Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors DarkVishnya

Description

DarkVishnya is a financially motivated threat actor targeting financial institutions in Eastern Europe. In 2017-2018 the group attacked at least 8 banks in this region.(Citation: Securelist DarkVishnya Dec 2018)

AI Analysis

· 2 weeks ago

Executive Summary

DarkVishnya is a financially motivated threat actor that targets financial institutions in Eastern Europe, with at least 8 banks attacked in the region between 2017-2018. The actor's primary motivation is financial gain, and their tactics, techniques, and procedures (TTPs) are designed to facilitate unauthorized access and data theft. DarkVishnya's activities pose a significant threat to the financial sector, and organizations in this space should be aware of their potential targeting.

Goals & Targeting

DarkVishnya's primary objective is to steal sensitive financial information and gain unauthorized access to banking systems. The group's targeting of financial institutions in Eastern Europe suggests that they are seeking to exploit vulnerabilities in these organizations' defenses, possibly for financial gain or to disrupt the financial sector. Typical victims of DarkVishnya's attacks include banks and other financial institutions, although the group's activities may also pose a threat to other organizations that handle sensitive financial information.

Enhanced Description

Despite the lack of publicly available information on DarkVishnya's background and motivations, their activities suggest a high degree of professionalism and expertise. The group's ability to successfully target and compromise multiple financial institutions in a relatively short period of time suggests a well-resourced and well-organized operation. As such, DarkVishnya should be considered a serious threat to the financial sector, and organizations in this space should take steps to educate themselves on the group's TTPs and enhance their defenses accordingly.

Key Capabilities

  • Network exploitation
  • Social engineering
  • Malware development
  • Privilege escalation
  • Lateral movement

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Command and Control
Exfiltration

ATT&CK Techniques

T1543.003
T1040
T1135
T1219
T1059.001
T1588.002
T1110
T1571
T1200

Software / Tooling

Custom malware
PowerShell

Campaigns & Victims

DarkVishnya's campaign patterns suggest a high degree of planning and coordination, with the group often using social engineering tactics to gain initial access to a target network. The group's operational tempo is characterized by a steady stream of attacks over a prolonged period of time, with multiple organizations targeted in a relatively short period. Notable past operations include the group's attacks on at least 8 banks in Eastern Europe between 2017-2018. Victim types typically include financial institutions, although the group's activities may also pose a threat to other organizations that handle sensitive financial information.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Unusual network activity on non-standard ports
  • Custom malware communications over HTTP or HTTPS
  • Suspicious login activity from unknown IP addresses

Recommended Actions

  • Implement robust security controls to detect and prevent spear-phishing attacks
  • Enhance network monitoring and incident response capabilities
  • Conduct regular security audits and penetration testing
  • Educate employees on the risks of social engineering and phishing attacks
  • Implement a robust incident response plan

Suggested Tags

Financially motivated
Targeted attacks
Eastern Europe
Financial sector
Threat actor

Confidence Assessment

The available data on DarkVishnya suggests a moderate to high level of confidence in the group's existence and activities. However, there are still significant gaps in our understanding of the group's background, motivations, and full range of TTPs. Further research and analysis are needed to fully understand the threat posed by DarkVishnya and to develop effective countermeasures.

ATT&CK Techniques

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Securelist DarkVishnya Dec 2018 — Golovanov, S. (2018, December 6). DarkVishnya: Banks attacked through direct connection to local network. Retrieved May 15, 2020.

Intel Summary

10

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

7

Tactics

Tags

Financial Targeting
Financially motivated
Targeted attacks
Eastern Europe
Financial sector
Threat actor

Details

MITRE ID
G0105
Type
Unknown
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--813636db-3939-4a45-bea9-6113e970c029
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.