logo

CRYSTALRAY hacker expands to 1,500 breached systems using SSH-Snake tool

ID: 85681ef0-5c0d-582d-b00e-fce2bc2d512b

STIX ID: report--85681ef0-5c0d-582d-b00e-fce2bc2d512b

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-07-11

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Sysdig researchers report that the CRYSTALRAY cybercrime group has scaled to over 1,500 victims by leveraging open-source tooling (SSH‑Snake, Sliver, zmap, nuclei, Platypus, etc.) to mass-scan, exploit known vulnerabilities (including CVE-2022-44877, CVE-2021-3129, CVE-2019-18394 and likely Confluence issues), steal SSH keys and credentials for lateral movement, deploy backdoors and cryptominers, and sell harvested credentials — mitigation recommended includes timely patching, secrets management, and reducing the attack surface.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.