Today > 13 Critical | 40 High | 37 Medium vulnerabilities   -   You can now download lists of IOCs here!

Hacktivists attack Russian organizations using rare RATs

Dec. 18, 2024, 2:37 p.m.

Description

The Cyber Anarchy Squad (C.A.S) is a hacktivist group targeting Russian and Belarusian organizations since 2022. They exploit vulnerabilities in public services and use free tools to inflict maximum damage. The group employs rare remote access Trojans like Revenge RAT and Spark RAT, alongside common tools like Mimikatz. C.A.S focuses on data theft and reputational damage, often collaborating with other hacktivist groups. They use Telegram to spread information about attacks and victims. The group's tactics include initial access through exploit of public-facing applications, execution via PowerShell and cmd, persistence through registry keys and startup folders, defense evasion by disabling security tools, and credential access using various utilities. C.A.S encrypts victim infrastructure using leaked ransomware builders and can destroy data using system utilities.

Date

Published: Dec. 18, 2024, 12:48 p.m.

Created: Dec. 18, 2024, 12:48 p.m.

Modified: Dec. 18, 2024, 2:37 p.m.

Attack Patterns

Revenge RAT - S0379

Spark RAT

Vasa Locker

Babyk

Babuk - S0638

Meterpreter

LockBit

Cyber Anarchy Squad (C.A.S)

T1565.001

T1059.003

T1059.001

T1547.001

T1562.001

T1005

T1486

T1016

T1082

T1190

T1003

Additional Informations

Technology

Telecommunications

Government

Manufacturing

Belarus

Russian Federation