


Perceptive Security
SOC/SIEM Consultancy

Bloody Wolf Expands Java-based NetSupport RAT Attacks in Kyrgyzstan and Uzbekistan
Published:
27 november 2025 om 18:13:00
Alert date:
5 december 2025 om 08:03:22
Source:
thehackernews.com

The threat actor Bloody Wolf has been conducting cyber attack campaigns targeting Kyrgyzstan since at least June 2025, delivering NetSupport RAT malware. The campaign has expanded as of October 2025 to also target Uzbekistan. The attacks utilize Java-based NetSupport RAT to compromise systems in these Central Asian countries. Research was conducted by Group-IB in collaboration with Ukuk, a state enterprise. This represents an ongoing active campaign with geographic expansion indicating escalating threat activity.
Technical details
Mitigation steps:
Affected products:
NetSupport RAT
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.