Iranian hackers targeting companies in India, China: Report


New Delhi, Aug 25 (IANS): Singapore-headquartered cybersecurity firm Group-IB has found that an Iranian group of newbie hackers recently targeted companies in India, Russia, Japan and China for financial gain.

The attacks were carried out in June using Dharma ransomware and a mix of publicly available tools, Group-IB said on Monday.

All the affected organisations had hosts with Internet-facing RDP (Remote Desktop) and weak credentials.

The hackers typically demanded a ransom between 1-5 BTC (Bitcoin), the company said.

The value of one Bitcoin is currently believed to be more than Rs 8,46,387.

Researchers with Group-IB recently observed increased activities around Dharma ransomware distribution.

Dharma, also known as Crysis, has been distributed under a ransomware-as-a-service (RaaS) model at least since 2016.

Its source code popped up for sale in March 2020 making it available to a wider audience, Group-IB said.

During an incident response engagement for a company in Russia, Group-IB's Digital Forensics and Incident Response (DFIR) team established that Persian-speaking newbie hackers were behind a new wave of Dharma distribution.

Even though the exact number of victims is unknown, the discovered forensic artifacts allowed them to establish the geography of their campaigns and the toolset, which is far behind the level of sophistication of big league Iranian APTs (advanced persistent threats), the company said.

The attacks came at a time when the pandemic exposed a great number of vulnerable hosts with many employees working from homes.

  

Top Stories


Leave a Comment

Title: Iranian hackers targeting companies in India, China: Report



You have 2000 characters left.

Disclaimer:

Please write your correct name and email address. Kindly do not post any personal, abusive, defamatory, infringing, obscene, indecent, discriminatory or unlawful or similar comments. Daijiworld.com will not be responsible for any defamatory message posted under this article.

Please note that sending false messages to insult, defame, intimidate, mislead or deceive people or to intentionally cause public disorder is punishable under law. It is obligatory on Daijiworld to provide the IP address and other details of senders of such comments, to the authority concerned upon request.

Hence, sending offensive comments using daijiworld will be purely at your own risk, and in no way will Daijiworld.com be held responsible.