PULSE NAME
The Digital Plagiarist Campaign: TelePorting the Carbanak Crew to a New Dimension
WHITE Anunak AlienVault 2017-01-09 Modified: 2017-08-30
31
IOCs
MEDIUM VOLUME
Over the past few months, the tr1adx team has been tracking a Threat Actor which we codenamed "TelePort Crew". We believe the TelePort Crew Threat Actor is operating out of Russia or Eastern Europe with the groups major motivations appearing to be financial in nature through cybercrime and/or corporate espionage. We have dubbed the groups latest campaign Digital Plagiarist for its signature practice of mirroring legitimate sites (using Tenmaxs TelePort Pro and TelePort Ultra site mirroring software) onto similarly named domains, on which the TelePort Crew would host and serve up malware laden Office documents. The Threat Actor would then craft specific spear phishing emails to direct their targets to visit the malicious web sites and open the malware laden documents. Corerrelation of the TelePort Crews TTPs and infrastructure leads us to believe the group is closely affiliated with, and may in fact be, the Carbanak Threat Actor.
Indicators of Compromise (2 / 31 total)
All domain FileHash-MD5 FileHash-SHA1
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 950afc52444e3b23a4923ab07c1e7d87 2017-01-09
FileHash-MD5 ae8404ad422e92b1be7561c418c35fb7 2017-01-09