Bloody Wolf, also tracked as Stan Ghouls, is a cybercriminal threat actor active since at least 2023 that conducts targeted spear-phishing campaigns primarily against organizations in Central Asia and Russia. The group has targeted entities in Uzbekistan, Russia, Kazakhstan, and Kyrgyzstan, with additional lower-volume infections reported in Belarus, Serbia, and Turkey. Victim organizations span manufacturing, financial services, information technology, government, logistics, health care, and education, indicating broad but selective regional targeting. The actor is known for impersonating government and legal institutions, including ministries of justice and court-related entities, and for using localized lures in languages such as Uzbek and Kyrgyz. Its phishing emails commonly deliver malicious PDF decoys that direct victims to download a next-stage loader. Recent campaigns used a custom Java-based loader that displays fake error messages, performs execution checks, limits repeated installation attempts, downloads NetSupport Manager for unauthorized remote access, and establishes persistence through Startup-folder scripts, Registry autorun entries, and scheduled tasks. Earlier activity used STRRAT, showing an evolution from commodity malware toward abuse of legitimate remote administration software to blend into normal administrative traffic. Bloody Wolf has demonstrated infrastructure churn and operational adaptation, including frequent rotation of command-and-control domains and use of Pastebin to store command-and-control information. Reporting has also noted geo-fencing in some campaigns. The group’s operations are assessed as primarily financially motivated, particularly given its targeting of financial institutions, although some reporting has noted that its sustained use of remote access tooling leaves open the possibility of espionage-style collection. Mirai-related payloads were observed on infrastructure associated with the actor, suggesting either experimentation with or access to infrastructure also used for IoT-focused activity, but direct operational control of such activity remains unconfirmed.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
75 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Дополнительные индикаторы компрометации и правило YARA для детектирования активности группы Stan Ghouls доступны клиентам сервиса аналитических отчетов об APT-угрозах.
Uses web services in its infrastructure, including storing C2 server addresses on Pastebin.
Impersonates government entities to socially engineer targets into downloading/using NetSupport Manager (abused as NetSupport RAT) for unauthorized remote access; associated with campaigns impacting Central Asia.
Targeting Russia and Uzbekistan; associated in this newsletter with use of NetSupport RAT.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.