Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors CRYSTALRAY

Also known as: stealing credentials, deploying backdoors, Cozy Bear, BlueBravo, Midnight Blizzard, APT28, Pawn Storm, Fancy Bear, Sednit, services, public key cryptography, one private, the file association, handler, Netshell, header, magic bytes, the IconEnvironmentDataBlock, metamorphic, mutating code

Description

CRYSTALRAY is a threat actor known for leveraging open source tools like zmap and SSH-Snake to conduct widespread vulnerability scanning and exploitation. They target victims to collect and sell credentials, deploy cryptominers, and maintain persistence in compromised environments. CRYSTALRAY uses multiple backdoors to control access and spreads through victim networks using SSH-Snake. The actor also uses tools like Platypus for managing victims and extracting sensitive information from compromised systems.

Goals & Targeting

Targeted Sectors

Media
Defense
Financial services
Utilities
Manufacturing
Information technology
Government

Targeted Countries / Regions

IR

AI Analysis

· 1 week ago

Executive Summary

CRYSTALRAY is a threat actor known for leveraging open-source tools like zmap and SSH-Snake to conduct widespread vulnerability scanning and exploitation. Their primary activities include credential theft, deploying cryptominers, and maintaining persistence in compromised environments. CRYSTALRAY uses multiple backdoors for control and spreads through networks using SSH-Snake, with a focus on collecting and selling credentials.

Goals & Targeting

CRYSTALRAY targets victims primarily to steal credentials, which are then sold in underground markets, and to deploy cryptominers for financial gain. The actor's targeting strategy appears to be relatively broad, with a focus on identifying vulnerable systems across sectors such as technology, healthcare, and energy. CRYSTALRAY's campaigns are not limited by geography, likely due to the global nature of their attack methods. Their victims include Linux-based systems, which are often less secured than Windows environments, making them an attractive target.

Enhanced Description

CRYSTALRAY operates with a notable preference for open-source tools such as zmap and SSH-Snake, which they employ for large-scale scanning and exploitation activities. The actor's main objectives are to compromise systems to gather sensitive data, deploy cryptominers for financial gain, and maintain persistent access to victim networks. CRYSTALRAY has been observed using tools like Platypus to manage their victims and extract sensitive information, indicating a systematic approach to managing compromised environments. Their modus operandi involves multiple stages of attack, starting with scanning vulnerable systems, exploiting them, and then using backdoors to maintain control. The actor's use of SSH-Snake for lateral movement suggests a focus on internal network expansion once initial access is achieved. CRYSTALRAY has a broad targeting scope across various sectors, with no specific region or industry appearing to be their primary focus.

Key Capabilities

  • Vulnerability scanning with zmap
  • Exploitation via SSH protocol
  • Credential theft
  • Cryptocurrency mining deployment
  • Network persistence and lateral movement using SSH-Snake
  • Victim management with Platypus

MITRE ATT&CK Tactics

Initial Access
Defense Evasion
Discovery

ATT&CK Techniques

T1003.001 - OS Credential Dumping: Unix-Linux lsmod
T1078 - Account Access Removal
T1569 - Exploitation for Authentication Bypass
T1133 - Service Stop/Destruct

Software / Tooling

zmap
SSH-Snake
Platypus
Mimikatz
CrackMap

Campaigns & Victims

CRYSTALRAY has consistently demonstrated a focus on compromising systems for credential theft and cryptomining. Their campaigns are characterized by large-scale scanning, suggesting a high volume of activity often targeting unpatched or poorly secured systems. Notable patterns include the use of SSH-based attacks, multiple backdoors for long-term persistence, and lateral movement within networks. Victims have been observed across various industries, with no apparent limitation on sector or geography.

IOC Patterns

  • SSH brute-force attempts using commonly known credentials
  • Suspicious dropped binaries from known C2 servers
  • Unusual network scanning activity consistent with zmap usage
  • Anomalous SSH session persistence
  • Known malware signatures of SSH-Snake and Platypus tools

Recommended Actions

  • Implement multi-factor authentication (MFA) for SSH access
  • Monitor network traffic for signs of large-scale scanning or unauthorized SSH connections
  • Patch systems regularly to address vulnerabilities
  • Use endpoint detection and response (EDR) solutions to identify suspicious activity
  • Segment networks to limit lateral movement potential
  • Educate users about phishing attempts that may lead to credential exposure

Suggested Tags

APT
credential_theft
cryptomining
espionage
sector_tech
sector_healthcare

Confidence Assessment

The analysis of CRYSTALRAY is based on community intelligence and observed TTPs, which provide a solid understanding of their capabilities but lack concrete details such as specific campaigns or exact timelines in which they were active. Their use of open-source tools makes attribution challenging, but the actor's operational methods are well-documented.

ATT&CK Techniques

Exfiltration
1 technique
Initial Access
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: services
  2. redcanary.com — Cited by web research for: SocGholish
  3. attack.mitre.org — Cited by web research for: MSBuild

Intel Summary

40

Techniques

40

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

Backdoor / C2
APT
credential_theft
cryptomining
espionage
sector_tech
sector_healthcare

Details

Type
Unknown
Primary Motivation
Financial gain
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.