Skip to content
CYCRAFT
SECURING SESSION
CyCraft
Back to Blog
Threat Intel01 Dec 2025

Hackers Posing as Kyrgyzstan Justice Ministry Spread NetSupport RAT via Fake PDFs

Bloody Wolf is hiding NetSupport RAT inside fake Justice Ministry PDFs and Java installers and old-school tactics keep catching unprepared victims across Central Asia.

By EthicalByte8 min read

NetSupport RAT Campaign Hackers Pretend to be Kyrgyz Ministry

A new campaign by the hacking group Bloody Wolf is distributing a well-known remote-access trojan NetSupport RAT across Kyrgyzstan and Uzbekistan. The attackers pose as the country's Justice Ministry and send fake PDF documents or Java-based installers to lure victims. Once opened, the RAT installs silently, giving full remote control to attackers.

Attack Vector: Fake PDFs + Old Java Exploits

The infection begins when targets receive a PDF or a seemingly legitimate file claiming to be from the "Justice Ministry." The payload uses legacy techniques: outdated Java exploits or bundled installers often ignored by modern users but still effective in regions where security hygiene is weak.

  • PDF disguised as an official legal document or notice.
  • Embedded or accompanying Java-based installer leading to RAT deployment.
  • NetSupport RAT runs quietly in background, granting remote access.
  • The malware disables or bypasses common antivirus tools to stay hidden.

Target Region & Impact

According to researchers, the campaign is concentrated in Kyrgyzstan and Uzbekistan. Victims include individuals and small-scale organizations who likely receive unexpected "official documents." Because the malware uses older tools, many traditional detections miss it making it especially dangerous for regions with lower cyber-security awareness.

Why Old Malware Still Works

Even though NetSupport RAT has been around since 2013, the combination of social engineering + outdated attack vectors remains surprisingly effective especially in areas where:

  • Users ignore software-update prompts.
  • Security tools are outdated or absent.
  • Users are unfamiliar with phishing tactics.
  • Legal-looking PDFs evoke trust, leading to lowered guard.

The campaign is a reminder: old malware + new victims = dangerous success.

NetSupport RATBloody WolfKyrgyzstanUzbekistanAndroid & Windows SecurityMalware Campaign

Interactions

18

Comments (0)

Anonymous