[ << ALL_FEED ]

DarkGaboon. The venom of a cyber-viper in the digital veins of Russian companies

More in General

DarkGaboon. The venom of a cyber viper in the digital veins of Russian companies 🐍

In January of this year, the cyber intelligence group of the TI department at PT ESC exposed a previously unknown financially motivated APT group DarkGaboon, whose cyberattacks against Russian companies were traced back to spring 2023.

The evolution of the malicious arsenal, infrastructure migration, and TTPs of the group were studied, but tools and techniques for the final impact were missing to fully reconstruct the kill chain. However, this spring, the department for comprehensive cyber threat response directly encountered DarkGaboon cyberattacks during incident investigations. The missing pieces of the kill-chain puzzle turned out to be a network share scanner and the LockBit ransomware.

📥 PT ESC experts discovered that DarkGaboon uses emails with RAT trojans Revenge and XWorm disguised as financial documents as the penetration vector, which are sent from an SMTP server located in Russia (185.185.70.85) and over 50 associated domains in the Russian domain zone.

To manage RAT sessions on infected hosts, the group uses a Windows host registered in Seychelles with an RDP connection, rented from the US hosting provider Nybula LLC, and a group of DDNS domains.

196.251.66.118
myhost.servepics.com
myhost.misecure.com
kilimanjaro.theworkpc.com

Artifacts discovered by PT ESC experts during incidents made it possible to link DarkGaboon to a whole series of cyberattacks in 2023–2025 against Russian companies using the LockBit ransomware.

Details — in our blog.

#TI #APT #Malware
@ptescalator

More from ti_author

More from ti_author

More in General