Bloody Wolf Threat Actor Expands Activity Across Central Asia
ID: f1cdacfb-51ab-5469-b76f-e98493c7bca6
STIX ID: report--f1cdacfb-51ab-5469-b76f-e98493c7bca6
Feed Name: Infosecurity Magazine (News)
Researchers (Group-IB and UKUK) uncovered a Bloody Wolf APT campaign active since late 2023 and operating in Kyrgyzstan (from at least June 2025) with expansion into Uzbekistan by October; actors use convincing PDF lures, spoofed domains and geofenced Java JAR downloads to deliver a Java-based loader that fetches and installs NetSupport RAT. The lightweight Java 8 loaders (single-class, limited launches) automate retrieval of NetSupport binaries, establish persistence (autorun entries, scheduled tasks), and present fake errors to distract victims; the group mass-produces JARs with varying artifacts and relies on publicly available NetSupport Manager builds to blend in with legitimate remote-administration activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
