HomeSecurityResearchers identify new hacking group FusionCore

Researchers identify new hacking group FusionCore

An emerging cybercrime group, FusionCore, is likely made up of English-speaking European teenagers with distinct skills.

FusionCore

Active since November, FusionCore has been a go-to destination for malicious actors. A security firm called Cyfirma recently identified its activities and reported that it provides services such as malware-on-a-subscription, hacking-on-demand, and ransomware.

To expand its malicious activities, the group launched an affiliate program called AnthraXXXLocker that specializes in ransomware.

See also: UK: Criminal Records Office (ACRO) faced ransomware attack

In the second half of 2022, FusionCore transformed into a malware-as-a-service unit after its creator, referred to as “Hydra,” faced an influx of requests for the infostealer malware it developed, according to Cyfirma.

The term “Hydra” comes from the ancient Greek myth of the nine-headed Lernaean water serpent, which could not be killed with a single blow. It was only when Hercules used twelve labors to defeat it that its remarkable regenerative powers were discovered - for every head lost, two grew back in its place.

The Hydra creator assembled a team of developers to design specialized malware, while continuously recruiting additional members through advertisements on its Telegram channel. According to the Cyfirma report, FusionCore is comprised of young and active malware developers with a wide range of talents – likely in their late teens.

See also: Hackers create free Quickbooks accounts to steal money

Researchers identify new hacking group FusionCore

The group offers custom malware such as Typhon Reborn – inspired by another classic Greek serpentine creature – ApolloRAT (a Remote Access Trojan), Cryptonic (an escape tool), and SarinLocker (a modern ransomware variant).

See also: Amazon stopped selling Flipper Zero

The organization relies heavily on open source tools like Obfuscar and NBMiner to provide superior obfuscation and crypto mining features.

In March, Hydra revealed a screenshot of the Typhon Reborn dashboard, which was set to default to Swedish time.

Information source: bankinfosecurity.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS