Microsoft profiles new threat group with unusual but effective practices
Full article359 words · extracted from arstechnica.com · click to collapse
Microsoft has been tracking a threat group that stands out for its ability to cash in from data theft hacks that use broad social engineering attacks, painstaking research, and occasional physical threats.
Unlike many ransomware attack groups, Octo Tempest, as Microsoft has named the group, doesn’t encrypt data after gaining illegal access to it. Instead, the threat actor threatens to share the data publicly unless the victim pays a hefty ransom. To defeat targets’ defenses, the group resorts to a host of techniques, which, besides social engineering, include SIM swaps, SMS phishing, and live voice calls. Over time, the group has grown increasingly aggressive, at times resorting to threats of physical violence if a target doesn’t comply with instructions to turn over credentials.
“In rare instances, Octo Tempest resorts to fear-mongering tactics, targeting specific individuals through phone calls and texts,” Microsoft researchers wrote in a post on Wednesday. “These actors use personal information, such as home addresses and family names, along with physical threats to coerce victims into sharing credentials for corporate access.”
Threats sent by Octo Tempest to targets.
Credit: Microsoft
Threats sent by Octo Tempest to targets. Credit: Microsoft
Octo Tempest first came to notice early last year, as it used SIM swaps to ensnare companies that provide mobile telecommunications processing services to other companies. The group would then sell the unauthorized access it gained through those swaps to other crime groups or use them to perform account takeovers of high-net-worth individuals to steal their cryptocurrency. By the end of the year, the group had broadened its techniques and expanded its targets to include cable telecommunications, email, and technology organizations. Around this time, it began extorting victims whose data it had stolen, sometimes resorting to physical threats.
Earlier this year, the native-English-speaking group became an affiliate of the ALPHV/BlackCat ransom-as-a-service operation. That made the group stand out, since Eastern European ransomware crime syndicates rarely accept English-speaking members. Octo Tempest’s ALPHV/BlackCat ransomware attacks target both Windows and Linux versions of systems, often when they run on VMWare ESXi servers. Targets often are in industries like natural resources, gaming, hospitality, consumer products, retail, manufacturing, law, technology, and financial services.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2023/10/microsoft-profiles-new-threat-group-with-unusual-but-effective-practices/