Feb 2Scaly Wolf uses White Snake stealer against Russian industryThe group, which has been on the radar since the summer of 2023, conducted several phishing campaigns using Russian regulatory body and law enforcement identities. The BI.ZONE Threat Intelligence team has identified at least a dozen campaigns linked to Scaly Wolf. …Information Security10 min readInformation Security10 min read
Dec 28, 2023A striking resemblance: Gambling Hyena and Twelfth Hyena clusters comparedWhat is common between two hacktivist groups attacking the Russian government sector. The BI.ZONE Threat Intelligence team has expanded its taxonomy of threat actors. Previously, we distinguished state-sponsored groups as Werewolves and all the others as Wolves. …Information Security4 min readInformation Security4 min read
Nov 29, 2023Rare Wolf preys on sensitive data using fake 1C:Enterprise invoices as lureHow adversaries create diversions and stay invisible BI.ZONE Threat Intelligence specialists have discovered a cybercriminal group that has been active since at least 2019. While this cluster of activity was previously directed against the countries neighboring Russia, now such attacks have reached Russia itself. …Information Security5 min readInformation Security5 min read
Oct 13, 2023Sticky Werewolf attacks public organizations in Russia and BelarusOur cyber threat intelligence experts discover a new group that uses presumably legitimate software to interfere with government organizations. A characteristic feature of these attackers is the use of popular tools that are easy to detect and block. Nevertheless, this has not stopped Sticky Werewolf from succeeding. …Information Security5 min readInformation Security5 min read
Aug 8, 2023White Snake spotted in emails: the stealer was disguised as official state requirementsAny threat actor with $140 can utilize this malware. For that price, they get a complete end-to-end attack kit: i) a builder to create malware samples, ii) access to the control panel of compromised devices, iii) updates and messenger support. …Information Security6 min readInformation Security6 min read
Jul 17, 2023Hacker group Quartz Wolf leverages legitimate software for cyberattacksCybercriminals have modified the standard “phishing email + remote access” combo with an unexpected hook — the leveraging of legitimate Russian software. BI.ZONE CESP has detected and prevented one such attack that targeted hospitality organizations. …Information Security3 min readInformation Security3 min read
Jun 28, 2023Hunting the hunter: BI.ZONE traces the footsteps of Red WolfThe cyber spies who had been on hiatus since 2022 make a surprising comeback. Red Wolf has been spotted penetrating company infrastructures for espionage purposes. By slowly moving forward in the compromised environments and not drawing much attention, the group managed to stay invisible for up to six months. BI.ZONE…Information Security4 min readInformation Security4 min read
Apr 10, 2023Watch Wolf weaponizes SEO against accountantsDelivering attacks through emails is so last century, or at least so seem to think the Watch Wolf group hackers who switched to spreading their malware through SEO poisoning. We discovered that they deliver the Buhtrap trojan through fake websites posing as legitimate resources for accountants. …Information Security5 min readInformation Security5 min read
Mar 22, 2023BI.ZONE detects destructive attacks by the Key Wolf groupA new threat has been uncovered. The Key Wolf hacker group is bombarding Russian users with file-encrypting ransomware. Interestingly enough, the attackers do not demand any ransom. Nor do they provide any options to decrypt the affected files. Our experts were the first to detect the proliferation of the new…Threat Intelligence5 min readThreat Intelligence5 min read
Mar 21, 2022Masscan with HTTPS supportBy Konstantin Molodyakov Masscan is a fast network scanner that is good for scanning a large range of IP addresses and ports. We’ve adapted it to our needs by giving it a little tweak. The biggest inconvenience in the original version was the inability to collect banners from HTTPS servers…Masscan10 min readMasscan10 min read