HomeSecurityFxmsp: The hacking group was selling access to corporate networks!

Fxmsp: The hacking group was selling access to corporate networks!

New information has come to light about the activity of the Russian hacking group Fxmsp, which last year advertised access to the networks of three cybersecurity. Researchers monitoring Fxmsp’s activities on underground forumshave counted the number of intrusions the hacking group has carried out and revealed the alleged identity of the attacker. The Fxmsp hacking group first gained widespread attention about a year ago, when cybersecurity boutique Advanced Intelligence (AdvIntel) published reports about the group’s efforts to close a $300,000 deal to sell access to networks owned by Symantec, Trend Micro and McAfee. The group has been quiet since the media spotlight, but it is very likely that it continues to operate via private messages.

hacking team

Group-IB researchers examined the activity of the Fxmsp group on forums where it advertised its business, estimating that the group has so far compromised the networks of at least 135 companies in 44 countries. Its targets have included banks, small and medium-sized businesses, government agencies, and Fortune 500 companies. Group-IB estimates that since around 2016, Fxmsp has earned at least $1.5 million from selling access to networks. In May 2019, AdvIntel stated that Fxmsp is a threat that has earned approximately $1,000,000 by exploiting its breaches against companies. The profit may seem quite large to hackers who have little or no experience in trading their “assets.” However, Fxmsp was not alone in this. However, the actual profit made by the hacking group is estimated to be much higher in reality, given that the transactions for access to 20% of the companies that were breached were carried out privately and were not accompanied by a public price.

Fxmsp

According to Group-IB, Fxmsp ceased its public activity in late 2019, but not before advertising access to a European power company that fell victim to a ransomware attack in 2020. One such company that was hit by ransomware this year is Italian multinational Enel. According to Yelisey Boguslavskiy, director of security research at AdvIntel, Fxmsp was part of a crew called GPTitan, which was made up of specialists who aimed to operate covertly in financial environments to steal data from high-profile networks. GPTitan contributed to the hacking group’s activity from two other crews, one in China and one in the US. This was a collaboration that led to data breaches of antivirus companies since spring 2019. It appears that Fxmsp has stopped acting alone and is now operating as part of a larger group. The non-hacking division of Fxmsp was responsible for marketing and monetizing access to networks and data. A network of affiliates operating under the pseudonym Antony Moricone offered to provide stolen information to hackers and illegal information traders, who used it to their advantage in the decision-making process at companies they were interested in.

Fxmsp-Access to corporate networks

Boguslavskiy does not consider it unlikely that the pseudonyms of the Antony Moricone group are operated by a single individual across many forums, as reported by Group-IB in its report. Specifically, Group-IB researchers identified the Lampeduza pseudonyms on other forums: Antony Moricone, BigPetya, Fivelife, Nikolay, tor.ter, andropov and Gromyko. Furthermore, the researchers disclosed in a report who might be the identity behind the hacking group Fxmsp: Andrey Turchin (which appears to originate from Kazakhstan), the same as BleepingComputer found in a study last year. Dmitry Volkov, CTO of Group-IB, states that Fxmsp established a trend that led the second half of 2019 to almost double the number of access sellers to networks that specialize in corporate intrusions. Volkov added that Fxmsp may still be active, keeping its business private. Even if it is no longer in the spotlight, it has set an example that others may follow.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS