# Versatile Werewolf (HeartlessSoul): Fondue.exe LOLBin Abuse via APPWIZ.cpl Side-Loading Delivers Sliver Implant and SoullessRAT

> An espionage cluster tracked by BI.ZONE as Versatile Werewolf (HeartlessSoul) abuses the legitimate Windows Features-on-Demand UX binary Fondue.exe as a LOLBin: a malicious APPWIZ.cpl placed in Fondue.exe's working directory is side-loaded ahead of system paths, executing a UPX-packed, Oreans Code Virtualizer-obfuscated applet that deploys a Sliver post-exploitation implant in memory. Delivery uses malicious MSI installers with Starlink (StarDebug) and drone-pilot-training (AlphaFly) lures against government, military, and drone-engineering personnel, with Scheduled Task persistence masquerading as Microsoft Edge updates.

- **Published:** 2026-06-18T00:00:00Z
- **Last reviewed:** 2026-06-18T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0861
- **ID:** TL-2026-0861
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** Versatile Werewolf
- **Detections:** 9 · **IOCs:** 32 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Versatile Werewolf (also tracked as HeartlessSoul) is one of three 'Werewolf' espionage clusters documented by BI.ZONE in its April 2026 'Unholy trinity' analysis, alongside Paper Werewolf (GOFFEE) and Eagle Werewolf. The cluster is notable for leveraging generative AI to accelerate tool development, producing the JavaScript-based SoullessRAT and weaponizing the open-source Sliver framework as its primary post-exploitation implant.

The infection chain begins with a social-engineering lure: spoofed product sites distribute malicious MSI installers impersonating a Starlink terminal management utility (StarDebug, stardebug[.]app, with Telegram support @StarDebugAdmin1) and a drone pilot training simulator (AlphaFly, alphafly-drones[.]com, whose site mimics betaflight.com and reuses media from obriy[.]airforce). The MSI extracts a PowerShell script (run-script.ps1), a VBS helper, and a .NET loader (installer.exe). The PowerShell stage pulls remote code from a private IP; the .NET loader executes an embedded PowerShell script that decodes two Base64 executables into %TEMP%. An NSIS installer deploys the genuine decoy application while an Inno Setup installer (testexe.exe) unpacks the legitimate Fondue.exe and a malicious appwiz.cpl into the hidden directory %PROGRAMDATA%\29167fc2-cdc7-490d-9c70-96bfb9b58225.

The core technique is hijack-execution-flow abuse of Fondue.exe (Windows Features on Demand UX, v10.0.19041.1), which resolves appwiz.cpl from its own working directory before standard system paths. The planted appwiz.cpl — packed with UPX and obfuscated with Oreans Code Virtualizer — is loaded into Fondue.exe's address space via DLL side-loading and stages the Sliver implant directly in memory. Sliver beacons to the C2 domain curtainbeatdisturbance[.]com and guards single-instance execution with the mutex MediumTurquoiseBeige.

Persistence is established through a Windows Scheduled Task named in the format MicrosoftEdgeUpdateTaskMachineUA{GUID} (observed: MicrosoftEdgeUpdateTaskMachineUA{dccb869b-0d8f-1b4e-f48c-85c613ae8b4b}) that re-launches %PROGRAMDATA%\29167fc2-cdc7-490d-9c70-96bfb9b58225\fondue.exe -Embedding every minute, masquerading as legitimate Microsoft Edge update activity. In a parallel delivery branch (newfolder[.]click) the cluster drops SoullessRAT, an AI-authored JavaScript RAT supporting C2 file upload, modular downloads (self-destruction, SSH, Outlook harvesting), system-information collection, PowerShell remote command execution, screenshot capture, logical-volume enumeration, directory listing, and process termination. No CVE is involved; this is a trusted-binary/technique-abuse threat warranting behavioral SOC detection. BeaconBeagle returned no existing config/beacon records for curtainbeatdisturbance[.]com at time of analysis.

## MITRE ATT&CK

- T1587 Develop Capabilities
- T1588 Obtain Capabilities
- T1583 Acquire Infrastructure
- T1608 Stage Capabilities
- T1566 Phishing
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1106 Native API
- T1053 Scheduled Task/Job
- T1547 Boot or Logon Autostart Execution
- T1574 Hijack Execution Flow
- T1218 System Binary Proxy Execution
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1564 Hide Artifacts
- T1620 Reflective Code Loading
- T1070 Indicator Removal
- T1552 Unsecured Credentials
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1057 Process Discovery
- T1113 Screen Capture
- T1114 Email Collection
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1573 Encrypted Channel
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel

## Sources

- [Unholy trinity: werewolves target law enforcers](https://bi-zone.medium.com/unholy-trinity-werewolves-target-law-enforcers-f28357945280)
- [Unholy trinity: werewolves target law enforcers (BI.ZONE blog)](https://bi.zone/eng/expertise/blog/triedinoe-zlo-oborotni-atakuyut-sotrudnikov-silovykh-struktur/)
- [Hackers Abuse Microsoft Fondue.exe to Side-Load APPWIZ.cpl and Execute Malware](https://cybersecuritynews.com/hackers-abuse-microsoft-fondue-exe/)
- [Fondue.exe | Windows Features on Demand UX | STRONTIC xcyclopedia](https://strontic.github.io/xcyclopedia/library/Fondue.exe-EEE0F4A169799F00BAD87C7D0834E348.html)
- [Sliver Implant Targets German Entities With DLL Sideloading and Proxying Techniques (Cyble)](https://cyble.com/blog/sliver-implant-targets-german-entities-with-dll-sideloading-and-proxying-techniques/)
- [Learning Sliver C2 (10) - Sideload](https://dominicbreuker.com/post/learning_sliver_c2_10_sideload/)
- [DNS C2 - BishopFox/sliver Wiki](https://github.com/BishopFox/sliver/wiki/DNS-C2/39a91150128884786f637c7bab6091841b420d99)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0861
