216.73.217.22

Key Group uses leaked builders of ransomware and wipers

· Published 02/10/2024 08:51 · Modified 02/10/2024 10:52

Export JSON

Essential information

Published
02/10/2024 08:51
Modified
02/10/2024 10:52
Tags
2024-10-02 annabelle chaos hakuna matata judge/nocry leaked builders multi-stage loaders njrat persistence phishing ransomware ruransom russian-speaking slam telegram ux-cryptor wiper xorist
Related entities
24 observables, 1 intrusion sets (apt), 17 techniques (mitre), 12 malware, 1 others

Description

Key Group, also known as keygroup777, is a financially motivated group primarily targeting Russian users. The group has been active since 2022, using various leaked builders and wipers, including , , , , , , , and . They distribute their malware through emails and GitHub repositories, often using . Key Group employs various methods and primarily communicates with victims via . The group is suspected to be a subsidiary project of the 'huis' group, known for conducting spam raids on channels. Key Group's use of publicly available builders highlights a growing trend among cybercriminal groups.

External references