logo

Stan Ghouls Target Uzbekistan and Russia with NetSupport RAT

ID: c6682ca1-a233-53db-94d2-70bf10a865ab

STIX ID: report--c6682ca1-a233-53db-94d2-70bf10a865ab

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-02-09

Date Updated: 2026-04-23

Author: Ddos

...
...

Kaspersky researchers attribute a fresh campaign to the Stan Ghouls (Bloody Wolf) group targeting organizations in Uzbekistan and Russia using Uzbek-language spear‑phishing PDFs that trick victims into running a malicious JAR loader; the loader installs the legitimate NetSupport RAT to gain full remote control and establishes persistence via startup folder, registry Run key, and a scheduled task. The report notes over 60 victims in the campaign and a curious presence of Mirai-related files on infrastructure linked to the group, raising concerns about potential IoT targeting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.