logo

Bloody Wolf: A Blunt Crowbar Threat To Justice

ID: 3c6dfec1-871b-5406-8cd1-7a1783bac940

STIX ID: report--3c6dfec1-871b-5406-8cd1-7a1783bac940

Feed Name: Group-IB Blog

Threat Score
72/100

Date Published: 2025-11-26

Date Updated: 2026-04-28

...
...

Bloody Wolf is an active APT targeting Central Asian government and commercial organizations using spear-phishing PDFs that host malicious JAR loaders which download and install legacy NetSupport RAT; Group-IB reports on the infection chain, JAR loader internals, persistence methods, MITRE mapping, and provides extensive IOCs (file hashes and malicious domains) along with defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.