VayGren and Mr.Burns: Strong Ties in Finance
· Published 10/07/2024 09:49 · Modified 10/07/2024 10:18
Essential information
- Published
- 10/07/2024 09:49
- Modified
- 10/07/2024 10:18
- Tags
- 2024-07-10 ave maria burnsrat metastealer purecrypter purelogs redline stealer teamviewer warzonerat
- Related entities
- 131 observables, 1 intrusion sets (apt), 31 techniques (mitre), 9 malware, 1 others
Description
F.A.C.C.T experts analyzed the tools and connections of cybercriminals attacking Russian accountants. An analysis of the infection chain of the VasyGrek attacker, his forum activity and connection with the malware developer Mr.Burns is presented. The history of Mr.Burns, starting in 2010, is given, as well as a description of the current version of the BurnsRAT malware, sold on forums and used in attacks on Russian companies.
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Observables (131)
-
ebdce7eae3a77ed05ed6279c46a8be8c560085f82ce0f9e4de0ad8c700c16fc4 -
f7878a67c6de2ff26c79ab890e4a60b76c67a7583c6a24bd96cd93a5f4a0e0aa -
e4a91db9e43655931fd3926ec00dbe8a063fbe0d3f0af7d902fd3b9d8281fb3d -
e360674d2abf0bea085d01bc3595e19efb3ac061ab8090a32d0c579c621c46f6 -
d79d130aa4f0b207e741909c45be613a1e3720cb82a0578012cc508c28da6bad -
c3b30120feef022d552f85b780d4c988ee82bc07e6b5948db5d32e59d44fa704 -
c2f97483f8a5a96fa39e8bd3d3458093ac527a8c8efd662e838d95a9bc2354fb -
bf9fc94905d75ccf3640d35899d533e50c7ba8bdce396443ae2d0507657a9e81 -
bbad7c6e8f0d7ae94941257e7ece4d2b144aad56e25760c8876b808f3e8420e6 -
ba629f7ee519379f1a5a8a4683ee9a48d1b0996268bfaf1162e4bf0f2b792b77 -
b2193cb3f8bd13c8a5769d5ce499a36b9c44e2eb2800bcdf22320525beaf9586 -
af8018b310bf030f6feca0f6f23d3e65f8926114d7cd493573badae24f5da0d1
Intrusion sets (APT) (1)
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Techniques (MITRE) (31)
-
Browser Information Discovery MITRE
-
Service Execution MITRE
-
Windows Service MITRE
-
Credentials In Files MITRE
-
Masquerade Task or Service MITRE
-
Symmetric Cryptography MITRE
-
Credentials from Web Browsers MITRE
-
Software Packing MITRE
-
Portable Executable Injection MITRE
-
System Checks MITRE
-
Windows Command Shell MITRE
-
Spearphishing Link MITRE
Malware (9)
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Family
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Family The MITRE Corporation Confidence 100
[RedLine Stealer](https://attack.mitre.org/software/S1240) is an information-stealer malware variant first identified in 2020.(Citation: ESET RedLine Stealer November 2024)(Citation: Proofpoint RedLine Stealer March 2020)(Citation: Splunk RedLine Stealer June 2023) [RedLine Stealer](https://attack.mitre.org/software/S1240)…
First seen 01/01/1970 · Last seen 16/11/5138 · -
AlienVault Confidence 100
PureCrypter is a fully-featured malware loader, developed by a threat actor called “PureCoder," that has been in use since at least 2021 to distribute a variety of remote…
First seen 01/01/1970 · Last seen 16/11/5138 ·
Others (1)
-
Finance