Hacktivists attack Russian organizations using rare RATs

Dec. 18, 2024, 2:37 p.m.

Description

The Cyber Anarchy Squad (C.A.S) is a hacktivist group targeting Russian and Belarusian organizations since 2022. They exploit vulnerabilities in public services and use free tools to inflict maximum damage. The group employs rare remote access Trojans like Revenge RAT and Spark RAT, alongside common tools like Mimikatz. C.A.S focuses on data theft and reputational damage, often collaborating with other hacktivist groups. They use Telegram to spread information about attacks and victims. The group's tactics include initial access through exploit of public-facing applications, execution via PowerShell and cmd, persistence through registry keys and startup folders, defense evasion by disabling security tools, and credential access using various utilities. C.A.S encrypts victim infrastructure using leaked ransomware builders and can destroy data using system utilities.

Date

  • Created: Dec. 18, 2024, 12:48 p.m.
  • Published: Dec. 18, 2024, 12:48 p.m.
  • Modified: Dec. 18, 2024, 2:37 p.m.

Attack Patterns

  • Revenge RAT - S0379
  • Spark RAT
  • Vasa Locker
  • Babyk
  • Babuk - S0638
  • Meterpreter
  • LockBit
  • Cyber Anarchy Squad (C.A.S)
  • T1565.001
  • T1059.003
  • T1059.001
  • T1547.001
  • T1562.001
  • T1005
  • T1486
  • T1016
  • T1082
  • T1190
  • T1003

Additional Informations

  • Technology
  • Telecommunications
  • Government
  • Manufacturing
  • Belarus
  • Russian Federation