Threat reportMalwareTL-2026-0861

Versatile Werewolf (HeartlessSoul): Fondue.exe LOLBin Abuse via APPWIZ.cpl Side-Loading Delivers Sliver Implant and SoullessRAT

highACTIVE

Versatile Werewolf (HeartlessSoul) (TL-2026-0861), also tracked as Unholy Trinity (campaign), is a high-severity malware campaign, first published 2026-06-18. It is attributed to Versatile Werewolf with medium confidence, affects Microsoft Windows (Fondue.exe / Features on Demand UX), maps to 29 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 32 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
29MITRE ATT&CK
Actors
1Versatile Werewolf
Detection rules
9SPL · KQL · Sigma
IOCs
32Indicators of compromise

Key facts for TL-2026-0861

Threat ID
TL-2026-0861
Also known as
Unholy Trinity (campaign), Fondue.exe side-loading campaign
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
Versatile Werewolf
Attribution confidence
MEDIUM
Motivation
ESPIONAGE
Target sectors
government, military, defense, aerospace, drone-manufacturing, law-enforcement
Target regions
Russia, Eastern Europe
Detection rules
9
Indicators of compromise
32

Malware and tooling in Versatile Werewolf (HeartlessSoul)

Malware and tooling: SoullessRAT, Oreans Code Virtualizer, Sliver - S0633, UPX

How Versatile Werewolf (HeartlessSoul) works

An espionage cluster tracked by BI.ZONE as Versatile Werewolf (HeartlessSoul) abuses the legitimate Windows Features-on-Demand UX binary Fondue.exe as a LOLBin: a malicious APPWIZ.cpl placed in Fondue.exe's working directory is side-loaded ahead of system paths, executing a UPX-packed, Oreans Code Virtualizer-obfuscated applet that deploys a Sliver post-exploitation implant in memory. Delivery uses malicious MSI installers with Starlink (StarDebug) and drone-pilot-training (AlphaFly) lures against government, military, and drone-engineering personnel, with Scheduled Task persistence masquerading as Microsoft Edge updates.

Versatile Werewolf (also tracked as HeartlessSoul) is one of three 'Werewolf' espionage clusters documented by BI.ZONE in its April 2026 'Unholy trinity' analysis, alongside Paper Werewolf (GOFFEE) and Eagle Werewolf. The cluster is notable for leveraging generative AI to accelerate tool development, producing the JavaScript-based SoullessRAT and weaponizing the open-source Sliver framework as its primary post-exploitation implant.

The infection chain begins with a social-engineering lure: spoofed product sites distribute malicious MSI installers impersonating a Starlink terminal management utility (StarDebug, stardebug[.]app, with Telegram support @StarDebugAdmin1) and a drone pilot training simulator (AlphaFly, alphafly-drones[.]com, whose site mimics betaflight.com and reuses media from obriy[.]airforce). The MSI extracts a PowerShell script (run-script.ps1), a VBS helper, and a .NET loader (installer.exe). The PowerShell stage pulls remote code from a private IP; the .NET loader executes an embedded PowerShell script that decodes two Base64 executables into %TEMP%. An NSIS installer deploys the genuine decoy application while an Inno Setup installer (testexe.exe) unpacks the legitimate Fondue.exe and a malicious appwiz.cpl into the hidden directory %PROGRAMDATA%\29167fc2-cdc7-490d-9c70-96bfb9b58225.

The core technique is hijack-execution-flow abuse of Fondue.exe (Windows Features on Demand UX, v10.0.19041.1), which resolves appwiz.cpl from its own working directory before standard system paths. The planted appwiz.cpl — packed with UPX and obfuscated with Oreans Code Virtualizer — is loaded into Fondue.exe's address space via DLL side-loading and stages the Sliver implant directly in memory. Sliver beacons to the C2 domain curtainbeatdisturbance[.]com and guards single-instance execution with the mutex MediumTurquoiseBeige.

Persistence is established through a Windows Scheduled Task named in the format MicrosoftEdgeUpdateTaskMachineUA{GUID} (observed: MicrosoftEdgeUpdateTaskMachineUA{dccb869b-0d8f-1b4e-f48c-85c613ae8b4b}) that re-launches %PROGRAMDATA%\29167fc2-cdc7-490d-9c70-96bfb9b58225\fondue.exe -Embedding every minute, masquerading as legitimate Microsoft Edge update activity. In a parallel delivery branch (newfolder[.]click) the cluster drops SoullessRAT, an AI-authored JavaScript RAT supporting C2 file upload, modular downloads (self-destruction, SSH, Outlook harvesting), system-information collection, PowerShell remote command execution, screenshot capture, logical-volume enumeration, directory listing, and process termination. No CVE is involved; this is a trusted-binary/technique-abuse threat warranting behavioral SOC detection. BeaconBeagle returned no existing config/beacon records for curtainbeatdisturbance[.]com at time of analysis.

