Middle East Telecoms Targeted for Command-and-Control Operations

    A recent report from Hunt.io reveals that over 1,350 command-and-control (C2) servers are active across 98 providers in the Middle East, with Saudi Telecom Company (STC) responsible for over 72% of the activity. This…

    4 articles · Updated May 22, 2026

Recent Intelligence Reports

  • Armored Likho Turns Windows Microphones Into Automated Eavesdropping Devices — Gbhackers · August 13, 2026
  • Armored Likho expands its cyber — Securelist · August 13, 2026
  • New APT Group Hits Power Grids in Three Countries with AI-Crafted Malware — Techtimes · July 4, 2026
  • Armored Likho APT Deploys BusySnake Stealer Against Government and Power Sector Targets — Gbhackers · July 4, 2026
  • Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign — Securelist · July 3, 2026
  • Middle East malicious infrastructure report highlights concentration of C2 servers — Scworld · May 23, 2026

CVSS v3.1 Breakdown