216.73.216.233

Hacktivists attack Russian organizations using rare RATs

· Published 18/12/2024 12:48 · Modified 18/12/2024 14:37

Export JSON

Essential information

Published
18/12/2024 12:48
Modified
18/12/2024 14:37
Tags
2024-12-18 babuk belarus data destruction hacktivist lockbit meterpreter ransomware revenge rat russia spark rat telegram
Related entities
1 intrusion sets (apt), 11 techniques (mitre), 7 malware, 6 others

Description

The Cyber Anarchy Squad (C.A.S) is a group targeting Russian and Belarusian organizations since 2022. They exploit vulnerabilities in public services and use free tools to inflict maximum damage. The group employs rare remote access Trojans like and , alongside common tools like Mimikatz. C.A.S focuses on data theft and reputational damage, often collaborating with other groups. They use to spread information about attacks and victims. The group's tactics include initial access through exploit of public-facing applications, execution via PowerShell and cmd, persistence through registry keys and startup folders, defense evasion by disabling security tools, and credential access using various utilities. C.A.S encrypts victim infrastructure using leaked builders and can destroy data using system utilities.

External references