Bloody Wolf Hackers Mimic as Government Agencies to Deploy NetSupport RAT via Weaponized PDF’s
ID: 15de4015-ab9c-56a6-9f7a-46b1e9be2fa6
STIX ID: report--15de4015-ab9c-56a6-9f7a-46b1e9be2fa6
Feed Name: cybersecurityNews.com
Bloody Wolf, an Advanced Persistent Threat, has intensified spear-phishing campaigns since June 2025 against government and private sector targets in Kyrgyzstan and Uzbekistan, delivering weaponized PDFs that trigger Java JAR loaders which install a weaponized NetSupport RAT; the campaigns use geo-fencing, local-language lures, and redundant persistence (Startup folder, registry changes, scheduled tasks) to maintain long-term access for data exfiltration and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
