logo

Ace in the Hole: exposing GambleForce, an SQL injection gang

ID: 24728ec7-64a5-5896-a26b-6c81b5f56408

STIX ID: report--24728ec7-64a5-5896-a26b-6c81b5f56408

Feed Name: Group-IB Blog

Threat Score
55/100

Date Published: 2023-12-14

Date Updated: 2026-04-27

...
...

Group-IB discovered and tracked GambleForce, a threat actor using basic SQL injection techniques and open-source pentesting tools to target 24 websites (government, gambling, retail, travel, and job sites) across Australia, China, Indonesia, the Philippines, India, South Korea, Thailand and Brazil; the actors successfully exfiltrated user databases from six victims, operated a Cobalt Strike teamserver with custom profiles and self-signed certs, and used other utilities like supershell, while Group-IB took down their C2 and published IoCs and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.