industroyer2 (2)

10427619487?profile=RESIZE_400xActivity Summary - Week Ending on 22 April 2022:

  • Red Sky Alliance identified 9,534 connections from new IP’s checking in with our Sinkholes
  • StreamHost in Belgium Hit 302x
  • Analysts identified 6,436 new IP addresses participating in various Botnets
  • Industroyer2  
  • Lightning Stealer
  • Emotet
  • TraderTraitor
  • Spying on Boris
  • Trolls in the Tolls

    Link to full report: IR-22-112-001_weekly112.pdf

10401512465?profile=RESIZE_400xThe Sandworm Group, a Russian based APT, which recently made headlines after their botnet of machines infected with Cyclops Blink malware, was taken down by the US Department of Justice, has been busy crafting attacks targeting the Ukrainian power grid.  The Computer Emergency Response Team of Ukraine (CERT-UA), had to step in and take action to thwart the attack on the country’s energy facilities.  Blame for the attack has been placed on Sandworm in support of Russian military actions in Easter