CRYSTALRAY hacker expands to 1,500 breached systems using SSH-Snake tool
ID: 85681ef0-5c0d-582d-b00e-fce2bc2d512b
STIX ID: report--85681ef0-5c0d-582d-b00e-fce2bc2d512b
Feed Name: Bleeping Computer
Sysdig researchers report that the CRYSTALRAY cybercrime group has scaled to over 1,500 victims by leveraging open-source tooling (SSH‑Snake, Sliver, zmap, nuclei, Platypus, etc.) to mass-scan, exploit known vulnerabilities (including CVE-2022-44877, CVE-2021-3129, CVE-2019-18394 and likely Confluence issues), steal SSH keys and credentials for lateral movement, deploy backdoors and cryptominers, and sell harvested credentials — mitigation recommended includes timely patching, secrets management, and reducing the attack surface.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
