HomeSecurityLately the OldGremlin group has been targeting Russian businesses!

Lately the OldGremlin group has been targeting Russian businesses!

Security firm Group-IB says it has identified a new cybercrime group that has repeatedly and deliberately targeted various Russian businesses with malware and ransomware attacks over the past six months. Group-IB says hackers from the OldGremlin group are behind the targeted attacks and are using a ransomware strain called TinyCryptor (also known as decr1pt).

OldGremlin

“They have tried to target only Russian companies so far,” Oleg Skulkin, senior analyst at Group-IB’s DFIR, told ZDNet this week.

"This is very unusual for Russian-speaking gangs who have this unspoken rule of not targeting Russia and post-Soviet countries."

How attacks unfold

OldGremlin attacks typically begin with phishing emails that deliver malware-laden ZIP files, which will typically infect the organization with a backdoor trojan called TinyNode. This gives the attackers an initial base in the network , where the hackers spread laterally to other systems and then deploy the ransomware in the final stage of their attacks.

Once a network is encrypted, the OldGremlin crew typically demands around $50,000 in ransom using messages left on the infected systems.

Skulkin says Group-IB identified the OldGremlin group in August, but the group's attacks date back to March, with the phishing they use having a variety of lures – for example impersonating journalists looking for work.

As Skulkin noted, attacks against Russian entities are rare but have happened in the past. Typically, groups like Silence and Cobalt started out as “small” ones in Russia before expanding their operations abroad, first to neighboring countries and then to targets around the world.

"If they're Russian, then it would be unusual, but not unheard of," KELA product manager Raveed Laeb told ZDNet in an interview this week.

“There is also the possibility that they are not Russian but operate outside of the CIS countries – for example, Ukrainian nationals likely have a dual motive to attack Russian entities, both economic and ideological,” Laeb added.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS