logo

Bloody Wolf Threat Actor Expands Activity Across Central Asia

ID: f1cdacfb-51ab-5469-b76f-e98493c7bca6

STIX ID: report--f1cdacfb-51ab-5469-b76f-e98493c7bca6

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2025-11-27

Date Updated: 2026-04-22

...
...

Researchers (Group-IB and UKUK) uncovered a Bloody Wolf APT campaign active since late 2023 and operating in Kyrgyzstan (from at least June 2025) with expansion into Uzbekistan by October; actors use convincing PDF lures, spoofed domains and geofenced Java JAR downloads to deliver a Java-based loader that fetches and installs NetSupport RAT. The lightweight Java 8 loaders (single-class, limited launches) automate retrieval of NetSupport binaries, establish persistence (autorun entries, scheduled tasks), and present fake errors to distract victims; the group mass-produces JARs with varying artifacts and relies on publicly available NetSupport Manager builds to blend in with legitimate remote-administration activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.