Threat group.View on attack.mitre.org
DarkVishnya is a financially motivated threat actor targeting financial institutions in Eastern Europe. In 2017-2018 the group attacked at least 8 banks in this region.
| Technique | Procedure example |
|---|---|
| T1040 Network Sniffing |
DarkVishnya used network sniffing to obtain login data. |
| T1046 Network Service Discovery |
DarkVishnya performed port scanning to obtain the list of active services. |
| T1059.001 PowerShell |
DarkVishnya used PowerShell to create shellcode loaders. |
| T1110 Brute Force |
DarkVishnya used brute-force attack to obtain login data. |
| T1135 Network Share Discovery |
DarkVishnya scanned the network for public shared folders. |
| T1200 Hardware Additions |
DarkVishnya physically connected Bash Bunny, Raspberry Pi, netbooks, and inexpensive laptops to the target organization's environment to access the company’s local network. |
| T1219 Remote Access Tools |
DarkVishnya used DameWare Mini Remote Control for lateral movement. |
| T1543.003 Windows Service |
DarkVishnya created new services for shellcode loaders distribution. |
| T1571 Non-Standard Port |
DarkVishnya used ports 5190 and 7900 for shellcode listeners, and 4444, 4445, 31337 for shellcode C2. |
| T1588.002 Tool |
DarkVishnya has obtained and used tools such as Impacket, Winexe, and PsExec. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.