[ << ALL_FEED ]

Phantom pains

More in General

Phantom pains 👻

In May, the Threat Intelligence department of the Positive Technologies Expert Security Center (PT ESC TI) discovered a new large-scale cyber espionage campaign by the APT group PhantomCore targeting Russia’s critical infrastructure.

The external perimeter of the cyberattack and the malicious arsenal were simultaneously described by Russian and foreign cybersecurity vendors. However, the PT ESC TI cyber intelligence team focused on a deeper investigation of the threat, which made it possible to:

🖥 discover key infrastructure: compromised Russian websites, phishing resources with FakeCaptcha, payload hubs, MeshCentral servers, SSH tunnels, the Phantom control panel;

👾 study and cover with detection rules the updated malicious arsenal: from open-source utilities popular in the cybercriminal environment (RSocx, MeshAgent, RClone, XenArmor Password Recovery) and updated versions of known tools from the personal arsenal (PhantomRAT) to previously unseen custom samples: PhantomRShell, PhantomProxyLite, PhantomTaskShell, PhantomStealer;

🥷 study the TTP and kill chain of cyberattacks, describe in detail the procedures performed on infected hosts;

🌐 study the geography, timeline, characteristics, and scale of the cyberattacks: more than 180 infections in Russia from May to July, 56% of which occurred on June 30; 49 hosts remain under the group’s control; the average time hackers spend in a compromised network is 24 days, with a maximum of 78 days;

📞 identify and notify victims among Russian government agencies, research institutes, defense industry enterprises, the shipbuilding sector, the chemical, mining, and manufacturing industries, as well as IT companies.

In addition, the PT ESC TI cyber intelligence team managed to discover a branch of the group not part of the main core. It consisted of low-skilled individuals recruited from Russian-language gaming Discord communities and was organized as its own cybercriminal startup by one of the members of the main PhantomCore core who had access to the source code of custom tools.

🫱 Full report — in our blog.

#TI #APT
@ptescalator

More from ti_author

More from ti_author

More in General