216.73.216.6

Bloody Wolf evolution: new targets, new tools

· Published 20/02/2025 19:47 · Modified 21/02/2025 10:29

Export JSON

Essential information

Published
20/02/2025 19:47
Modified
21/02/2025 10:29
Tags
2025-02-20 edr jar files kazakhstan netsupport phishing remote administration russia strrat telegram
Related entities
1 intrusion sets (apt), 11 techniques (mitre), 1 malware, 4 others

Description

Bloody Wolf, a notorious threat actor, has shifted its tactics by replacing malware with the legitimate tool . The group has expanded its targets to include organizations in both and , compromising over 400 systems. Their attack method involves emails with PDF attachments containing links to malicious . These files download and install components, enabling full system access. The campaign exploits the prevalence of remote work and the increased use of software. The attackers' use of legitimate tools makes detection more challenging for conventional defenses. The report provides detailed technical information about the attack process and indicators of compromise.

External references