RDoS attacks by fake Fancy Bear hit banks in multiple locations
ID: 8a68b753-ec05-5e9a-b9a8-f8def8b5fe84
STIX ID: report--8a68b753-ec05-5e9a-b9a8-f8def8b5fe84
Feed Name: Group-IB Blog
In late October 2019 a mass email extortion (RDoS) campaign targeted banks and financial organizations across multiple regions, impersonating Fancy Bear to demand 3 BTC and threatening DDoS attacks; some recipients saw small demonstration UDP/ICMP floods (including use of UDP port 3283). Group-IB concludes the activity was financially motivated extortion by impostors rather than the real APT28, and highlights indicators such as the sender [email protected] and the novel use of ARD-related UDP port 3283 in DDoS traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
