HomeSecurityBloody Wolf targets Uzbekistan and Russia with NetSupport...

Bloody Wolf targets Uzbekistan and Russia with NetSupport RAT

The hacking group Bloody Wolf has been linked to a campaign, targeting Uzbekistan and Russia, to infect systems with the NetSupport RAT.

Bloody Wolf NetSupport

Cybersecurity firm Kaspersky is tracking this activity under the name Stan Ghouls. The threat group has been active since at least 2023, organizing attacks spear-phishing against the industrial, financial, and IT sectors in Russia, Kyrgyzstan, Kazakhstan, and Uzbekistan.

See also: Hackers target IT and OSINT professionals with new PyStoreRAT

The campaign is estimated to have affected around 50 victims in Uzbekistan, while 10 devices in Russia have also been affected. Other infections have been detected to a lesser extent in Kazakhstan, Turkey, Serbia and Belarus. Infection attempts have also been recorded on devices within government organizations, logistics companies, medical facilities and educational institutions.

“Given Stan Ghouls’ targeting of financial institutions, we believe their primary motivation is financial gain,” Kaspersky noted. “However, the widespread use of RATs may also indicate cyberespionage.”

Bloody Wolf: NetSupport RAT Usage

The hacking group has previously been linked to the use of STRRAT (also known as Strigoi Master). The misuse of NetSupport, a legitimate remote administration tool, is a new technique.

See also: Compromised dYdX packages on npm and PyPI distribute wallet thieves and RATs

In November 2025, Group-IB recorded phishing attacks targeting entities in Kyrgyzstan for distributing the tool.

Bloody Wolf targets Uzbekistan and Russia with NetSupport RAT

How does the attack work?

The attack chains are quite simple, using phishing emails loaded with malicious PDF attachments. The PDF documents embed links that, when clicked, lead to the download of a malicious loader that handles multiple tasks:

– It displays a fake error message to give the victim the impression that the application cannot be run on their computer.

– Checks if the number of previous RAT installation is less than three. If the number has reached or exceeded the limit, the loader displays an error message: “Attempts limit reached. Try on another computer.”

– Downloads the NetSupport RAT from external domains and launches it.

– Ensures the persistence of the NetSupport RAT by configuring an autorun script in the Startup folder, adding a NetSupport launch script (“run.bat”) to the autorun key in the Registry, and creating a scheduled task to trigger the execution of the same batch script.

See also: Odyssey Stealer: New malware campaign targets Mac computers

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Bloody Wolf targets Uzbekistan and Russia with NetSupport RAT

Kaspersky also detected Mirai botnet payloadsstored on infrastructure linked to Bloody Wolf, suggesting the group may have expanded its arsenal to target IoT devices.

“Over 60 targets have been affected. This is an extremely high volume for a sophisticated targeted campaign,” the company concluded. “This demonstrates the significant resources these actors are willing to invest in their operations.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS