Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Energetic Bear/Crouching Yeti: attacks on servers

released on 2018-04-23 @ 10:52:07 AM
Indicators in this pulse relate to web-shells used by a number of different attackers. Energetic Bear/Crouching Yeti is a widely known APT group active since at least 2010. The group tends to attack different companies with a strong focus on the energy and industrial sectors. Companies attacked by Energetic Bear/Crouching Yeti are geographically distributed worldwide with a more obvious concentration in Europe and the US. In 2016-2017, the number of attacks on companies in Turkey increased significantly. The main tactics of the group include sending phishing emails with malicious documents and infecting various servers. The group uses some of the infected servers for auxiliary purposes – to host tools and logs. Others are deliberately infected to use them in waterhole attacks in order to reach the group’s main targets.