Ace in the Hole: exposing GambleForce, an SQL injection gang
ID: 24728ec7-64a5-5896-a26b-6c81b5f56408
STIX ID: report--24728ec7-64a5-5896-a26b-6c81b5f56408
Feed Name: Group-IB Blog
Group-IB discovered and tracked GambleForce, a threat actor using basic SQL injection techniques and open-source pentesting tools to target 24 websites (government, gambling, retail, travel, and job sites) across Australia, China, Indonesia, the Philippines, India, South Korea, Thailand and Brazil; the actors successfully exfiltrated user databases from six victims, operated a Cobalt Strike teamserver with custom profiles and self-signed certs, and used other utilities like supershell, while Group-IB took down their C2 and published IoCs and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
