Threat reportMalwareTL-2026-0861
Versatile Werewolf (HeartlessSoul): Fondue.exe LOLBin Abuse via APPWIZ.cpl Side-Loading Delivers Sliver Implant and SoullessRAT
Versatile Werewolf (HeartlessSoul) (TL-2026-0861), also tracked as Unholy Trinity (campaign), is a high-severity malware campaign, first published 2026-06-18. It is attributed to Versatile Werewolf with medium confidence, affects Microsoft Windows (Fondue.exe / Features on Demand UX), maps to 29 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 32 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 29MITRE ATT&CK
- Actors
- 1Versatile Werewolf
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 32Indicators of compromise
Key facts for TL-2026-0861
- Threat ID
- TL-2026-0861
- Also known as
- Unholy Trinity (campaign), Fondue.exe side-loading campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- Versatile Werewolf
- Attribution confidence
- MEDIUM
- Motivation
- ESPIONAGE
- Target sectors
- government, military, defense, aerospace, drone-manufacturing, law-enforcement
- Target regions
- Russia, Eastern Europe
- Detection rules
- 9
- Indicators of compromise
- 32
Malware and tooling in Versatile Werewolf (HeartlessSoul)
Malware and tooling: SoullessRAT, Oreans Code Virtualizer, Sliver - S0633, UPX
How Versatile Werewolf (HeartlessSoul) works
An espionage cluster tracked by BI.ZONE as Versatile Werewolf (HeartlessSoul) abuses the legitimate Windows Features-on-Demand UX binary Fondue.exe as a LOLBin: a malicious APPWIZ.cpl placed in Fondue.exe's working directory is side-loaded ahead of system paths, executing a UPX-packed, Oreans Code Virtualizer-obfuscated applet that deploys a Sliver post-exploitation implant in memory. Delivery uses malicious MSI installers with Starlink (StarDebug) and drone-pilot-training (AlphaFly) lures against government, military, and drone-engineering personnel, with Scheduled Task persistence masquerading as Microsoft Edge updates.
Versatile Werewolf (also tracked as HeartlessSoul) is one of three 'Werewolf' espionage clusters documented by BI.ZONE in its April 2026 'Unholy trinity' analysis, alongside Paper Werewolf (GOFFEE) and Eagle Werewolf. The cluster is notable for leveraging generative AI to accelerate tool development, producing the JavaScript-based SoullessRAT and weaponizing the open-source Sliver framework as its primary post-exploitation implant.
The infection chain begins with a social-engineering lure: spoofed product sites distribute malicious MSI installers impersonating a Starlink terminal management utility (StarDebug, stardebug[.]app, with Telegram support @StarDebugAdmin1) and a drone pilot training simulator (AlphaFly, alphafly-drones[.]com, whose site mimics betaflight.com and reuses media from obriy[.]airforce). The MSI extracts a PowerShell script (run-script.ps1), a VBS helper, and a .NET loader (installer.exe). The PowerShell stage pulls remote code from a private IP; the .NET loader executes an embedded PowerShell script that decodes two Base64 executables into %TEMP%. An NSIS installer deploys the genuine decoy application while an Inno Setup installer (testexe.exe) unpacks the legitimate Fondue.exe and a malicious appwiz.cpl into the hidden directory %PROGRAMDATA%\29167fc2-cdc7-490d-9c70-96bfb9b58225.
The core technique is hijack-execution-flow abuse of Fondue.exe (Windows Features on Demand UX, v10.0.19041.1), which resolves appwiz.cpl from its own working directory before standard system paths. The planted appwiz.cpl — packed with UPX and obfuscated with Oreans Code Virtualizer — is loaded into Fondue.exe's address space via DLL side-loading and stages the Sliver implant directly in memory. Sliver beacons to the C2 domain curtainbeatdisturbance[.]com and guards single-instance execution with the mutex MediumTurquoiseBeige.
Persistence is established through a Windows Scheduled Task named in the format MicrosoftEdgeUpdateTaskMachineUA{GUID} (observed: MicrosoftEdgeUpdateTaskMachineUA{dccb869b-0d8f-1b4e-f48c-85c613ae8b4b}) that re-launches %PROGRAMDATA%\29167fc2-cdc7-490d-9c70-96bfb9b58225\fondue.exe -Embedding every minute, masquerading as legitimate Microsoft Edge update activity. In a parallel delivery branch (newfolder[.]click) the cluster drops SoullessRAT, an AI-authored JavaScript RAT supporting C2 file upload, modular downloads (self-destruction, SSH, Outlook harvesting), system-information collection, PowerShell remote command execution, screenshot capture, logical-volume enumeration, directory listing, and process termination. No CVE is involved; this is a trusted-binary/technique-abuse threat warranting behavioral SOC detection. BeaconBeagle returned no existing config/beacon records for curtainbeatdisturbance[.]com at time of analysis.
