ATT&CKGroupsDarkVishnya

DarkVishnya

G0105

Threat group.View on attack.mitre.org

About this group

DarkVishnya is a financially motivated threat actor targeting financial institutions in Eastern Europe. In 2017-2018 the group attacked at least 8 banks in this region.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1040
Network Sniffing

DarkVishnya used network sniffing to obtain login data.

T1046
Network Service Discovery

DarkVishnya performed port scanning to obtain the list of active services.

T1059.001
PowerShell

DarkVishnya used PowerShell to create shellcode loaders.

T1110
Brute Force

DarkVishnya used brute-force attack to obtain login data.

T1135
Network Share Discovery

DarkVishnya scanned the network for public shared folders.

T1200
Hardware Additions

DarkVishnya physically connected Bash Bunny, Raspberry Pi, netbooks, and inexpensive laptops to the target organization's environment to access the company’s local network.

T1219
Remote Access Tools

DarkVishnya used DameWare Mini Remote Control for lateral movement.

T1543.003
Windows Service

DarkVishnya created new services for shellcode loaders distribution.

T1571
Non-Standard Port

DarkVishnya used ports 5190 and 7900 for shellcode listeners, and 4444, 4445, 31337 for shellcode C2.

T1588.002
Tool

DarkVishnya has obtained and used tools such as Impacket, Winexe, and PsExec.

Software2

Campaigns0

None recorded.

References1

  1. Securelist DarkVishnya Dec 2018 Open source
    Golovanov, S. (2018, December 6). DarkVishnya: Banks attacked through direct connection to local network. Retrieved May 15, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.