logo

Bloody Wolf Targets Uzbekistan, Russia Using NetSupport RAT in Spear-Phishing Campaign

ID: fd082c9e-6cbd-5c0c-be50-cd52879f6842

STIX ID: report--fd082c9e-6cbd-5c0c-be50-cd52879f6842

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-02-09

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Executive summary: The report describes an active spear‑phishing campaign by the actor known as Bloody Wolf (Kaspersky: Stan Ghouls) that has deployed NetSupport RAT via malicious PDFs to compromise targets in Uzbekistan, Russia and neighboring states, with roughly 60+ victims observed and additional infrastructure linked to Mirai IoT payloads. The document also contextualizes this activity alongside other threat clusters (ExCobalt, Punishing Owl, Vortex Werewolf), detailing their tools and TTPs including loaders, persistence mechanisms, credential theft and kernel rootkits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.