Threat Advisory

Bloody Wolf Group Targets Kazakhstan with STRRAT Malware via Phishing Emails

Threat: Malware
Threat Actor Name: Bloody Wolf
Targeted Region: Kazakhstan
Targeted Sector: Government & Defense
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

The Bloody Wolf threat actor group has been observed launching a phishing campaign targeting organizations in Kazakhstan. This campaign utilizes STRRAT, a commercial malware also known as Strigoi Master. The attackers send phishing emails impersonating the country’s regulatory agencies, with malicious PDF attachments that contain links to download the malware and a Java interpreter installation guide, required for the malware’s operation. It demonstrates a strategic approach, using less common file types and legitimate web services to bypass defenses and evade detection.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

The Bloody Wolf threat actor group has been observed launching a phishing campaign targeting organizations in Kazakhstan. This campaign utilizes STRRAT, a commercial malware also known as Strigoi Master. The attackers send phishing emails impersonating the country’s regulatory agencies, with malicious PDF attachments that contain links to download the malware and a Java interpreter installation guide, required for the malware’s operation. It demonstrates a strategic approach, using less common file types and legitimate web services to bypass defenses and evade detection.[emaillocker id="1283"]

 

The phishing emails carry PDF attachments that pose as non-compliance notices. These documents include links to malicious JAR files, which are less commonly used and help the attackers bypass security defenses. One of the links leads to a legitimate government website that encourages users to install Java, further enhancing the attack's credibility. The STRRAT malware, once executed, downloads dependencies such as system-hook keylogger libraries from public repositories like GitHub. It then establishes persistence by copying itself to various directories, creating scheduled tasks, and modifying registry keys. The malware communicates with its C2 server via Pastebin links and gathers extensive system information, including device name, supported languages, and antivirus software status. STRRAT can execute a wide range of commands from the C2 server, such as rebooting or shutting down the system, downloading and executing additional files, running commands interactively, intercepting keystrokes, managing startup programs, and controlling the victim’s browser and screen remotely. Additionally, the malware can install a proxy, establish remote connections, collect browser, and mail client data, restart processes with administrator privileges, and encrypt user files with a .crimson extension.

 

This campaign underscores the evolving tactics of cyber espionage groups like Bloody Wolf, who are increasingly leveraging commercial malware and phishing strategies to target critical sectors. By exploiting legitimate services and deploying multi-stage payloads, they can evade detection and maintain long-term persistence within compromised networks. Organizations should enhance their email security, monitor for unusual file types, and implement advanced threat detection mechanisms to mitigate such threats.

THREAT PROFILE:

Tactic Technique Id Technique
 Initial Access  T1566 Phishing
Execution T1059 Command and Scripting Interpreter
T1204 User Execution
Persistence T1053 Scheduled Task/Job
T1136 Create Account
T1547 Boot or Logon Autostart Execution
Privilege Escalation T1134 Access Token Manipulation
Defense Evasion T1070 Indicator Removal
 T1112 Modify Registry
T1564 Hide Artifacts
Credential Access T1056 Input Capture
T1555 Credentials from Password Stores
 Discovery T1057 Process Discovery
T1082 System Information Discovery
 T1518 Software Discovery
Collection T1113 Screen Capture
T1185 Browser Session Hijacking
Command and Control T1090 Proxy
T1102 Web Service
T1105 Ingress Tool Transfer
Impact T1486 Data Encrypted for Impact
T1529 System Shutdown/Reboot

REFERENCES:

The following reports contain further technical details:
https://thehackernews.com/2024/08/kazakh-organizations-targeted-by-bloody.html

[/emaillocker]
crossmenu