threat-intel
From cause to cash: a cross-border look at hacktivist activity
High
Summary
This Securelist article details a cross-border hacktivist campaign led by groups including 4BID, with a broadened geographic scope impacting organizations in Kazakhstan, the UAE, Syria, and Egypt. The campaign utilized tactics such as exploiting ProxyShell vulnerabilities in Microsoft Exchange, deploying ransomware like ClearWater and Warp RAT, and leveraging RMM tools like Panorama9 and AnyDesk. The investigation uncovered connections between multiple threat actors, including 4BID, Goffee, and С.A.S., highlighting a complex and coordinated attack.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
