
Attacks on businesses are an increasingly common phenomenon, and ransomware creators are teaming up with other criminals to attack business networks and reap greater profits.
This collaboration aims to enable attacks on more secure and profitable targets. The AdvIntel shows how this clandestine community is developing multi-dimensional criminal alliance structures.
Access to corporate network data
Ransomware groups tend to follow various strategies to infect a larger number of victims and choose targets such as companies or government entities, to make thousands of dollars.
Many times, to be able to carry out these attacks, ransomware groups collaborate with multiple third-party cybercriminals, such as network hacking experts and malware developers.
For network breach experts, revenue generation is a significant challenge and ransomware groups offer a solution for revenue generation.
Researchers have even discovered a hacker, codenamed -TMT-, who has joined this hidden community to make money from illegal activities. The community claims to have stolen credentials from many corporate networks, which he sells for prices ranging from $3,000 to $5,000.
The hacker - TMT - also provided details about the breaches it carries out, according to the AdvIntel report. The group focuses primarily on corporate networks and uses infected RDP and malware for the initial stages of the attack.
“According to AdvIntel’s intelligence sources, since August 2019, -TMT- among other developers , has been collaborating with REvil developers, supporting crypto locker uploads.”
The collaboration between network intruders, Metasploit / Cobalt Strike specialists and ransomware developers is based on a solid foundation for exploiting attacks on high‑profile targets.
