Crypt Ghouls
· Published 21/12/2025 08:00 · Modified 21/12/2025 08:00
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 21/12/2025 08:00
- Modified
- 21/12/2025 08:00
- Updated at
- 21/12/2025 08:00
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 1 reports, 18 attack patterns (mitre), 4 malware, 4 sectors, 1 countries, 12 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (1)
-
18 MITREs 5 Malwares 1 Observable 1 APT
Attack patterns (MITRE) (18)
-
T1003 usesOS Credential Dumping MITRE
-
T1082 usesSystem Information Discovery MITRE
-
T1486 usesData Encrypted for Impact MITRE
-
T1112 usesModify Registry MITRE
-
T1562.001 usesDisable or Modify Tools MITRE
-
T1135 usesNetwork Share Discovery MITRE
-
T1016 usesSystem Network Configuration Discovery MITRE
-
T1490 usesInhibit System Recovery MITRE
-
T1543.003 usesWindows Service MITRE
-
T1055 usesProcess Injection MITRE
-
T1068 usesExploitation for Privilege Escalation MITRE
-
T1059.001 usesPowerShell MITRE
Malware (4)
-
Babuk - S0638 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
CobInt usesFamily
-
LockBit Black usesFamily
-
Babyk usesFamily
Sectors (4)
-
Energy targets
-
Retail targets
-
Finance targets
-
Government targets
Countries (1)
-
Russian Federation targets
Indicators (12)
-
a27d900b1f94cb9e970c5d3b2dcf6686b02fb722eda30c85acc05ba55fdabfbcindicates -
56682344aa1dc0a0a5b0d26bd3a8dfe8ceb8772d6cd9e3f8cbd78ca78fe3c2abindicates -
stix 100/100 Revoked· Valid until 14/10/2025 · Source: AlienVault
-
3edb6fb033cc00c016520e2590e2888e393ad5ed725e853eea3bc86cee3b28b8indicates -
http://localtonet.com/nssm-2.24.zipindicatesstix 100/100 Revoked· Valid until 04/12/2024 · Source: AlienVault -
stix 100/100 Revoked· Valid until 14/10/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 19/09/2025 · Source: AlienVault
-
7c1b1e8c880a30c43b3a52ee245f963a977e1f40284f4b83f4b9afe3821753ddindicates -
stix 100/100 Revoked· Valid until 14/10/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 14/10/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 04/12/2024 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 14/10/2025 · Source: AlienVault