Cybersecurity analysts have identified a series of coordinated attacks targeting organizations in Kazakhstan, perpetrated by a malicious entity known as “Bloody Wolf.” This group deploys STRRAT, a low-cost yet powerful piece of malware available on underground markets for around $80.
Since late 2023, the team at BI.ZONE Threat Intelligence has been monitoring Bloody Wolf’s operations. The attackers use advanced phishing schemes, posing as officials from Kazakhstan’s Ministry of Finance and other governmental bodies to distribute STRRAT, also referred to as Strigoi Master. According to BI.ZONE’s analysis, “This malware, priced as low as $80 on dark web marketplaces, enables attackers to seize control of corporate systems and access sensitive information.”
The phishing attacks involve emails with PDF attachments that appear to be compliance notices. These PDFs contain links to harmful Java archive (JAR) files and Java interpreter installation instructions, essential for the malware’s functionality.
To enhance the attack’s credibility, one link directs victims to an authentic government site that prompts Java installation for proper portal use. In contrast, the malware itself is hosted on a counterfeit government site (e.g., egov-kz[.]online), designed to imitate official Kazakhstan websites.
Once installed, STRRAT maintains persistence through various techniques, such as creating scheduled tasks, modifying the registry, and placing itself in the startup folder. It then communicates with command and control servers via Pastebin to exfiltrate data and receive further commands.
Capabilities of STRRAT include:
- Credential theft from major browsers and email clients
- Keylogging
- Remote command execution
- File manipulation
- Control over screen and browser
- Proxy installation
- Ransomware-like file encryption
“By utilizing less common file types like JAR, the attackers manage to bypass traditional defenses,” BI.ZONE pointed out. “Leveraging legitimate services like Pastebin for communications allows them to evade many network security measures.”
This incident underscores a growing trend of cybercriminals using affordable, commercially available malware to execute intricate attacks against both governmental and corporate targets.
Indicators of compromise include:
- e35370cb7c8691b5fdd9f57f3f462807b40b067e305ce30eabc16e0642eca06b
- 00172976ee3057dd6555734af28759add7daea55047eb6f627e5491701c3ec83
- cb55cf3e486f3cbe3756b9b3abf1673099384a64127c99d9065aa26433281167
- a6fb286732466178768b494103e59a9e143d77d49445a876ebd3a40904e2f0b0
- 25c622e702b68fd561db1aec392ac01742e757724dd5276b348c11b6c5e23e59
- 14ec3d03602467f8ad2e26eef7ce950f67826d23fedb16f30d5cf9c99dfeb058
- ee113a592431014f44547b144934a470a1f7ab4abec70ba1052a4feb3d15d5c6
- https://pastebin[.]com/raw/dFKy3ZDm:13570
- https://pastebin[.]com/raw/dLzt4tRB:13569
- https://pastebin[.]com/raw/dLzt4tRB:10101
- https://pastebin[.]com/raw/YZLySxsv:20202
- https://pastebin[.]com/raw/8umPhg86:13772
- https://pastebin[.]com/raw/67b8GSUQ:13671
- https://pastebin[.]com/raw/8umPhg86:13771
- https://pastebin[.]com/raw/67b8GSUQ:13672
- https://pastebin[.]com/raw/dLzt4tRB:13880
- https://pastebin[.]com/raw/YZLySxsv:13881
- 91.92.240[.]188
- 185.196.10[.]116



