Technadu
Hacktivist Groups Expand Attacks Beyond Russia to Middle East and Central Asia
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Hacktivist groups 4BID, Hakerskii Kit, and C.A.S. have broadened their attack geography, targeting organizations in Kazakhstan, the UAE, Syria, and Egypt, moving beyond their previous focus on Russian and Belarusian entities. The investigation began after indicators of compromise were detected in a breached Russian organization, leading researchers to uncover interconnected actors. Attackers primarily exploited the ProxyShell vulnerability in Microsoft Exchange to gain initial access, deploying the fd.aspx web shell for remote control and reconnaissance. The campaigns also utilized new ransomware samples, including ClearWater, and a previously undocumented backdoor named BlackSalt. Despite the new targets, most compromised systems still belong to Russian and Belarusian organizations. This shift in focus appears to be motivated by a claim from a 4BID member that attacking Russia is no longer profitable.
Key Points: • Hacktivist groups 4BID, Hakerskii Kit, and C.A.S. are targeting organizations in Kazakhstan, UAE, Syria, and Egypt. • Initial access is commonly gained through the ProxyShell vulnerability in Microsoft Exchange. • New malware includes the ClearWater ransomware and a backdoor named BlackSalt.