DarkGaboon. The venom of a cyber-viper in the digital veins of Russian companies

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
DarkGaboon. The venom of a cyber viper in the digital veins of Russian companies 🐍
In January of this year, the cyber intelligence group of the TI department at PT ESC exposed a previously unknown financially motivated APT group DarkGaboon, whose cyberattacks against Russian companies were traced back to spring 2023.
The evolution of the malicious arsenal, infrastructure migration, and TTPs of the group were studied, but tools and techniques for the final impact were missing to fully reconstruct the kill chain. However, this spring, the department for comprehensive cyber threat response directly encountered DarkGaboon cyberattacks during incident investigations. The missing pieces of the kill-chain puzzle turned out to be a network share scanner and the LockBit ransomware.
📥 PT ESC experts discovered that DarkGaboon uses emails with RAT trojans Revenge and XWorm disguised as financial documents as the penetration vector, which are sent from an SMTP server located in Russia (185.185.70.85) and over 50 associated domains in the Russian domain zone.
To manage RAT sessions on infected hosts, the group uses a Windows host registered in Seychelles with an RDP connection, rented from the US hosting provider Nybula LLC, and a group of DDNS domains.
196.251.66.118
myhost.servepics.com
myhost.misecure.com
kilimanjaro.theworkpc.com
Artifacts discovered by PT ESC experts during incidents made it possible to link DarkGaboon to a whole series of cyberattacks in 2023–2025 against Russian companies using the LockBit ransomware.
Details — in our blog.
#TI #APT #Malware
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



