Alternate Group Names
GOLD HERON, \\
Alternative Names
Gold Heron, DoppelPaymer, doppel paymer, DoppelPaymer group, DoppelPaymer ransomware, DoppelPaymer gang,
---------------------------------------------
(CrowdStrike) CrowdStrike Intelligence has identified a new ransomware variant identifying itself as BitPaymer. This new variant was behind a series of ransomware campaigns beginning in June 2019, including attacks against the City of Edcouch, Texas and the Chilean Ministry of Agriculture. We have dubbed this new ransomware DoppelPaymer because it shares most of its code with the BitPaymer ransomware operated by \\\'Indrik Spider\\\'. However, there are a number of differences between DoppelPaymer and BitPaymer, which may signify that one or more members of Indrik Spider have split from the group and forked the source code of both Dridex and BitPaymer to start their own Big Game Hunting ransomware operation. DoppelPaymer has been observed to be distributed by Smoke Loader (operated by \\\'Smoky Spider\\\') and Emotet (operated by \\\'Mummy Spider, TA542\\\').\\
First Seen- 2019
Other Names: (other than above mentioned): Grief Group
Targets: Austria, Brazil, Canada, Chile, Dominican Republic, France, Germany, Greece, Italy, Mexico, Portugal, Spain, Switzerland, Thailand, United Kingdom, United States -
Target Categories- Government, Manufacturing
Tools-
Cobalt
Strike (category: Tools)
type: Backdoor, Vulnerability scanner, Keylogger, Tunneling, Loader,
Exfiltration
Cobalt Strike is a paid penetration testing product that allows an attacker to
deploy an agent named \'Beacon\' on the victim machine. Beacon includes a wealth
of functionality to the attacker, including, but not limited to command
execution, key logging, file transfer, SOCKS proxying, privilege escalation,
mimikatz, port scanning and lateral movement. Beacon is in-memory/file-less, in
that it consists of stageless or multi-stage shellcode that once loaded by
exploiting a vulnerability or executing a shellcode loader, will reflectively
load itself into the memory of a process without touching the disk. It supports
C2 and staging over HTTP, HTTPS, DNS, SMB named pipes as well as forward and
reverse TCP; Beacons can be daisy-chained. Cobalt Strike comes with a toolkit
for developing shellcode loaders, called Artifact Kit. The Beacon implant has
become popular amongst targeted attackers and criminal users as it is well
written, stable, and highly customizable.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=7ea8d070-cfd7-473c-a615-437fc292af55
https://www.cobaltstrike.com/
https://www.fireeye.com/blog/threat-research/2017/06/phished-at-the-request-of-counsel.html
https://blogs.jpcert.or.jp/en/2018/08/volatility-plugin-for-detecting-cobalt-strike-beacon.html
https://github.com/JPCERTCC/aa-tools/blob/master/cobaltstrikescan.py
https://www.fireeye.com/blog/threat-research/2018/11/not-so-cozy-an-uncomfortable-examination-of-a-suspected-apt29-phishing-campaign.html
http://blog.morphisec.com/new-global-attack-on-point-of-sale-systems
https://www.lac.co.jp/lacwatch/people/20180521_001638.html
https://www.pentestpartners.com/security-blog/cobalt-strike-walkthrough-for-red-teamers/
https://www.bleepingcomputer.com/news/security/threat-actors-use-older-cobalt-strike-versions-to-blend-in/
https://documents.trendmicro.com/assets/white_papers/wp-cashing-in-on-atm-malware.pdf
https://blog.talosintelligence.com/2020/09/coverage-strikes-back-cobalt-strike-paper.html
https://www.bleepingcomputer.com/news/security/alleged-source-code-of-cobalt-strike-toolkit-shared-online/
https://www.darkreading.com/threat-intelligence/how-to-identify-cobalt-strike-on-your-network/a/d-id/1339357
https://www.deepinstinct.com/2021/03/18/cobalt-strike-post-exploitation-attackers-toolkit/
