logo

Bloody Wolf Hackers Mimic as Government Agencies to Deploy NetSupport RAT via Weaponized PDF’s

ID: 15de4015-ab9c-56a6-9f7a-46b1e9be2fa6

STIX ID: report--15de4015-ab9c-56a6-9f7a-46b1e9be2fa6

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2025-12-01

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Bloody Wolf, an Advanced Persistent Threat, has intensified spear-phishing campaigns since June 2025 against government and private sector targets in Kyrgyzstan and Uzbekistan, delivering weaponized PDFs that trigger Java JAR loaders which install a weaponized NetSupport RAT; the campaigns use geo-fencing, local-language lures, and redundant persistence (Startup folder, registry changes, scheduled tasks) to maintain long-term access for data exfiltration and lateral movement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.