New ICS Threat Activity Group: VANADINITE
ID: 3475b013-0dc7-5c7e-81b0-f992f92c5794
STIX ID: report--3475b013-0dc7-5c7e-81b0-f992f92c5794
Feed Name: Dragos Blog
Dragos details VANADINITE, an activity group targeting ICS/OT environments across North America, Europe and APAC that gains initial access by exploiting public vulnerabilities in external-facing network devices (notably Citrix CVE-2020-8193) and using adversary-controlled or compromised VPS hosting (Choopa/Vultr). The report covers observed espionage-focused intrusions, possible use of ColdLock ransomware causing IT disruption, overlaps with Winnti/LEAD activity, and provides TTPs, detection guidance, and mitigation recommendations (patching, MFA, segmentation, monitoring).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
