[ << ALL_FEED ]

Keeping a finger on the Pulse: cyberattacks by the Mythic Likho group on Russia's critical information infrastructure

More in General

Keeping a finger on the Pulse: cyberattacks by the Mythic Likho group on Russia’s critical information infrastructure 🔮

The Threat Intelligence Department of Positive Technologies’ Expert Security Center (PT ESC) conducted a comprehensive study of Mythic Likho’s cyberattacks on Russia’s critical infrastructure, combining cyberthreat intelligence data, incident investigation findings, and publicly exposed traces of the group’s activity.

The goal of the study is to build an exhaustive industry-wide understanding of the group’s tactics, techniques, and attack tools.

Key characteristics of Mythic Likho’s cyberattacks:

📨 Use of compromised websites and email accounts of Russian institutions and organizations to store and deliver malicious tools.

🧛🏾‍♂️ Cyberattacks accompanied by elaborate social engineering: mimicking compromised organizations and their employees, corresponding with victims using a carefully crafted cover story.

🧬 An impressive arsenal of constantly evolving in-house tools: HuLoader and ReflectPulse loaders, Loki backdoor.

🤛🏼 Collaboration with the (Ex)Cobalt group.

Read more — in our blog 📖

#TI #APT #Malware
@ptescalator (X, Max)

More from ti_author

More from ti_author

More in General