MITRE ATT&CK techniques used in TL-2026-0861

Collection

T1005 Data from Local System; T1113 Screen Capture; T1114 Email Collection

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1564 Hide Artifacts; T1620 Reflective Code Loading

Exfiltration

T1041 Exfiltration Over C2 Channel

Persistence

T1053 Scheduled Task/Job; T1547 Boot or Logon Autostart Execution

Discovery

T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery

Execution

T1059 Command and Scripting Interpreter; T1106 Native API; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1573 Encrypted Channel

Credential Access

T1552 Unsecured Credentials

Initial Access

T1566 Phishing

stealth

T1574 Hijack Execution Flow

Resource Development

T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities; T1608 Stage Capabilities

Affected products and versions in Versatile Werewolf (HeartlessSoul)

  • Microsoft — Windows (Fondue.exe / Features on Demand UX)
    Vulnerable versions: 10.0.19041.1 (binary abused as LOLBin)

Remediation for Versatile Werewolf (HeartlessSoul)

Immediate actions

  • Block C2 domain curtainbeatdisturbance[.]com and distribution domains stardebug[.]app, alphafly-drones[.]com, newfolder[.]click at perimeter/DNS
  • Hunt for Fondue.exe executing from any path other than %WINDIR%\System32 (e.g. %PROGRAMDATA% subfolders)
  • Hunt for an appwiz.cpl present in any directory alongside Fondue.exe outside System32
  • Quarantine hosts with a Scheduled Task matching MicrosoftEdgeUpdateTaskMachineUA{GUID} that launches fondue.exe -Embedding

Workarounds

  • Restrict or monitor execution of Fondue.exe (Features on Demand) which is rarely needed interactively
  • Alert on Scheduled Tasks created with Microsoft-Edge-update-like names that point to non-standard binaries

Longer-term hardening

  • Deploy EDR with behavioral detection for trusted-binary side-loading (Fondue.exe loading non-System32 CPL/DLL)
  • Enable command-line and module-load (Sysmon Event ID 7) logging across the fleet
  • Application control (WDAC/AppLocker) to restrict execution of binaries from %PROGRAMDATA% and %TEMP%
  • User awareness training on MSI lures impersonating Starlink/drone tooling

Weaknesses (CWE) in Versatile Werewolf (HeartlessSoul)

CWE-427, CWE-426

Timeline of Versatile Werewolf (HeartlessSoul)

  • Espionage activity employing Sliver-via-Fondue.exe side-loading and SoullessRAT via fake AlphaFly installer observed in the wild (related Werewolf-cluster campaign).
  • Distribution and C2 infrastructure (stardebug[.]app, alphafly-drones[.]com, curtainbeatdisturbance[.]com, newfolder[.]click) attributed to the Werewolf clusters.
  • Sliver implant C2 (curtainbeatdisturbance[.]com) and single-instance mutex MediumTurquoiseBeige documented; staging/persistence directory %PROGRAMDATA%\29167fc2-cdc7-490d-9c70-96bfb9b58225 identified.
  • Parallel delivery branch via newfolder[.]click documented dropping SoullessRAT, an AI-authored JavaScript RAT with modular SSH, Outlook-harvesting, self-destruction, screenshot, and remote-PowerShell capabilities.
  • StarDebug lure (stardebug[.]app, Telegram support @StarDebugAdmin1) impersonating a Starlink terminal management utility and AlphaFly lure (alphafly-drones[.]com, mimicking betaflight.com and reusing obriy[.]airforce media) documented as the social-engineering delivery vectors.
  • Versatile Werewolf assessed to leverage generative AI to develop tooling, including the JavaScript SoullessRAT and a comment-rich, unobfuscated VBS helper.
  • Fondue.exe LOLBin abuse via malicious appwiz.cpl side-loading, UPX + Oreans Code Virtualizer packing, and MicrosoftEdgeUpdateTaskMachineUA{GUID} scheduled-task persistence documented.
  • BI.ZONE publishes 'Unholy trinity: werewolves target law enforcers,' documenting Versatile Werewolf (HeartlessSoul) alongside Paper Werewolf (GOFFEE) and Eagle Werewolf, with full IOC set.
  • BeaconBeagle queried for the Sliver C2 domain curtainbeatdisturbance[.]com during analysis; no existing config or beacon records were returned at that time.
  • Cyber Security News publishes coverage of the Fondue.exe APPWIZ.cpl side-loading technique delivering the Sliver implant.

Sources cited for Versatile Werewolf (HeartlessSoul)

Detection coverage for TL-2026-0861

As of 2026-06-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0861 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
32 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats