Analysis of the Crypt Ghouls group: continuing the investigation into a series of attacks on Russia
SecureList
OCTOBER 18, 2024
The attackers used a contractor’s login information to connect to the victim’s internal systems via a VPN. The VPN connections were established from IP addresses associated with a Russian hosting provider’s network and a contractor’s network. zip hxxp://localtonet.com/download/localtonet-win-64.zip
Let's personalize your content