Crypto Mimic
2020-09-30 • NTTSecurity • UNVEILING THE CRYPTOMIMIC
CryptoMimic, also referred to in industry reporting as Dangerous Password, CageyChameleon, and Leery Turtle, is an APT actor that NTT Security has observed active since around March 2018. The group targets banks and finance-related organizations worldwide, particularly those connected to cryptocurrencies, with victims in Japan, Russia, Europe, and the United States; unlike many espionage-focused APT groups, its objective appears to be financial gain. Attacks typically begin with a tailored email or LinkedIn message containing a shortened link that leads to a password-protected decoy document bundled with a shortcut file; opening the shortcut silently launches a script that downloads further components from the group's command-and-control infrastructure. This delivers a staged VBScript remote access tool that profiles the victim and, if of interest, is followed by interactive access, credential theft, and deployment of additional executables. CryptoMimic takes extensive measures to limit exposure of its tools, including rapidly expiring download links, swapping malicious files for benign ones, and deleting infrastructure within about a week, and researchers observed the group launching over a dozen attacks in a single month.
-
34
Related Actors
-
232
Related Reports
Related Actors
Related Reports in This Cluster
Top Authors
View Crypto Mimic reports only