216.73.217.22

Infostealer Campaign against ISPs

· Published 11/03/2025 14:14 · Modified 11/03/2025 16:53

Export JSON

Essential information

Published
11/03/2025 14:14
Modified
11/03/2025 16:53
Tags
2025-03-11 brute-force cryptomining infostealer persistence scripting
Related entities
18 techniques (mitre), 5 malware, 3 others

Description

A campaign targeting ISP infrastructure providers on the West Coast of the United States and China has been identified. Originating from Eastern Europe, the attackers use simple tools to abuse victims' computer processing power for and credential theft. The initial access is gained through brute force attacks using weak credentials. The malware has diverse functions including data exfiltration, additional crimeware deployment, self-termination to avoid detection, establishment, remote access disabling, and pivot attacks to targeted CIDRs. The actors perform minimal intrusive operations, relying on languages and API calls for C2 operations. The campaign specifically targets ISP infrastructure, likely for purposes.

External references