Analysis of the Crypt Ghouls group: continuing the investigation into a series of attacks on Russia
SecureList
OCTOBER 18, 2024
The group under review has a toolkit that includes utilities such as Mimikatz, XenAllPasswordPro, PingCastle, Localtonet, resocks, AnyDesk, PsExec, and others. The attackers used a contractor’s login information to connect to the victim’s internal systems via a VPN. zip hxxp://localtonet.com/download/localtonet-win-64.zip
Let's personalize your content