From May to August 2026, Russian organizations from various industries were subjected to a series of targeted cyberattacks by the Feral Wolf group. Bi.Zone Threat Intelligence specialists found that the attackers exploited vulnerabilities in corporate systems, misconfigurations, and contractor infrastructure to penetrate networks.
One of the main attack methods was exploiting vulnerabilities in Atlassian Confluence, which allowed remote access to systems. In some cases, hackers used incorrect configurations of 1C-based solutions to launch malicious code and access databases.
After penetration, Feral Wolf used hidden control and traffic proxying tools. Legitimate protocols were used to mask activity, as well as mechanisms that made it difficult to detect and analyze the attackers' actions.
The final stage was launching the GenieLocker ransomware. It encrypted critical data, effectively halting the operations of the affected companies.
According to Bi.Zone, in the first half of 2026, industry accounted for 11% of attacks, retail for 8%, IT companies for 5%, and the construction sector for 3%. Researchers believe the main reason for the group's activity is financial motivation.