Sunday, March 26, 2023
AI Home Security
No Result
View All Result
  • Home
  • Home Security
  • Cyber Security
  • Biometric Technology
  • Home
  • Home Security
  • Cyber Security
  • Biometric Technology
No Result
View All Result
Morning News
No Result
View All Result
Home Cyber Security

Bluebottle Cybercrime Group Preys on Financial Sector in French-Speaking African Nations

justmattg by justmattg
January 5, 2023
in Cyber Security
0
Bluebottle Cybercrime Group Preys on Financial Sector in French-Speaking African Nations
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

READ ALSO

OpenAI Reveals Redis Bug Behind ChatGPT User Data Exposure Incident

‘Dark Power’ Ransomware Extorts 10 Targets in Less Than a Month


Jan 05, 2023Ravie LakshmananCybercrime / Banking Security

Bluebottle Cybercrime Group

A cybercrime group dubbed Bluebottle has been linked to a set of targeted attacks against the financial sector in Francophone countries located in Africa from at least July 2022 to September 2022.

“The group makes extensive use of living-off-the-land, dual use tools, and commodity malware, with no custom malware deployed in this campaign,” Symantec, a division of Broadcom Software, said in a report shared with The Hacker News.

The cybersecurity firm said the activity shares overlaps with a threat cluster tracked by Group-IB under the name OPERA1ER, which has carried out dozens of attacks aimed at banks, financial services, and telecom companies in Africa, Asia, and Latin America between 2018 and 2022.

The attribution stems from similarities in the toolset used, the attack infrastructure, the absence of bespoke malware, and the targeting of French-speaking nations in Africa. Three different unnamed financial institutions in three African nations were breached, although it’s not known whether Bluebottle successfully monetized the attacks.

The financially motivated adversary, also known by the name DESKTOP-GROUP, has been responsible for a string of heists totaling $11 million, with actual damages touching $30 million.

The recent attacks illustrate the group’s evolving tactics, including employing an off-the-shelf malware named GuLoader in the early stages of the infection chain as well as weaponizing kernel drivers to disable security defenses.

Symantec said it couldn’t trace the initial intrusion vector, although it detected job-themed files on the victim networks, indicating that hiring related phishing lures were likely put to use to trick the targets into opening malicious email attachments.

What’s more, an attack detected in mid-May 2022 involved the delivery of an information stealer malware in the form of a ZIP file containing an executable screen saver (.SCR) file. Also observed in July 2022 was the use of an optical disc image (.ISO) file, which has been utilized by many a threat actor as a means of distributing malware.

“If the Bluebottle and OPERA1ER actors are indeed one and the same, this would mean that they swapped out their infection techniques between May and July 2022,” the researchers noted.

The spear-phishing attachments lead to the deployment of GuLoader, which subsequently acts as a conduit to drop additional payloads on the machine, such as Netwire, Quasar RAT, and Cobalt Strike Beacon. Lateral movement is facilitated through tools like PsExec and SharpHound.

Another technique adopted by the group is the use of a signed helper driver to terminate security software, a method that has been utilized by multiple hacking crews for similar purposes, according to findings from Mandiant, SentinelOne, and Sophos last month.

The fact that the same driver (called POORTRY by Mandiant) has been leveraged by several cybercriminal groups lends credence to the theory that these threat actors are using a code signing service to get their malware pass attestation mechanisms.

With the threat actors suspected to be French-speaking, it’s likely that the attacks could expand to other French-speaking nations across the world, the company cautioned.

“The effectiveness of its campaigns means that Bluebottle is unlikely to stop this activity,” the researchers said. “It appears to be very focused on Francophone countries in Africa, so financial institutions in these countries should remain on high alert.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Related Posts

OpenAI Reveals Redis Bug Behind ChatGPT User Data Exposure Incident
Cyber Security

OpenAI Reveals Redis Bug Behind ChatGPT User Data Exposure Incident

March 26, 2023
Everything You Need to Know
Cyber Security

‘Dark Power’ Ransomware Extorts 10 Targets in Less Than a Month

March 26, 2023
Microsoft Warns of Stealthy Outlook Vulnerability Exploited by Russian Hackers
Cyber Security

Microsoft Warns of Stealthy Outlook Vulnerability Exploited by Russian Hackers

March 26, 2023
U.K. National Crime Agency Sets Up Fake DDoS-For-Hire Sites to Catch Cybercriminals
Cyber Security

U.K. National Crime Agency Sets Up Fake DDoS-For-Hire Sites to Catch Cybercriminals

March 25, 2023
Malicious Python Package Uses Unicode Trickery to Evade Detection and Steal Data
Cyber Security

Malicious Python Package Uses Unicode Trickery to Evade Detection and Steal Data

March 25, 2023
Red Teaming at Scale to Uncover Your Big Unknowns
Cyber Security

Red Teaming at Scale to Uncover Your Big Unknowns

March 24, 2023
Next Post
Android Spyware Targeting Financial Institutions

Android Spyware Targeting Financial Institutions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

POPULAR NEWS

Hackers Create Malicious Dota 2 Game Modes to Secretly Access Players’ Systems

Hackers Create Malicious Dota 2 Game Modes to Secretly Access Players’ Systems

February 13, 2023
Trickbot Members Sanctioned for Pandemic-Era Ransomware Hits

Trickbot Members Sanctioned for Pandemic-Era Ransomware Hits

February 11, 2023
The New Threats to Cryptocurrency Users

The New Threats to Cryptocurrency Users

February 12, 2023
Do you know who is watching you?

Do you know who is watching you?

January 2, 2023
PopID announces big customer deployment for face biometric payments in UAE

PopID announces big customer deployment for face biometric payments in UAE

February 14, 2023

EDITOR'S PICK

New HiatusRAT Malware Targets Business-Grade Routers to Covertly Spy on Victims

New HiatusRAT Malware Targets Business-Grade Routers to Covertly Spy on Victims

March 6, 2023
The Ethics of Network and Security Monitoring

The Ethics of Network and Security Monitoring

March 17, 2023
Lazarus Group Likely Using New WinorDLL64 Backdoor to Exfiltrate Sensitive Data

Lazarus Group Likely Using New WinorDLL64 Backdoor to Exfiltrate Sensitive Data

February 27, 2023
New Analysis Reveals Raspberry Robin Can be Repurposed by Other Threat Actors

New Analysis Reveals Raspberry Robin Can be Repurposed by Other Threat Actors

January 11, 2023

About

We bring you the best news & updates related to Home security, Cyber security and Biometric technology. Keep visiting our website for latest updates.

Follow us

Categories

  • Biometric Technology
  • Cyber Security
  • Home Security

Recent Posts

  • OpenAI Reveals Redis Bug Behind ChatGPT User Data Exposure Incident
  • ‘Dark Power’ Ransomware Extorts 10 Targets in Less Than a Month
  • Microsoft Warns of Stealthy Outlook Vulnerability Exploited by Russian Hackers
  • U.K. National Crime Agency Sets Up Fake DDoS-For-Hire Sites to Catch Cybercriminals
  • Privacy Policy
  • Contact Us

© 2023 AI Home Security - All rights reserved.

No Result
View All Result
  • Home
  • Home Security
  • Cyber Security
  • Biometric Technology

© 2023 AI Home Security - All rights reserved.