Threat Actor Profile

Bloody Wolf

Active Since
2023
Motivation
Espionage, Regional intelligence collection
Recent Activity

Bloody Wolf has expanded cyber operations across Central Asia, including campaigns targeting Kyrgyzstan since at least June 2025 and Uzbekistan by October 2025. Recent activity uses spear-phishing emails with PDF attachments impersonating government agencies, particularly Ministries of Justice, to deliver malicious Java Archive files that deploy NetSupport RAT.

Primary Targets
  • Government organizations
  • Financial institutions
  • Information technology organizations
  • Telecommunications organizations
  • Private and commercial organizations
  • Organizations in Central Asia
Target Locations
  • Kyrgyzstan
  • Uzbekistan
  • Kazakhstan
  • Russia
  • Central Asia
Target Sectors
  • Government
  • Finance
  • Technology
  • Telecommunications
  • Private Sector
Vulnerabilities

Spear-phishing emails impersonating government agencies

PDF attachments with embedded malicious links

Malicious Java Archive files

Unauthorized NetSupport Manager deployments

Java Runtime abuse

Government-spoofing domains

Geo-fenced delivery infrastructure

Techniques
  • Phishing

  • Spearphishing Attachment

  • User Execution

  • Malicious File

  • Command and Scripting Interpreter

  • Windows Command Shell

  • Boot or Logon Autostart Execution

  • Registry Run Keys / Startup Folder

  • Scheduled Task/Job

  • File and Directory Discovery

  • Application Layer Protocol

  • Web Protocols

  • Remote Access Software

  • Government agency impersonation

  • PDF lure delivery

  • JAR loader execution

  • Geo-fenced payload delivery

  • Fake error message display

  • Persistence through registry keys

  • Persistence through scheduled tasks

  • Persistence through startup folder scripts

Malware Tools
  • STRRAT
  • NetSupport RAT
  • NetSupport Manager
  • Custom JAR generator
  • Java Archive loaders
  • Government-spoofing PDF lures
Bitsight Contextualized Intelligence
  • Bloody Wolf targets Central Asia with government-themed spear-phishing, PDF lures, malicious JAR files, STRRAT, and weaponized NetSupport RAT activity.

Defensive Takeaways
  • Continuously monitor for spear-phishing campaigns impersonating government agencies

  • Detect and block phishing emails containing PDF attachments with embedded links

  • Block or restrict JAR execution on user endpoints unless explicitly required

  • Disable Java Runtime where it is not needed

  • Audit legitimate NetSupport Manager and other remote administration tool deployments

  • Alert on unauthorized NetSupport installations or unusual remote access sessions

  • Monitor for registry Run key, scheduled task, and startup folder persistence

  • Conduct proactive threat hunting for NetSupport RAT deployments

  • Educate users on spear-phishing risks and fake government communications

  • Maintain an incident response plan for compromises involving Bloody Wolf tactics, techniques, and procedures

How Bitsight Helps

Understanding threat actor capabilities is only half the battle—the other half is knowing whether your organization is in their crosshairs. See how Bitsight threat intelligence helps you move from observation to action.

Request threat intel demo