Analysis of Cyber Anarchy Squad attacks targeting Russian and Belarusian organizations
ID: 16d6dfd6-24e9-5742-a570-64e5007e86ba
STIX ID: report--16d6dfd6-24e9-5742-a570-64e5007e86ba
Feed Name: Securelist by Kaspersky
This intelligence report profiles the hacktivist group C.A.S, documenting their ongoing campaigns since 2022 against organizations in Russia and Belarus. It details initial access via exploited public-facing applications (Jira, Confluence, MS SQL), post-exploitation toolsets including Revenge RAT, Spark RAT and Meterpreter, credential theft (Mimikatz, BrowserThief, XenAllPasswordPro), persistence and defense-evasion techniques, ransomware deployment (LockBit/Babuk builders) and destructive data-wiping using dd. The report includes IoCs (malicious file paths and IPs), examples of commands observed, evidence of collaboration with other hacktivist groups, and recommendations for hardening and monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
