CRYSTALRAY Hackers Infect Over 1,500 Victims Using Network Mapping Tool
ID: 613a0cb8-f330-5a35-a1f4-2fb8072196a6
STIX ID: report--613a0cb8-f330-5a35-a1f4-2fb8072196a6
Feed Name: The Hacker News
Sysdig reports that CRYSTALRAY has expanded into a large-scale campaign compromising over 1,500 victims globally by mass-scanning and exploiting known flaws in public-facing services (Apache ActiveMQ, Atlassian Confluence, Oracle WebLogic, Solr, etc.). The actors leverage open-source reconnaissance and traversal tools (SSH-Snake, zmap, httpx, nuclei) for lateral movement, use Sliver and a reverse-shell manager dubbed Platypus for persistence, exfiltrate and sell credentials, and deploy cryptocurrency miners while killing competing miners.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