MITRE ATT&CK techniques used in TL-2026-0861
Collection
T1005 Data from Local System; T1113 Screen Capture; T1114 Email Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1564 Hide Artifacts; T1620 Reflective Code Loading
Exfiltration
T1041 Exfiltration Over C2 Channel
Persistence
T1053 Scheduled Task/Job; T1547 Boot or Logon Autostart Execution
Discovery
T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery
Execution
T1059 Command and Scripting Interpreter; T1106 Native API; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1573 Encrypted Channel
Credential Access
Initial Access
stealth
Resource Development
T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities; T1608 Stage Capabilities
Affected products and versions in Versatile Werewolf (HeartlessSoul)
- Microsoft — Windows (Fondue.exe / Features on Demand UX)
Vulnerable versions: 10.0.19041.1 (binary abused as LOLBin)
Remediation for Versatile Werewolf (HeartlessSoul)
Immediate actions
- Block C2 domain curtainbeatdisturbance[.]com and distribution domains stardebug[.]app, alphafly-drones[.]com, newfolder[.]click at perimeter/DNS
- Hunt for Fondue.exe executing from any path other than %WINDIR%\System32 (e.g. %PROGRAMDATA% subfolders)
- Hunt for an appwiz.cpl present in any directory alongside Fondue.exe outside System32
- Quarantine hosts with a Scheduled Task matching MicrosoftEdgeUpdateTaskMachineUA{GUID} that launches fondue.exe -Embedding
Workarounds
- Restrict or monitor execution of Fondue.exe (Features on Demand) which is rarely needed interactively
- Alert on Scheduled Tasks created with Microsoft-Edge-update-like names that point to non-standard binaries
Longer-term hardening
- Deploy EDR with behavioral detection for trusted-binary side-loading (Fondue.exe loading non-System32 CPL/DLL)
- Enable command-line and module-load (Sysmon Event ID 7) logging across the fleet
- Application control (WDAC/AppLocker) to restrict execution of binaries from %PROGRAMDATA% and %TEMP%
- User awareness training on MSI lures impersonating Starlink/drone tooling
Weaknesses (CWE) in Versatile Werewolf (HeartlessSoul)
Timeline of Versatile Werewolf (HeartlessSoul)
- Espionage activity employing Sliver-via-Fondue.exe side-loading and SoullessRAT via fake AlphaFly installer observed in the wild (related Werewolf-cluster campaign).
- Distribution and C2 infrastructure (stardebug[.]app, alphafly-drones[.]com, curtainbeatdisturbance[.]com, newfolder[.]click) attributed to the Werewolf clusters.
- Sliver implant C2 (curtainbeatdisturbance[.]com) and single-instance mutex MediumTurquoiseBeige documented; staging/persistence directory %PROGRAMDATA%\29167fc2-cdc7-490d-9c70-96bfb9b58225 identified.
- Parallel delivery branch via newfolder[.]click documented dropping SoullessRAT, an AI-authored JavaScript RAT with modular SSH, Outlook-harvesting, self-destruction, screenshot, and remote-PowerShell capabilities.
- StarDebug lure (stardebug[.]app, Telegram support @StarDebugAdmin1) impersonating a Starlink terminal management utility and AlphaFly lure (alphafly-drones[.]com, mimicking betaflight.com and reusing obriy[.]airforce media) documented as the social-engineering delivery vectors.
- Versatile Werewolf assessed to leverage generative AI to develop tooling, including the JavaScript SoullessRAT and a comment-rich, unobfuscated VBS helper.
- Fondue.exe LOLBin abuse via malicious appwiz.cpl side-loading, UPX + Oreans Code Virtualizer packing, and MicrosoftEdgeUpdateTaskMachineUA{GUID} scheduled-task persistence documented.
- BI.ZONE publishes 'Unholy trinity: werewolves target law enforcers,' documenting Versatile Werewolf (HeartlessSoul) alongside Paper Werewolf (GOFFEE) and Eagle Werewolf, with full IOC set.
- BeaconBeagle queried for the Sliver C2 domain curtainbeatdisturbance[.]com during analysis; no existing config or beacon records were returned at that time.
- Cyber Security News publishes coverage of the Fondue.exe APPWIZ.cpl side-loading technique delivering the Sliver implant.
Sources cited for Versatile Werewolf (HeartlessSoul)
- Unholy trinity: werewolves target law enforcers
- Unholy trinity: werewolves target law enforcers (BI.ZONE blog)
- Hackers Abuse Microsoft Fondue.exe to Side-Load APPWIZ.cpl and Execute Malware
- Fondue.exe | Windows Features on Demand UX | STRONTIC xcyclopedia
- Sliver Implant Targets German Entities With DLL Sideloading and Proxying Techniques (Cyble)
- Learning Sliver C2 (10) - Sideload
- DNS C2 - BishopFox/sliver Wiki
Detection coverage for TL-2026-0861
As of 2026-06-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0861 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.