Werewolves is a ransomware group that emerged in October 2023, primarily motivated by financial gain through the encryption and exfiltration of victim data. This group distinguishes itself by leveraging zero-day vulnerabilities and custom malware in its operations, often demanding exorbitant ransoms. They maintain a highly organized structure and employ social engineering tactics alongside technical exploits. Werewolves operate under a dual extortion model, encrypting data and threatening its public release if ransom demands are not met.
Tecnicas MITRE
T1505.003, T1078.003, T1486, T1071.001
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
BrazilBelarusGermanyFranceGhanaItalyMacedonia, the Former Yugoslav Republic ofNetherlandsSerbiaRussian Federation
Sectores objetivo (SOCRadar)
Construction of BuildingsOther Information ServicesCredit UnionsRail TransportationSoftware PublishersEnterprises & HoldingAccommodationAir TransportationManufacturingConstruction