Rescana
Bloody Wolf Intensifies Spear-Phishing Campaign Using NetSupport RAT
Article Content
The threat actor known as Bloody Wolf has escalated its spear-phishing campaign targeting organizations in Uzbekistan and Russia, utilizing the remote administration tool NetSupport RAT. Active since at least 2023, this campaign employs sophisticated techniques including custom Java-based loaders and multi-layered persistence mechanisms, with infrastructure overlap with IoT malware like the Mirai botnet. The group has also targeted government and private sectors in Kyrgyzstan since June 2025, using weaponized PDF documents that mimic official communications.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.