FoalShell

Malware type
webshell
Profile updated
2026-07-07 13:06:36

Context

According to BI.ZONE, FoalShell is a simple reverse shell used by Cavalry Werewolf, written in Go, C++, and C#. FoalShell allows attackers to execute arbitrary commands in the cmd.exe command line interpreter on a compromised host.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Foalshell_Auto (yara-rule)

Reports & references

  • bi-zone.medium.com — Cavalry Werewolf Raids Russias Public Sector With Trusted Relationship Attacks E19F7A5C83Ef (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Foalshell (report)

External references