Tag Archive for: longrunning

Long-running RUBYCARP botnet operation examined


BleepingComputer reports that intrusions involving known security flaws and brute force tactics have been deployed by Romanian threat operation RUBYCARP for at least a decade, with the group currently operating a botnet with more than 600 breached servers.

After several months of targeting Laravel apps impacted by the remote code execution flaw, tracked as CVE-2021-3129, RUBYCARP has transitioned to brute-force attacks against SSH servers to distribute a shellbot payload that would make the server a part of its botnet infrastructure, according to a report from the Sysdig Threat Research Team.

Moreover, cryptocurrency miners XMRig, NanoMiner, and C2Bash have been used by the threat group to exfiltrate cryptocurrency assets, said researchers. The findings also showed that aside from engaging in phishing attacks involving emails spoofing European financial and logistics entities to facilitate financial data theft, RUBYCARP has also entered the business of cyber weapon development and trade.

Source…

Russia Report reveals long-running cyber warfare campaign against UK – ComputerWeekly.com

  1. Russia Report reveals long-running cyber warfare campaign against UK  ComputerWeekly.com
  2. ISC Attributes Cyber-Attacks and Election Interference to Russia  Infosecurity Magazine
  3. Security services set for extra powers after damning report on Russian threat  shropshirestar.com
  4. Boris Johnson accused of giving Kremlin green light to meddle in UK politics  The Independent
  5. View Full Coverage on read more

“cyber warfare news” – read more