HomeSecurityBloody Wolf expands attacks with Java-based NetSupport RAT

Bloody Wolf expands attacks with Java-based NetSupport RAT

The threat group known as Bloody Wolf has been engaged in a cyberattack campaign targeting Kyrgyzstan since at least June 2025 with the goal of delivering the NetSupport RAT. Since October 2025, the activity has also expanded to Uzbekistan, according to Group-IB researchers Amirbek Kurbanov and Volen Kayo , in a report published in collaboration with Ukuk , a state-owned enterprise under the Prosecutor General's Office of the Kyrgyz Republic.

See also: RomCom: SocGholish Fake Update attacks to distribute Mythic Agent

Bloody Wolf

The attacks have targeted the financial, government and information technology (IT) sectors. “These threat actors impersonated the Kyrgyz Ministry of Justice via official PDF documents and domain names, which hosted malicious Java Archive (JAR) files designed to deploy the NetSupport RAT,” the Singapore-based company said. “This combination of social engineering and accessible tools allows Bloody Wolf to remain effective while maintaining a low operational profile.”

Bloody Wolf is the name given to a group of hackers of unknown origin that has used spear-phishing attacks to target entities in Kazakhstan and Russia using tools such as STRRAT and NetSupport. The group is estimated to have been active since at least late 2023. The targeting of Kyrgyzstan and Uzbekistan with similar initial access techniques marks an expansion of the threat actor’s operations in Central Asia, primarily by impersonating trusted government ministries in phishing emails to distribute malicious links or attachments. The attack chains broadly follow the same approach, as recipients of the messages are tricked into clicking on links that download malicious Java archive (JAR) loader files along with instructions to install the Java Runtime.

See also: Russian hackers target American engineering company

Bloody Wolf expands attacks with Java-based NetSupport RAT

While the email claims that installation is necessary to view the documents, the reality is that it is used to execute the loader. Once launched, the loader proceeds to retrieve the next payload stage (i.e., the NetSupport RAT) from infrastructure controlled by the attacker and establishes a persistent presence in three ways:

  • – Create a scheduled task
  • – Adding a value to the Windows Registry
  • – Dropping a batch script into the “%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup” folder

The Uzbekistan phase of the campaign is notable for incorporating geofencing, causing requests originating outside the country to be redirected to the legitimate data.egov[.]uz. Requests from within Uzbekistan have been found to trigger the download of the JAR file from an embedded link within the attached PDF.

See also: US: $10 million reward for information on Russian FSB hackers

Bloody Wolf expands attacks with Java-based NetSupport RAT

Group-IB reported that the JAR loaders observed in the campaigns are built with Java 8, which was released in March 2014. It is believed that the attackers are using a custom JAR generator or template to create these objects.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS