Bloody Wolf, also tracked as Stan Ghouls, is a cybercriminal threat actor active since at least 2023 that conducts targeted spear-phishing campaigns primarily against organizations in Central Asia and Russia. Reported victim geography includes Uzbekistan, Russia, Kyrgyzstan, and Kazakhstan, with additional lower-volume or collateral infections observed in Belarus, Serbia, and Turkey. Targeted sectors include manufacturing, finance, information technology, government, logistics, healthcare, education, and justice-related entities. The group is known for using localized social engineering themes and impersonating government or judicial bodies, including ministries of justice and court-related institutions, to increase the credibility of phishing lures. Campaigns commonly begin with phishing emails carrying PDF decoys or links that lead victims to download a malicious loader. Bloody Wolf has used custom Java-based droppers and loaders that display fake error messages, perform basic execution checks, and limit repeated installation attempts before retrieving the final remote-access payload. A notable evolution in the group’s tooling is its shift from using STRRAT to abusing legitimate remote administration software, especially NetSupport Manager, as a remote access trojan. This allows the actor to blend malicious activity with normal administrative traffic and maintain interactive control over compromised systems. Persistence has been established through redundant mechanisms including Startup-folder scripts, Registry autorun entries, and scheduled tasks. Reporting also notes frequent infrastructure rotation, including registering fresh command-and-control domains for individual campaigns, and at least one case in which command-and-control information was staged through a legitimate web service. The actor’s operations are generally assessed as financially motivated, particularly given its interest in financial institutions, although some reporting has noted that extensive use of remote-access tooling could also support espionage objectives. Bloody Wolf has been linked to more than 60 victims in one campaign wave centered on Uzbekistan and Russia. Some reporting also observed Mirai-related payloads on infrastructure associated with the group, raising the possibility of experimentation with or expansion toward IoT-focused activity, although direct operational control of such tooling has not been conclusively established. Known aliases include Bloody Wolf APT and Stan Ghouls.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
75 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Дополнительные индикаторы компрометации и правило YARA для детектирования активности группы Stan Ghouls доступны клиентам сервиса аналитических отчетов об APT-угрозах.
Uses web services in its infrastructure, including storing C2 server addresses on Pastebin.
Impersonates government entities to socially engineer targets into downloading/using NetSupport Manager (abused as NetSupport RAT) for unauthorized remote access; associated with campaigns impacting Central Asia.
Targeting Russia and Uzbekistan; associated in this newsletter with use of NetSupport RAT.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.