Feral Wolf malware hashes (MQTTDoor, MatrixDoor, GenieLocker, fscan)
This rule monitors for file and process creation events associated with known FeralWolf threat actor malware, including MQTTDoor, MatrixDoor, RDPSocksProxy, GenieLocker ransomware, fscan, and tools leveraging CVE-2026-31431.
Microsoft Sentinel (KQL)

