216.73.217.80

Strikes with commercial malware against organizations in Kazakhstan

· Published 01/08/2024 08:56 · Modified 01/08/2024 09:01

Export JSON

Essential information

Published
01/08/2024 08:56
Modified
01/08/2024 09:01
Tags
2024-08-01 data theft phishing remote access strigoi master strrat
Related entities
10 observables, 1 intrusion sets (apt), 16 techniques (mitre), 2 malware, 1 others

Description

BI.ZONE experts have been monitoring the activities of a threat group called Bloody Wolf since late 2023. This group targets organizations in Kazakhstan using , a commercial malware known as . The attackers employ emails posing as communications from government agencies, with attached PDFs containing malicious links. These links lead to the download of , along with a Java installation guide required for the malware's operation. The malware exhibits various capabilities, including keylogging, data exfiltration, remote control, and encryption of user files.

External references