https://www.darkreading.com/attacks-breaches/cobalt-strike-becomes-a-preferred-hacking-tool-by-cybercrime-apt-groups/d/d-id/1341073
http://www.intel471.com/blog/cobalt-strike-cybercriminals-trickbot-qbot-hancitor
https://blog.malwarebytes.com/researchers-corner/2021/06/cobalt-strike-a-penetration-testing-tool-popular-among-criminals/
https://www.proofpoint.com/us/blog/threat-insight/cobalt-strike-favorite-tool-apt-crimeware
https://labs.sentinelone.com/hotcobalt-new-cobalt-strike-dos-vulnerability-that-lets-you-halt-operations/
https://www.intezer.com/blog/malware-analysis/cobalt-strike-detect-this-persistent-threat/
https://www.intezer.com/blog/malware-analysis/vermilionstrike-reimplementation-cobaltstrike/
https://www.recordedfuture.com/detect-cobalt-strike-inside-look/
https://elis531989.medium.com/the-squirrel-strikes-back-analysis-of-the-newly-emerged-cobalt-strike-loader-squirrelwaffle-937b73dbd9f9
https://blog.nviso.eu/2021/10/21/cobalt-strike-using-known-private-keys-to-decrypt-traffic-part-1/
https://www.cybereason.com/blog/threat-analysis-report-all-paths-lead-to-cobalt-strike-icedid-emotet-and-qbot
https://asec.ahnlab.com/en/31811/
https://unit42.paloaltonetworks.com/cobalt-strike-malleable-c2-profile/
https://unit42.paloaltonetworks.com/cobalt-strike-metadata-encoding-decoding/
https://unit42.paloaltonetworks.com/cobalt-strike-metadata-encryption-decryption/
https://securityintelligence.com/posts/analysis-rce-vulnerability-cobalt-strike/
https://cloud.google.com/blog/products/identity-security/making-cobalt-strike-harder-for-threat-actors-to-abuse
https://unit42.paloaltonetworks.com/cobalt-strike-memory-analysis/
https://securityintelligence.com/posts/defining-cobalt-strike-reflective-loader/
https://unit42.paloaltonetworks.com/cobalt-strike-malleable-c2/
https://asec.ahnlab.com/en/59110/
https://unit42.paloaltonetworks.com/attackers-exploit-public-cobalt-strike-profiles/
https://www.europol.europa.eu/media-press/newsroom/news/europol-coordinates-global-action-against-criminal-abuse-of-cobalt-strike
https://attack.mitre.org/software/S0154/
https://malpedia.caad.fkie.fraunhofer.de/details/win.cobalt_strike
https://otx.alienvault.com/browse/pulses?q=tag:Cobalt%20Strike
DoppelPaymer (category:
Malware)
type: Ransomware, Big Game Hunting
(CrowdStrike) We have dubbed this new ransomware DoppelPaymer because it shares
most of its code with the \'BitPaymer\' ransomware operated by INDRIK SPIDER.
However, there are a number of differences between DoppelPaymer and BitPaymer,
which may signify that one or more members of INDRIK SPIDER have split from the
group and forked the source code of both Dridex and BitPaymer to start their
own Big Game Hunting ransomware operation.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6e1df6f2-f969-4cd0-bc33-e25588eb2672
https://www.crowdstrike.com/blog/doppelpaymer-ransomware-and-dridex-2/
https://malpedia.caad.fkie.fraunhofer.de/details/win.doppelpaymer
https://otx.alienvault.com/browse/pulses?q=tag:DoppelPaymer
Grief (category:
Malware)
type: Ransomware, Big Game Hunting
(Zscaler) An early Grief ransomware (aka Pay or Grief) sample was compiled on
May 17, 2021. This sample is particularly interesting because it contains the
Grief ransomware code and ransom note, but the link in the ransom note points
to the \'DoppelPaymer\' ransom portal. This suggests that the malware author may
have still been in the process of developing the Grief ransom portal.
Ransomware threat groups often rebrand the name of the malware as a diversion.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=aa2dfc3d-ed20-4970-9624-ea19b096a395
https://www.zscaler.com/blogs/security-research/doppelpaymer-continues-cause-grief-through-rebranding
https://redcanary.com/blog/grief-ransomware/
https://socradar.io/dark-web-threat-profile-grief-ransomware-group/
Source: https://andreacristaldi.github.io/APTmap/
