Crypto Mimic

2020-09-30 • NTTSecurityUNVEILING THE CRYPTOMIMIC

CryptoMimic, also referred to in industry reporting as Dangerous Password, CageyChameleon, and Leery Turtle, is an APT actor that NTT Security has observed active since around March 2018. The group targets banks and finance-related organizations worldwide, particularly those connected to cryptocurrencies, with victims in Japan, Russia, Europe, and the United States; unlike many espionage-focused APT groups, its objective appears to be financial gain. Attacks typically begin with a tailored email or LinkedIn message containing a shortened link that leads to a password-protected decoy document bundled with a shortcut file; opening the shortcut silently launches a script that downloads further components from the group's command-and-control infrastructure. This delivers a staged VBScript remote access tool that profiles the victim and, if of interest, is followed by interactive access, credential theft, and deployment of additional executables. CryptoMimic takes extensive measures to limit exposure of its tools, including rapidly expiring download links, swapping malicious files for benign ones, and deleting infrastructure within about a week, and researchers observed the group launching over a dozen attacks in a single month.

Related Actors

Related Reports in This Cluster

Top Authors

View Crypto Mimic reports only

View Crypto Mimic reports only