Also known as: stealing credentials, deploying backdoors, Cozy Bear, BlueBravo, Midnight Blizzard, APT28, Pawn Storm, Fancy Bear, Sednit, services, public key cryptography, one private, the file association, handler, Netshell, header, magic bytes, the IconEnvironmentDataBlock, metamorphic, mutating code
CRYSTALRAY is a threat actor known for leveraging open source tools like zmap and SSH-Snake to conduct widespread vulnerability scanning and exploitation. They target victims to collect and sell credentials, deploy cryptominers, and maintain persistence in compromised environments. CRYSTALRAY uses multiple backdoors to control access and spreads through victim networks using SSH-Snake. The actor also uses tools like Platypus for managing victims and extracting sensitive information from compromised systems.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
CRYSTALRAY is a threat actor known for leveraging open-source tools like zmap and SSH-Snake to conduct widespread vulnerability scanning and exploitation. Their primary activities include credential theft, deploying cryptominers, and maintaining persistence in compromised environments. CRYSTALRAY uses multiple backdoors for control and spreads through networks using SSH-Snake, with a focus on collecting and selling credentials.
Goals & Targeting
CRYSTALRAY targets victims primarily to steal credentials, which are then sold in underground markets, and to deploy cryptominers for financial gain. The actor's targeting strategy appears to be relatively broad, with a focus on identifying vulnerable systems across sectors such as technology, healthcare, and energy. CRYSTALRAY's campaigns are not limited by geography, likely due to the global nature of their attack methods. Their victims include Linux-based systems, which are often less secured than Windows environments, making them an attractive target.
Enhanced Description
CRYSTALRAY operates with a notable preference for open-source tools such as zmap and SSH-Snake, which they employ for large-scale scanning and exploitation activities. The actor's main objectives are to compromise systems to gather sensitive data, deploy cryptominers for financial gain, and maintain persistent access to victim networks. CRYSTALRAY has been observed using tools like Platypus to manage their victims and extract sensitive information, indicating a systematic approach to managing compromised environments. Their modus operandi involves multiple stages of attack, starting with scanning vulnerable systems, exploiting them, and then using backdoors to maintain control. The actor's use of SSH-Snake for lateral movement suggests a focus on internal network expansion once initial access is achieved. CRYSTALRAY has a broad targeting scope across various sectors, with no specific region or industry appearing to be their primary focus.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
CRYSTALRAY has consistently demonstrated a focus on compromising systems for credential theft and cryptomining. Their campaigns are characterized by large-scale scanning, suggesting a high volume of activity often targeting unpatched or poorly secured systems. Notable patterns include the use of SSH-based attacks, multiple backdoors for long-term persistence, and lateral movement within networks. Victims have been observed across various industries, with no apparent limitation on sector or geography.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis of CRYSTALRAY is based on community intelligence and observed TTPs, which provide a solid understanding of their capabilities but lack concrete details such as specific campaigns or exact timelines in which they were active. Their use of open-source tools makes attribution challenging, but the actor's operational methods are well-documented.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
40
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics