EXECUTIVE SUMMARY
The Bloody Wolf threat actor group has been observed launching a phishing campaign targeting organizations in Kazakhstan. This campaign utilizes STRRAT, a commercial malware also known as Strigoi Master. The attackers send phishing emails impersonating the country’s regulatory agencies, with malicious PDF attachments that contain links to download the malware and a Java interpreter installation guide, required for the malware’s operation. It demonstrates a strategic approach, using less common file types and legitimate web services to bypass defenses and evade detection.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
The Bloody Wolf threat actor group has been observed launching a phishing campaign targeting organizations in Kazakhstan. This campaign utilizes STRRAT, a commercial malware also known as Strigoi Master. The attackers send phishing emails impersonating the country’s regulatory agencies, with malicious PDF attachments that contain links to download the malware and a Java interpreter installation guide, required for the malware’s operation. It demonstrates a strategic approach, using less common file types and legitimate web services to bypass defenses and evade detection.[emaillocker id="1283"]
The phishing emails carry PDF attachments that pose as non-compliance notices. These documents include links to malicious JAR files, which are less commonly used and help the attackers bypass security defenses. One of the links leads to a legitimate government website that encourages users to install Java, further enhancing the attack's credibility. The STRRAT malware, once executed, downloads dependencies such as system-hook keylogger libraries from public repositories like GitHub. It then establishes persistence by copying itself to various directories, creating scheduled tasks, and modifying registry keys. The malware communicates with its C2 server via Pastebin links and gathers extensive system information, including device name, supported languages, and antivirus software status. STRRAT can execute a wide range of commands from the C2 server, such as rebooting or shutting down the system, downloading and executing additional files, running commands interactively, intercepting keystrokes, managing startup programs, and controlling the victim’s browser and screen remotely. Additionally, the malware can install a proxy, establish remote connections, collect browser, and mail client data, restart processes with administrator privileges, and encrypt user files with a .crimson extension.
This campaign underscores the evolving tactics of cyber espionage groups like Bloody Wolf, who are increasingly leveraging commercial malware and phishing strategies to target critical sectors. By exploiting legitimate services and deploying multi-stage payloads, they can evade detection and maintain long-term persistence within compromised networks. Organizations should enhance their email security, monitor for unusual file types, and implement advanced threat detection mechanisms to mitigate such threats.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1566 | Phishing |
| Execution | T1059 | Command and Scripting Interpreter |
| T1204 | User Execution | |
| Persistence | T1053 | Scheduled Task/Job |
| T1136 | Create Account | |
| T1547 | Boot or Logon Autostart Execution | |
| Privilege Escalation | T1134 | Access Token Manipulation |
| Defense Evasion | T1070 | Indicator Removal |
| T1112 | Modify Registry | |
| T1564 | Hide Artifacts | |
| Credential Access | T1056 | Input Capture |
| T1555 | Credentials from Password Stores | |
| Discovery | T1057 | Process Discovery |
| T1082 | System Information Discovery | |
| T1518 | Software Discovery | |
| Collection | T1113 | Screen Capture |
| T1185 | Browser Session Hijacking | |
| Command and Control | T1090 | Proxy |
| T1102 | Web Service | |
| T1105 | Ingress Tool Transfer | |
| Impact | T1486 | Data Encrypted for Impact |
| T1529 | System Shutdown/Reboot |
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/08/kazakh-organizations-targeted-by-bloody.html