[ << ALL_FEED ]

The Return of the Blood Wolf

More in General

The Return of the Bloody Wolf 🐺

Since early May, the PT ESC cyber intelligence team has discovered a new wave of attacks by the Bloody Wolf group against organizations in Kyrgyzstan.

Previously, colleagues described the attack chain used by this group against users in Kazakhstan and Russia. In the current campaign, we see Bloody Wolf’s signature style (with some exceptions).

The attack chain still begins with a phishing email containing an attached PDF file (screenshot 1). The document contains a notification about an inspection purportedly from the tax service, prosecutor general’s office, or judicial department, along with links to download materials. Opening them requires Java, and installation instructions are also included in the attachments. Since early May, we have identified 40 such PDF files uploaded to public sandboxes, predominantly from Kyrgyzstan (screenshots 2–5) 📁

Interestingly, the links for the Russian and Kyrgyz languages differ and lead to different domains, although the final payload is identical — only the names of created folders, registry keys, and scheduled tasks differ. The URLs from which files are downloaded are quite long, for example:

http://esf-kg.com/api/public/storage/cases/7432612384dio/ispolnitelnyj_protsess/accounts/companies/clients/420523/attachments_823664/registered/files7312518/download/PostanovleniePrivate1.4KG.jar
Code language: YAML (yaml)


The use of such long URLs may be intended to mimic the structure of real government portals so as not to arouse the victim’s suspicion 🏢

After following the link, a JAR loader is downloaded (part of the code is shown in screenshot 6). When launched, it creates a folder with a specified name in the user’s Documents folder and downloads a set of files for NetSupport, after first checking node availability. It then opens client32.exe — the main NetSupport file — and also establishes persistence in three ways: via a BAT file in the startup folder, via a registry key (Run), and via a scheduled task triggered at system logon.

The loader also checks the number of times the file has been launched: if it exceeds three, it will not open. Additionally, when client32.exe executes, a decoy window appears: in the latest samples, an error message; previously, an INN verification application (screenshots 7, 8).

IoCs:

C2 NetSupport RAT: 
hgame33.com
ravinads.com

Servers hosting JAR and NetSupport payload files:
auditnotice-kg.com
servicedoc-kg.com
esf-kg.com
tax-kg.com
minjust-kg.com
sti-salyk.com
sti-kg.com

PostanovleniePrivate1.4.jar
MD5:5c4a57e2e40049f8e8a6a74aa8085c80
SHA-1:15eb1cdd994b56f1d060137a2ac2f7fd7d10c48c
SHA-256:b10418925a91072e1e30438dc89ba12fbb3b0ead13f314919be33d476e3efa42

Постановление_Судебный_исполнитель_15833.pdf_с_уведомлением.pdf
MD5:b51d9edc1dc8b6200f260589a4300009
SHA-1:c5fcc1c71d5fbcadc2189d5cef6c026c14f4a11a
SHA-256:18d97b6014088df9ba731cf6327758fb500a0133b44c3d47122b341a3edb8d03
Code language: YAML (yaml)


#TI #Phishing #APT
@ptescalator

More from ti_author

More from ti_author

More in General