Bloody Wolf is a cybercriminal threat actor active since at least 2023 that conducts targeted spear-phishing campaigns against organizations in Central Asia and Russia. The group is also tracked as Stan Ghouls and has been observed targeting entities in Uzbekistan, Kyrgyzstan, Kazakhstan, and Russia, with additional lower-volume victimization reported in other countries. Known victim sectors include government, finance, information technology, manufacturing, logistics, medical, education, and justice-related organizations. The actor is notable for impersonating government and legal institutions in localized phishing lures, including ministry, court, and judicial themes, to increase credibility with regional targets. Campaigns commonly use malicious PDF decoys that direct victims to retrieve a next-stage loader. Bloody Wolf has repeatedly used custom Java-based droppers or loaders that display fake error messages, perform basic execution checks, and in some cases limit repeated installation attempts, likely as a simple anti-analysis measure. Bloody Wolf historically used STRRAT, also known as Strigoi Master, and later shifted to abusing the legitimate remote administration product NetSupport Manager as a remote access trojan. This transition reflects a preference for blending malicious activity with legitimate administrative tooling. Once installed, NetSupport provides the operators with persistent remote access and broad control over compromised systems. Persistence has been established through redundant mechanisms including Startup-folder scripts, Registry autorun entries, and scheduled tasks. The group’s operations show regular infrastructure churn, including frequent refresh of command-and-control-related resources and campaign-specific delivery infrastructure. Reporting has also noted use of public web services to support operations. Some campaigns incorporated geofencing to constrain payload delivery to intended regional victims. Assessment of Bloody Wolf’s motive most strongly supports financially motivated crime, particularly given repeated targeting of financial institutions and use of commodity remote-access tooling. However, the breadth of targeting and sustained access enabled by remote administration tools means espionage cannot be fully excluded. Separate observations of Mirai-related payloads on infrastructure associated with the actor have been reported, but any direct operational expansion into IoT targeting remains unconfirmed. Aliases associated with this actor include Stan Ghouls and Bloody Wolf APT.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
75 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses web services in its infrastructure, including storing C2 server addresses on Pastebin.
Impersonates government entities to socially engineer targets into downloading/using NetSupport Manager (abused as NetSupport RAT) for unauthorized remote access; associated with campaigns impacting Central Asia.
Targeting Russia and Uzbekistan; associated in this newsletter with use of NetSupport RAT.
Threat group reported targeting Russia and Uzbekistan using NetSupport RAT.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.