Full Report
Since late June 2025, Group-IB analysts observed a surge in spear-phishing emails across Central Asia. The attackers impersonate government agencies to gain the trust of their victims. This blog describes the techniques, tools and ongoing activity of the threat group known as Bloody Wolf.
Analysis Summary
# Threat Actor: Bloody Wolf
## Attribution & Identity
* **Name:** Bloody Wolf
* **Aliases:** None explicitly listed in the provided text, though the group is noted for its specific focus on Central Asian targets.
* **Known Associations:** The actor is noted for impersonating government agencies to build trust with victims.
## Activity Summary
* **Recent Campaigns:** Since late June 2025, the group has initiated a surge in spear-phishing campaigns.
* **Operations:** The group uses social engineering via emails that appear to originate from legitimate state bodies. They leverage specialized malware and local themes to compromise target environments.
## Tactics, Techniques & Procedures
* **Phishing:** Spear-phishing emails containing malicious attachments or links.
* **Social Engineering:** Impersonating government agencies (e.g., Ministries of Justice, Tax authorities).
* **Malware Execution:** Use of malicious files (likely loaders or stealers) to gain initial access.
* **MITRE ATT&CK IDs:**
* **T1566:** Phishing
* **T1036:** Masquerading
## Targeting
* **Sectors:** Government, Finance, Audit/Legal, and potentially Healthcare or Public Administration.
* **Geography:** Central Asia (specifically targeting entities in Kyrgyzstan and Uzbekistan based on domain names).
* **Victims:** Government agencies and related professional sectors (e.g., accounting and legal professionals).
## Tools & Infrastructure
* **Malware Families:** The report references several unique file hashes suggesting the use of custom loaders or reconnaissance tools (e.g., `d63ea8b4361a1b4f93f145bc813dc7435ff36cf2ced27ece0d48a9e6ac08c2be`).
* **Infrastructure (C2 & Domains):**
* minjust-kg[.]com (Impersonating Ministry of Justice, Kyrgyzstan)
* esf-kg[.]com
* audit-kg[.]com
* ach-uz[.]com
* uzaudit[.]com (Impersonating Uzbekistan audit services)
* soliq-uz[.]com (Impersonating Uzbekistan Tax Committee)
* hisobot-uz[.]com
* ttbbaits[.]com
* nac-ac[.]com
* hgame33[.]com
* ravinads[.]com
## Implications
Bloody Wolf represents a significant threat to regional stability in Central Asia. By successfully impersonating state authorities, they bypass traditional skepticism, leading to high infection rates. Their focus on government-adjacent sectors suggests an objective of cyber-espionage or the theft of sensitive state and financial data.
## Mitigations
* **Email Security:** Implement DMARC/SPF/DKIM and utilize advanced email filtering to detect spoofed domains.
* **Awareness Training:** Conduct phishing simulations specifically focused on government impersonation and domain typosquatting.
* **Network Monitoring:** Block all traffic to the identified indicators of compromise (IoCs) provided in the report.
* **Domain Monitoring:** Implement monitoring for newly registered domains that mimic official government web portals in Central Asia.