Introduction
DarkVishnya is a financially motivated threat actor targeting financial institutions in Eastern Europe. In 2017-2018 the group attacked at least 8 banks in this region. Securelist DarkVishnya Dec 2018
Activities and Tactics
Information pending cataloguing.
Notable Campaigns
Information pending cataloguing.
Tactics, Techniques, and Procedures (TTPs)
- T1200 Hardware Additions
- T1588.002 Tool
- T1543.003 Windows Service
- T1046 Network Service Discovery
- T1135 Network Share Discovery
- T1110 Brute Force
- T1219 Remote Access Tools
- T1059.001 PowerShell
- T1040 Network Sniffing
- T1571 Non-Standard Port
ATT&CK technique IDs (denormalized)
Notable Indicators of Compromise (IOCs)
No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.
Malware and Tools
- FLASHFLOOD
- MINI-MO
MITRE ATT&CK Software
Attribution and Evidence
Information pending cataloguing.
References
[1] mitre-attack [3] Securelist DarkVishnya Dec 2018 Golovanov, S. (2018, December 6). DarkVishnya: Banks attacked through direct connection to local network. Retrieved May 15, 2020.