Stan Ghouls targeting Russia and Uzbekistan with NetSupport RAT
ID: 9cdb720e-ace2-5269-88b7-813e2e847f4d
STIX ID: report--9cdb720e-ace2-5269-88b7-813e2e847f4d
Feed Name: Securelist by Kaspersky
Stan Ghouls (aka Bloody Wolf) conducted a targeted spear-phishing campaign (primarily in Uzbekistan, with victims in Russia, Kazakhstan and a few other countries) using malicious PDF decoys that direct victims to a Java loader which downloads and installs NetSupport RAT; the report provides technical details, persistence methods, approximately 60+ victims across finance, manufacturing and IT sectors, extensive IoCs (file hashes and domains), and notes Mirai IoT binaries hosted on infrastructure tied to the campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
