The threat actor tracked as Bloody Wolf has conducted a large-scale malware distribution operation impacting organizations in Uzbekistan and Russia. Kaspersky Labs monitors this activity under the designation Stan Ghouls and has recorded operations dating back to at least 2023. The adversary has consistently targeted organizations in the manufacturing, financial, and IT sectors across Russia, Kyrgyzstan, Kazakhstan, and Uzbekistan.
The current wave of activity has resulted in the compromise of approximately 50 systems in Uzbekistan and a further 10 systems in Russia, with additional infections observed in Kazakhstan, Turkey, Serbia, and Belarus. Victims include not only commercial enterprises but also government entities, logistics organizations, healthcare institutions, and educational facilities, indicating broad targeting rather than narrowly scoped reconnaissance operations.
Motivation and Attribution
Assessment of victim selection patterns suggests financial gain as the primary objective, particularly given the focus on financial sector organizations. At the same time, widespread deployment of remote access trojans provides capabilities suitable for intelligence gathering, indicating the operations could support both financially motivated and information collection activities.
Technical Evolution and Tooling
The campaign reflects a technical transition in the group’s operational toolkit. Earlier operations relied on STRRAT, also known as Strigoi Master, whereas the current campaign employs NetSupport RAT, a legitimate remote administration product repurposed for malicious use. This transition became visible after Group-IB documented phishing operations targeting entities in Kyrgyzstan during November 2025 that deployed comparable tooling.
Attack Methodology and Technical Implementation
The infection chain follows a structured sequence aimed at achieving initial access while establishing durable persistence. Attackers distribute phishing emails containing malicious PDF attachments that function as the initial delivery mechanism. Embedded hyperlinks within these documents trigger a multi-stage payload retrieval process when activated by victims.
Once executed, the malicious loader performs several coordinated actions intended to mislead victims while securing system access. It displays a fabricated compatibility error to convince users that the program cannot run on their system, thereby reducing suspicion. The loader also includes an anti-replay control mechanism that records installation attempts and halts execution if three previous attempts are detected, presenting the message “Attempt limit reached. Try another computer.”
After completing these checks, the loader downloads the NetSupport RAT payload from attacker-controlled command-and-control infrastructure. Persistence is then implemented across multiple system components to maintain continued access. The loader places an autorun script in the Windows Startup folder, creates a Registry entry referencing a batch file that launches NetSupport, and configures a scheduled task to execute the same batch script at defined intervals.
Infrastructure Overlap and Capability Expansion
Analysis of infrastructure associated with Bloody Wolf has identified Mirai botnet components hosted on servers connected to the campaign. This overlap suggests potential expansion into attacks targeting Internet of Things devices, possibly to support distributed denial-of-service operations or enable additional compromise pathways. The combination of RAT deployment and botnet infrastructure points to a threat actor with broad technical capabilities and adaptable operational objectives.
Campaign Scale and Resource Investment
Confirmed compromise of more than 60 distinct targets represents a relatively large operational footprint for a campaign demonstrating both technical sophistication and focused targeting. Such scale indicates significant operational investment and may suggest either state-backed support or access to substantial criminal resources.
ExCobalt’s Multi-Vector Attacks Against Russian Infrastructure
Simultaneously with Bloody Wolf operations, Russian organizations are experiencing continued attacks from the ExCobalt threat group, which Positive Technologies describes as one of the most dangerous actors currently targeting Russian infrastructure. The group has evolved its initial access strategy, shifting from direct exploitation of externally exposed services toward supply chain compromise through infiltration of contractors and service providers.
Initial Access Evolution
The group has altered its network penetration approach, reducing reliance on exploitation of newly disclosed vulnerabilities affecting public-facing corporate services such as Microsoft Exchange. Current operations increasingly leverage compromise of third-party contractors as an entry point to primary targets, reflecting recognition that trusted partner connections can circumvent traditional perimeter defenses.
Credential Harvesting Operations
ExCobalt campaigns include advanced credential interception techniques targeting enterprise communication platforms. Attackers inject malicious scripts into Outlook Web Access authentication portals to capture login credentials during user authentication. In addition, operations focus on extracting Telegram credentials and stored message histories from compromised endpoints, indicating interest in sensitive private communications.
Malware Arsenal and Technical Capabilities
The group employs a diverse malware toolkit spanning multiple operational objectives.
- CobInt functions as the primary backdoor, providing persistent remote control of compromised hosts, enabling command execution, file operations, and lateral movement within affected environments.
- Ransomware deployment plays a substantial role in operations, with Babuk and LockBit variants used to encrypt victim data and extort payments. This activity supports financially motivated goals and may also finance continued operational development.
- PUMAKIT represents a kernel-mode rootkit operating at low system levels to enable privilege escalation, conceal files and directories, and hide malicious activity from security monitoring tools. PUMAKIT builds upon earlier rootkit families linked to related clusters, including Facefish observed in February 2021, Kitsune in February 2022, and Megatsune in November 2023. Kitsune was previously attributed to the Sneaky Wolf cluster, also tracked as Sneaking Leprechaun by BI.ZONE, suggesting possible tooling or operational relationships between groups.
- Octopus is a Rust-based toolkit designed for privilege escalation on Linux systems. Use of Rust demonstrates modern development practices that can complicate analysis and detection due to memory safety features and increasingly common legitimate adoption.
Punishing Owl: Emerging Hacktivist Threats
State institutions, research organizations, and IT companies in Russia have also become targets of an emerging threat actor identified as Punishing Owl. The group appears politically motivated rather than financially driven, employing data theft and public disclosure strategies typical of hacktivist operations.
Operational Timeline and Attribution Indicators
Activity attributed to the group began in December 2025, accompanied by social media channels used to publish threats and leak stolen information. Analysis of administrative access patterns indicates that at least one account connected to the operation is managed from Kazakhstan, although this does not conclusively determine the group’s geographic location or affiliation.
Attack Technique and Malware Deployment
Punishing Owl relies primarily on phishing campaigns distributing password-protected ZIP archives as the infection vector. Encryption prevents automated inspection of archive contents while also encouraging victims to treat the attachment as legitimate correspondence requiring manual action.
The archive contains a Windows shortcut file disguised as a PDF document using icon and filename manipulation. When opened, the LNK file executes a PowerShell command that downloads a custom information stealer named ZipWhisper from attacker infrastructure. The malware collects sensitive information from compromised systems and transmits it to the same remote servers used for payload delivery. Stolen data is subsequently published on dark web leak portals as part of public disclosure efforts intended to damage victims and demonstrate operational success.
This campaign illustrates how politically motivated threat actors can produce meaningful operational impact through relatively simple techniques that exploit human behavior and organizational security weaknesses rather than relying on complex technical exploits.