216.73.216.6

Analyzing the familiar tools used by the Crypt Ghouls hacktivists

· Published 18/10/2024 14:09 · Modified 21/10/2024 09:54

Export JSON

Essential information

Published
18/10/2024 14:09
Modified
21/10/2024 09:54
Tags
2024-10-18 babuk cobint credential harvesting hacktivism lateral movement lockbit lockbit 3.0 ransomware russia xenallpasswordpro
Related entities
1 observables, 1 intrusion sets (apt), 18 techniques (mitre), 5 malware, 5 others

Description

The Crypt Ghouls group is targeting Russian businesses and government agencies with attacks. They utilize a toolkit including utilities like Mimikatz, , PingCastle, and others. The group employs and as final payloads. Initial access is often gained through compromised contractor credentials. The attackers use various techniques to harvest login credentials, perform network reconnaissance, and spread laterally. There are overlaps in tools and tactics with other groups targeting , suggesting potential collaboration or resource sharing among threat actors. Victims include Russian government agencies and companies in mining, energy, finance, and retail sectors.

External references