PULSE NAME
Router Roulette: Cybercriminals and Nation-States Sharing Compromised Networks
WHITE APT28 AlienVault 2024-08-07 Modified: 2024-09-06
73
IOCs
HIGH VOLUME
TrendMicro highlights the dangers of internet-facing routers and elaborates on Pawn Storm's exploitation of EdgeRouters, complementing the FBI's advisory from February 27, 2024. Cybercriminals and nation-state actors share an interest in compromised routers used as an anonymization layer, with cybercriminals renting out compromised routers and nation-state threat actors like Pawn Storm and Sandworm using dedicated proxy botnets. The analysis focuses on a criminal botnet of Ubiquiti EdgeRouters, disrupted by the FBI in January 2024, which Pawn Storm accessed in April 2022 for persistent espionage campaigns.
Indicators of Compromise (9 / 73 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 142e4198e11d405899619d49cc6dc79c 2024-08-07
FileHash-MD5 369d5d0a5c800724a6d77f100fef0e2c 2024-08-07
FileHash-MD5 6f56666e4a9d31089b6310ebbdffa6f4 2024-08-07
FileHash-MD5 973eee9fae6e3a353286206da7a89904 2024-08-07
FileHash-MD5 ae3054b3d932f7605cfd13ed31668efb 2024-08-07
FileHash-MD5 cb075ac6e8084aa29cffc2000cbe2576 2024-08-07
FileHash-MD5 d5f6794c3b41f1d7f12715ba3315fd7b 2024-08-07
FileHash-MD5 e994df2dec28cc74fa9471f02e23b6af 2024-08-07
FileHash-MD5 f4c0c90d97f3d774d26268bc8900c887 2024-08-07