Full Report
Top Russian companies and banks under attack from OldGremlin - a group controlling TinyCryptor ransomware
Analysis Summary
# Threat Actor: OldGremlin
## Attribution & Identity
* **Name:** OldGremlin
* **Identity:** A sophisticated, Russian-speaking threat actor.
* **Associations:** Known for developing and utilizing their own proprietary malware, specifically the **TinyCryptor** ransomware (also known as Gremlin).
## Activity Summary
OldGremlin has been highly active in conducting targeted ransomware attacks against high-profile organizations. The article highlights a shift in their behavior, where they have moved from targeting smaller organizations to focusing on top Russian companies and banks. Their campaigns typically involve long dwell times, where they maintain access to the network for several weeks or months before deploying ransomware to ensure maximum impact.
## Tactics, Techniques & Procedures
* **Phishing:** Initial access is often gained through targeted phishing emails containing malicious attachments or links.
* **Lateral Movement:** Use of legitimate tools and frameworks to move through the network.
* **Execution via PsExec:** Deploying ransomware modules using Cobalt Strike’s PsExec functionality.
* **Screen Capture:** Monitoring victim activity and harvesting information through screenshots.
* **C2 Communication:** Utilizing the Tor network for anonymized command and control.
* **Encryption:** Using RC4 for data transmission and custom AES-based encryption for file locking.
**MITRE ATT&CK Mapping:**
* **Phishing (T1566):** Used for initial infection.
* **System Services: SMB/Windows Admin Shares (T1021.002):** Deployment via PsExec.
* **Screen Capture (T1113):** Data collection.
* **Proxy: Multi-hop Proxy (T1090.003):** C2 via Tor.
* **Encrypted Channel: Symmetric Cryptography (T1573.001):** RC4 encryption.
* **Data Encrypted for Impact (T1486):** Deployment of TinyCryptor.
## Targeting
* **Sectors:** Financial services (banks), heavy industry, logistics, and major software developers.
* **Geography:** Primarily targeting organizations within the Russian Federation.
* **Victims:** Top-tier Russian banks and major commercial enterprises.
## Tools & Infrastructure
* **Malware:**
* **TinyCryptor (Gremlin):** Custom ransomware.
* **Cobalt Strike:** Commercial post-exploitation framework.
* **Infrastructure:**
* **Domains:**
* rbcholding[.]press
* broken-poetry-de86.nscimupf.workers[.]dev
* calm-night-6067.bhrcaoqf.workers[.]dev
* rough-grass-45e9.poecdjusb.workers[.]dev
* ksdkpwprtyvbxdobr0.tyvbxdobr0.workers[.]dev
* hello.tyvbxdobr0.workers[.]dev
* **IP Addresses:**
* 136.244.67[.]59
* 95.179.252[.]217
* 45.61.138[.]170
* 5.181.156[.]84
## Implications
OldGremlin represents a significant threat to the Russian corporate sector. Unlike many "Ransomware-as-a-Service" (RaaS) groups that target Western entities, OldGremlin specifically targets domestic Russian organizations. Their high level of technical sophistication and ability to remain undetected for long periods suggest they are a disciplined and capable adversary focused on high-value financial extortion.
## Mitigations
* **Endpoint Protection:** Implement Managed XDR solutions to detect Cobalt Strike and unauthorized PsExec activity.
* **Email Security:** Deploy advanced business email protection to filter sophisticated phishing attempts.
* **Access Control:** Restrict the use of administrative tools like PsExec and monitor for unusual lateral movement.
* **Backup Strategy:** Maintain offline, encrypted backups to ensure recovery without paying the ransom.
* **Network Monitoring:** Monitor for traffic originating from or heading to the Tor network and the identified Cloudflare Workers infrastructure.