How did SaT entangle several groups at once in a tangle?

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
How did CaT entangle several groups at once? 🧶
In the fall of 2024, our attention was drawn to an interesting tool discovered while studying the activity of the PhaseShifters group. It turned out to be a subscription-based crypter (CaaS) called Crypters And Tools — we already covered it in detail in the first part of our research: how it works, what sets it apart from others, and how its infrastructure is organized.
Now we return to the topic of APT groups, but shift the focus to other threat actors — TA558, Blind Eagle, and Aggah — whose activities we will examine in more detail.
🐾 Which groups definitely used Crypters And Tools in their attacks?
🔎 How interconnected are these groups that use CaT?
🇵🇰 How is Aggah faring after 2022?
🧩 How did we identify specific users?
💥 Which users are members of the TA558 group, and what does negrocock have to do with it?
🇳🇬 From which African country were 60 thousand emails sent, and what does Crypters And Tools have to do with it?
You will find answers to these and other questions in the second part of our article about Crypters And Tools.
#TI #APT #hacktool
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



