Full Report
In its latest campaign this spring, DarkGaboon was observed deploying LockBit 3.0 ransomware against victims in Russia, Positive Technologies said in a report last week.
Analysis Summary
# Threat Actor: DarkGaboon
## Attribution & Identity
- **Identification:** Financially motivated cybercrime group first identified by Positive Technologies in January.
- **Known Aliases:** DarkGaboon.
- **Associated Groups:** Operates independently, unlike typical LockBit affiliates utilizing Ransomware-as-a-Service (RaaS); they appear to use a publicly leaked version of LockBit 3.0.
- **Language/Origin Indicators:** Likely fluent in Russian; uses Russian language for phishing emails and ransom notes.
## Activity Summary
- **Historical Activity:** Traced back to operations starting in 2023.
- **Recent/Campaign Activity:** Active in spring (current year), deploying LockBit 3.0 ransomware in a current campaign. Previously linked to LockBit-based attacks on Russian financial institutions between March and April 2023, using the same contact email addresses in ransom notes.
## Tactics, Techniques & Procedures
- **Initial Access:** Spearphishing via emails written in Russian, designed to appear urgent and targeting financial department employees.
- **Delivery Mechanism:** Malicious attachments disguised as legitimate financial documents using lure templates sourced from public Russian-language sites.
- **Execution/Impact:** Deploys **LockBit 3.0** ransomware to encrypt files.
- **Post-Infection:** Leaves a ransom note written in Russian containing two contact email addresses.
- **Data Exfiltration:** No signs of data exfiltration were found during recent incidents.
- **Observable TTPs (Blends with general cybercrime):** Uses open-source tools like **Revenge RAT** and **XWorm**.
- **MITRE ATT&CK IDs:** Not explicitly provided in the text, but ransomware deployment and phishing are central.
## Targeting
- **Sectors:** Banking, retail, tourism, and public services.
- **Geography:** Specifically targeting Russian companies/organizations.
- **Victims:** Russian organizations (general mention).
## Tools & Infrastructure
- **Malware Families Used:** LockBit 3.0 (independently sourced/leaked version), Revenge RAT, XWorm.
- **Infrastructure:** Ransom notes contain two contact email addresses (previously linked to March/April 2023 attacks). No specific C2 domains or IPs were mentioned.
## Implications
DarkGaboon poses a significant financial threat to Russian organizations by leveraging widely available ransomware tools (LockBit 3.0) and tailoring their social engineering (Russian language phishing) to their local targets. Their independent operation model might make tracking slightly different from traditional RaaS affiliates.
## Mitigations
- Implement robust email filtering and train finance department personnel to scrutinize urgent financial documents received via email, especially suspicious Russian-language lures.
- Deploy and maintain comprehensive endpoint detection and response (EDR) capable of detecting known behaviors and file characteristics associated with LockBit 3.0, Revenge RAT, and XWorm.
- Ensure backup and recovery capabilities are robust, given the focus on file encryption.
- Monitor for communication attempts via the identified ransom note email addresses if previous incidents are relevant to the environment.