
CyberWire Daily Dual Russian cyber gangs hit 23 companies. [Research Saturday]
Jan 13, 2024
Ryan Westman, Senior Manager, Threat Intelligence at eSentire's Threat Response Unit (TRU) discusses two Russian-speaking cyber gangs targeting 23 companies using malicious Google ads. They focus on popular business software like Zoom, Slack, and Adobe. The threat actors are part of Russian-speaking Malware-as-a-Service (MaaS) groups called BatLoader and FakeBat. They target industries like manufacturing, software, legal, retail, and healthcare. This episode analyzes their tactics, malware types, and activities, including delivering ransomware, harvesting credentials, and installing remote access Trojans. The discussion also explores the capabilities and payment models of the cyber gangs, as well as incident response strategies and cybersecurity programs.
Chapters
Transcript
Episode notes
1 2 3 4 5
Introduction
00:00 • 2min
Russian Cyber Gangs: Batloader vs Fake Bat
01:36 • 6min
Activities of Dual Russian Cyber Gangs
07:34 • 2min
Russian Speaking Malware-as-a-Service Groups and Cyber Attack Sophistication
09:19 • 5min
Russian Speaking Cyber Gangs Target Employees from 23 Companies
14:47 • 2min
