Analysis of new Crypt Ghouls threat group 👻
Last December, we discovered a new group targeting Russian businesses and government agencies with
#ransomware. Investigation into this group’s activity suggests a connection between it and other groups which are actively targeting Russian entities.
The group are deploying toolkits including Mimikatz, XenAllPasswordPro, PingCastle, Localtonet, resocks, AnyDesk, PsExec, and as the final payload, they deploy LockBit 3.0 and Babuk for final infection.
Additionally, as previously noted, we've noticed a fair bit of overlap in the TTPs between this group and other well known groups such as MorLock, BlackJack and Shedding Zmiy.
Read the full report ⇒
kas.pr/osu8