Bloody Wolf Intensifies Spear-Phishing Campaign Using NetSupport RAT

Bloody Wolf Intensifies Spear-Phishing Campaign Using NetSupport RAT

First seen 10 Feb 2026, 04:55 UTC CybersecuritynewsRescanaGbhackersCyberpressScworld 28.7

Article Content

Browse articles
ThreatCluster

The threat actor known as Bloody Wolf has escalated its spear-phishing campaign targeting organizations in Uzbekistan and Russia, utilizing the remote administration tool NetSupport RAT. Active since at least 2023, this campaign employs sophisticated techniques including custom Java-based loaders and multi-layered persistence mechanisms, with infrastructure overlap with IoT malware like the Mirai botnet. The group has also targeted government and private sectors in Kyrgyzstan since June 2025, using weaponized PDF documents that mimic official communications.

Timeline

2023-01-01
Bloody Wolf's spear-phishing campaign begins
2025-06-30
Bloody Wolf intensifies operations in Kyrgyzstan
2025-12-01
Cybersecuritynews reports on Bloody Wolf's tactics
2026-02-09
Rescana reports on Bloody Wolf's activities targeting Uzbekistan and Russia