Understanding threat actor capabilities is only half the battle—the other half is knowing whether your organization is in their crosshairs. See how Bitsight threat intelligence helps you move from observation to action.
Bloody Wolf has expanded cyber operations across Central Asia, including campaigns targeting Kyrgyzstan since at least June 2025 and Uzbekistan by October 2025. Recent activity uses spear-phishing emails with PDF attachments impersonating government agencies, particularly Ministries of Justice, to deliver malicious Java Archive files that deploy NetSupport RAT.
Spear-phishing emails impersonating government agencies
PDF attachments with embedded malicious links
Malicious Java Archive files
Unauthorized NetSupport Manager deployments
Java Runtime abuse
Government-spoofing domains
Geo-fenced delivery infrastructure
Phishing
Spearphishing Attachment
User Execution
Malicious File
Command and Scripting Interpreter
Windows Command Shell
Boot or Logon Autostart Execution
Registry Run Keys / Startup Folder
Scheduled Task/Job
File and Directory Discovery
Application Layer Protocol
Web Protocols
Remote Access Software
Government agency impersonation
PDF lure delivery
JAR loader execution
Geo-fenced payload delivery
Fake error message display
Persistence through registry keys
Persistence through scheduled tasks
Persistence through startup folder scripts
Bloody Wolf targets Central Asia with government-themed spear-phishing, PDF lures, malicious JAR files, STRRAT, and weaponized NetSupport RAT activity.
Continuously monitor for spear-phishing campaigns impersonating government agencies
Detect and block phishing emails containing PDF attachments with embedded links
Block or restrict JAR execution on user endpoints unless explicitly required
Disable Java Runtime where it is not needed
Audit legitimate NetSupport Manager and other remote administration tool deployments
Alert on unauthorized NetSupport installations or unusual remote access sessions
Monitor for registry Run key, scheduled task, and startup folder persistence
Conduct proactive threat hunting for NetSupport RAT deployments
Educate users on spear-phishing risks and fake government communications
Maintain an incident response plan for compromises involving Bloody Wolf tactics, techniques, and procedures
Understanding threat actor capabilities is only half the battle—the other half is knowing whether your organization is in their crosshairs. See how Bitsight threat intelligence helps you move from observation to action.