logo

Analysis of Cyber Anarchy Squad attacks targeting Russian and Belarusian organizations

ID: 16d6dfd6-24e9-5742-a570-64e5007e86ba

STIX ID: report--16d6dfd6-24e9-5742-a570-64e5007e86ba

Feed Name: Securelist by Kaspersky

Threat Score
75/100

Date Published: 2024-12-18

Date Updated: 2026-04-29

Author: Kaspersky

...
...

This intelligence report profiles the hacktivist group C.A.S, documenting their ongoing campaigns since 2022 against organizations in Russia and Belarus. It details initial access via exploited public-facing applications (Jira, Confluence, MS SQL), post-exploitation toolsets including Revenge RAT, Spark RAT and Meterpreter, credential theft (Mimikatz, BrowserThief, XenAllPasswordPro), persistence and defense-evasion techniques, ransomware deployment (LockBit/Babuk builders) and destructive data-wiping using dd. The report includes IoCs (malicious file paths and IPs), examples of commands observed, evidence of collaboration with other hacktivist groups, and recommendations for hardening and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.