Application security, Threat Intelligence

Broader targeting conducted by Bloody Wolf APT

A computer screen with Javascript is seen

Infosecurity Magazine reports that attacks by the advanced persistent threat group Bloody Wolf that exploited Java to spread the NetSupport remote administration tool have reached Uzbekistan in October after being initially aimed at Kyrgyzstan in June.

Malicious PDFs, domains, and instructions purporting to be from the Ministry of Justice have been used by Bloody Wolf to lure targets into downloading Java to view sent case files, a joint analysis from Group-IB and UKUK showed. However, opening the JAR file prompts the retrieval of NetSupport binaries over HTTP, the use of autorun entries for persistence, the creation of scheduled tasks, and the showing of fraudulent error messages. Attackers' use of an old NetSupport Manager iteration contrasts with their previous utilization of STRRAT.

"[Bloody Wolf's] shift from traditional malware to legitimate remote-administration software indicates an ongoing evolution of tactics aimed at evading detection and blending into normal IT activity. Given the group's adaptability and persistence, organizations in Central Asia should remain vigilant for expected continued spear-phishing activity and evolving infection chains in the near future," said researchers.

You can skip this ad in 5 seconds