Full Report
Phishing dominated cyber attacks in H2 2024, accounting for over 90% of incidents across industries due to its simplicity and effectiveness.
Analysis Summary
This actor information appears to be derived from an article that focuses heavily on specific TTPs and a named ransomware group rather than a traditional, persistent threat actor profile. Therefore, I will structure the output based on the most clearly defined entities (the RansomHub group and the observed TTPs).
# Threat Actor: RansomHub Group (Inferred Primary Actor/Campaign)
## Attribution & Identity
Attribution for the overall campaign is not explicitly detailed, but a key entity involved is the **"RansomHub"** group, described as having a profit model targeting **$6-$9 million per stolen data** recovery.
## Activity Summary
The activity summary is drawn from observed TTPs associated with compromised data extortion:
* A significant portion (15%) of observed incidents are linked to the RansomHub group.
* The predominant initial access vector observed in related activity is **phishing (over 90% of incidents)** utilizing **misconfigured Microsoft Teams instances** via a custom tool named **'TeamsPhisher'**.
* The activity also involves domain impersonation, specifically targeting finance/insurance platforms (20-25%) and cryptocurrency platforms (25-30%).
## Tactics, Techniques & Procedures
- Phishing via misconfigured Microsoft Teams instances (using 'TeamsPhisher').
- Domain Impersonation (targeting finance, insurance, and crypto platforms).
- Use of legitimate remote access tools for post-exploitation.
- Network reconnaissance using scanning tools.
- **MITRE ATT&CK IDs (Not explicitly provided in the source, but inferred TTPs):** Initial Access via Phishing (T1566), Remote Access Software (T1219), Network Service Scanning (T1595).
## Targeting
- Sectors: Finance & Insurance (primary focus), Cryptocurrency platforms.
- Geography: Not specified.
- Victims: Not specified beyond industry sectors.
## Tools & Infrastructure
- **Malware families used:** Not explicitly named, but custom phishing tool **'TeamsPhisher'** is utilized.
- **Infrastructure:**
- Remote Access Tools: AnyDesk, ScreenConnect
- Scanning Tools: Nmap, Angry IP Scanner
- C2: Not specified.
## Implications
The reliance on TeamsPhisher suggests a sophisticated initial access technique exploiting misconfigurations in cloud collaboration tools, indicating a pivot towards legitimate enterprise communication platforms for initial compromise. The RansomHub group is monetarily focused on large data extortion operations.
## Mitigations
- Harden Microsoft Teams configurations, particularly permissions related to external sharing or integration that could be exploited by phishing tools.
- Enhance endpoint detection for the deployment and execution of legitimate remote access software (AnyDesk, ScreenConnect).
- Implement rigorous domain monitoring and DMARC/DKIM policies to counteract domain impersonation aimed at financial and crypto entities.