Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Hacktivists are broadening their scope beyond political motivation

e99efd77392e2b4fe4d9bf5728a12b98

TLP:CLEAR
Active

MD5 Hash

Description

Kaspersky researchers uncovered interconnected hacktivist campaigns attributed to groups including 4BID, Hakerskii Kit, and C.A.S., targeting organizations primarily in Russia and Belarus, but expanding to Kazakhstan, UAE, Syria, and Egypt. Attackers exploited ProxyShell vulnerabilities in Microsoft Exchange servers to deploy fd.aspx web shells and various post-exploitation frameworks including Sliver, Havoc, Mythic Apollo, AdaptixC2, and a custom BlackSalt backdoor. The campaigns deployed ransomware including ClearWater and updated versions of Blackout Locker, alongside EDR killers using BYOVD techniques. Attackers leveraged legitimate RMM tools like AnyDesk, Panorama9, and Tactical RMM for persistence, with AI-generated scripts showing varying quality. The geographical expansion and increased use of ransomware suggest a shift from purely political motivation toward financial gain.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Hacktivists are broadening their scope beyond political motivation
Pattern Type
STIX
Confidence
75%
Valid From
Jul 12, 2026 03:08
Total Sightings
0
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of e99efd77392e2b4fe4d9bf5728a12b98

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.