The Return of the Blood Wolf

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
Since early May, the PT ESC cyber intelligence team has discovered a new wave of attacks by the Bloody Wolf group against organizations in Kyrgyzstan.
Previously, colleagues described the attack chain used by this group against users in Kazakhstan and Russia. In the current campaign, we see Bloody Wolf’s signature style (with some exceptions).
The attack chain still begins with a phishing email containing an attached PDF file (screenshot 1). The document contains a notification about an inspection purportedly from the tax service, prosecutor general’s office, or judicial department, along with links to download materials. Opening them requires Java, and installation instructions are also included in the attachments. Since early May, we have identified 40 such PDF files uploaded to public sandboxes, predominantly from Kyrgyzstan (screenshots 2–5) 📁
Interestingly, the links for the Russian and Kyrgyz languages differ and lead to different domains, although the final payload is identical — only the names of created folders, registry keys, and scheduled tasks differ. The URLs from which files are downloaded are quite long, for example:
http://esf-kg.com/api/public/storage/cases/7432612384dio/ispolnitelnyj_protsess/accounts/companies/clients/420523/attachments_823664/registered/files7312518/download/PostanovleniePrivate1.4KG.jar
Code language: YAML (yaml)The use of such long URLs may be intended to mimic the structure of real government portals so as not to arouse the victim’s suspicion 🏢
After following the link, a JAR loader is downloaded (part of the code is shown in screenshot 6). When launched, it creates a folder with a specified name in the user’s Documents folder and downloads a set of files for NetSupport, after first checking node availability. It then opens
client32.exe — the main NetSupport file — and also establishes persistence in three ways: via a BAT file in the startup folder, via a registry key (Run), and via a scheduled task triggered at system logon. The loader also checks the number of times the file has been launched: if it exceeds three, it will not open. Additionally, when
client32.exe executes, a decoy window appears: in the latest samples, an error message; previously, an INN verification application (screenshots 7, 8).IoCs:
C2 NetSupport RAT:
hgame33.com
ravinads.com
Servers hosting JAR and NetSupport payload files:
auditnotice-kg.com
servicedoc-kg.com
esf-kg.com
tax-kg.com
minjust-kg.com
sti-salyk.com
sti-kg.com
PostanovleniePrivate1.4.jar
MD5:5c4a57e2e40049f8e8a6a74aa8085c80
SHA-1:15eb1cdd994b56f1d060137a2ac2f7fd7d10c48c
SHA-256:b10418925a91072e1e30438dc89ba12fbb3b0ead13f314919be33d476e3efa42
Постановление_Судебный_исполнитель_15833.pdf_с_уведомлением.pdf
MD5:b51d9edc1dc8b6200f260589a4300009
SHA-1:c5fcc1c71d5fbcadc2189d5cef6c026c14f4a11a
SHA-256:18d97b6014088df9ba731cf6327758fb500a0133b44c3d47122b341a3edb8d03
Code language: YAML (yaml)







#TI #Phishing #APT
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



