FoalShell
- Malware type
- webshell
- Profile updated
- 2026-07-07 13:06:36
Context
According to BI.ZONE, FoalShell is a simple reverse shell used by Cavalry Werewolf, written in Go, C++, and C#. FoalShell allows attackers to execute arbitrary commands in the cmd.exe command line interpreter on a compromised host.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Foalshell_Auto (yara-rule)
Reports & references
- bi-zone.medium.com — Cavalry Werewolf Raids Russias Public Sector With Trusted Relationship Attacks E19F7A5C83Ef (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Foalshell (report)