Hacktivists attack Russian organizations using rare RATs
Dec. 18, 2024, 2:37 p.m.
Tags
External References
Description
The Cyber Anarchy Squad (C.A.S) is a hacktivist group targeting Russian and Belarusian organizations since 2022. They exploit vulnerabilities in public services and use free tools to inflict maximum damage. The group employs rare remote access Trojans like Revenge RAT and Spark RAT, alongside common tools like Mimikatz. C.A.S focuses on data theft and reputational damage, often collaborating with other hacktivist groups. They use Telegram to spread information about attacks and victims. The group's tactics include initial access through exploit of public-facing applications, execution via PowerShell and cmd, persistence through registry keys and startup folders, defense evasion by disabling security tools, and credential access using various utilities. C.A.S encrypts victim infrastructure using leaked ransomware builders and can destroy data using system utilities.
Date
Published: Dec. 18, 2024, 12:48 p.m.
Created: Dec. 18, 2024, 12:48 p.m.
Modified: Dec. 18, 2024, 2:37 p.m.
Attack Patterns
Revenge RAT - S0379
Spark RAT
Vasa Locker
Babyk
Babuk - S0638
Meterpreter
LockBit
Cyber Anarchy Squad (C.A.S)
T1565.001
T1059.003
T1059.001
T1547.001
T1562.001
T1005
T1486
T1016
T1082
T1190
T1003
Additional Informations
Technology
Telecommunications
Government
Manufacturing
Belarus
Russian Federation