Executive Summary
In mid-2025, the threat actor known as Bloody Wolf launched a targeted cyber campaign against government and enterprise entities in Kyrgyzstan, later expanding its operations to Uzbekistan by October 2025. Utilizing sophisticated phishing lures, attackers delivered Java-based loaders that deployed the NetSupport Remote Access Trojan (RAT), allowing persistent access and potential data exfiltration. The campaign featured advanced evasion tactics, encrypted command-and-control traffic, and was attributed by Group-IB and local cybersecurity agencies. Affected organizations faced risks of unauthorized network access and potential compromise of sensitive information.
This incident highlights ongoing regional cybercrime escalation, especially the trend of weaponizing legitimate tools like NetSupport RAT through creative malware loaders. With cross-border expansion and zero-day techniques, the event exemplifies how remote access trojans are reshaping threat landscapes and driving demand for advanced network and east-west traffic controls.
Why This Matters Now
Remote access trojans like NetSupport enable threat actors to covertly maintain persistent access and escalate attacks within high-value targets. The Bloody Wolf campaign’s spread into Central Asia underscores the urgent need for organizations to strengthen internal segmentation, anomaly detection, and encrypted traffic inspection to counter evolving lateral movement and exfiltration tactics.
Attack Path Analysis
Bloody Wolf initiated its campaign by delivering NetSupport RAT via phishing, exploiting user trust to establish a foothold in victim environments. After gaining access, the adversary attempted privilege escalation to obtain broader permissions, leveraging potential credential theft or local misconfigurations. The attackers then moved laterally within networks, seeking to expand control to other workloads or services. Using the RAT, they established persistent command-and-control channels to remote infrastructure, stealthily operating with encrypted communication. Sensitive data was exfiltrated through covert or application-layer channels. The campaign’s main impact involved data theft and persistent unauthorized access, posing risks to business continuity.
Kill Chain Progression
Initial Compromise
Description
Attackers delivered malicious Java-based NetSupport RAT via phishing emails to compromise user endpoints and gain initial access.
Related CVEs
CVE-2025-34181
CVSS 8.7A path traversal vulnerability in NetSupport Manager versions prior to 14.12.0001 allows authenticated attackers to write arbitrary files to server locations, potentially leading to remote code execution.
Affected Products:
NetSupport NetSupport Manager – < 14.12.0001
Exploit Status:
proof of concept
MITRE ATT&CK® Techniques
Spearphishing Attachment
Malicious File
Remote Access Software
Command and Scripting Interpreter: Java
Application Layer Protocol: Web Protocols
Registry Run Keys / Startup Folder
Obfuscated Files or Information
Input Capture: Keylogging
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Incident Response Testing
Control ID: 12.10.5
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 10
CISA Zero Trust Maturity Model 2.0 – Strong Authentication and Access Controls
Control ID: Identity Pillar - Strong Authentication
NIS2 Directive – Cybersecurity Risk-management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Critical target for Bloody Wolf's NetSupport RAT campaign in Central Asia, requiring enhanced threat detection and east-west traffic security for sensitive government operations.
Financial Services
High-value target vulnerable to Remote Access Trojan attacks, needing zero trust segmentation and encrypted traffic protection against state-sponsored lateral movement threats.
Telecommunications
Infrastructure sector at risk from geographic expansion of RAT attacks, requiring multicloud visibility and egress security to prevent data exfiltration and network compromise.
Information Technology/IT
Primary attack vector for NetSupport RAT deployment through compromised systems, necessitating inline IPS and anomaly detection for Java-based threat prevention capabilities.
Sources
- Bloody Wolf Expands Java-based NetSupport RAT Attacks in Kyrgyzstan and Uzbekistanhttps://thehackernews.com/2025/11/bloody-wolf-expands-java-based.htmlVerified
- NetSupport RAT: The RAT King Returnshttps://blogs.vmware.com/security/2023/11/netsupport-rat-the-rat-king-returns.htmlVerified
- CVE-2025-34181 - NetSupport Manager < 14.12.0001 Authenticated Path Traversal Arbitrary File Write RCEhttps://cvefeed.io/vuln/detail/CVE-2025-34181Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Implementing CNSF capabilities such as zero trust segmentation, east-west traffic monitoring, threat detection, and strict egress controls would have significantly limited adversary movement, detected anomalies, and prevented data exfiltration throughout the attack lifecycle. These controls collectively raise the bar for unauthorized persistence and data theft by tightly monitoring, segmenting, and governing all traffic flows and privileged actions.
Control: Threat Detection & Anomaly Response
Mitigation: Early detection of suspicious activity or covert remote access attempts.
Control: Zero Trust Segmentation
Mitigation: Restricted access paths minimized the attack surface for privilege escalation.
Control: East-West Traffic Security
Mitigation: Blocked unauthorized internal movement and generated alerts on suspicious inter-workload communication.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: In-line inspection and distributed policy enforcement detect or block C2 channels.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound exfiltration attempts are restricted, logged, or blocked.
Comprehensive visibility expedited response to rapidly contain and remediate unauthorized access.
Impact at a Glance
Affected Business Functions
- Finance
- Government Operations
- Information Technology
Estimated downtime: 5 days
Estimated loss: $500,000
Potential exposure of sensitive government and financial data, including personally identifiable information (PII) and confidential communications.
Recommended Actions
Key Takeaways & Next Steps
- • Implement zero trust segmentation and microsegmentation to isolate sensitive workloads and restrict east-west movement.
- • Deploy egress policy enforcement to monitor, filter, and control outbound traffic, thereby preventing unauthorized data exfiltration.
- • Enable advanced threat detection and anomaly response capabilities that baseline environment behavior and alert on covert RAT or C2 activities.
- • Ensure continuous centralized visibility across multi-cloud environments for rapid detection and incident response.
- • Regularly review and enforce least privilege access practices and automation for privileged resource governance.



