The group usually targets vulnerable servers to breach information including internal data from companies or encrypts files and demands money. Their targets of attack are usually Windows servers that are poorly managed or are not patched to the latest version. Besides these, there are also attack cases that targeted email servers or MS-SQL database servers.
Executive Summary
Dalbit is a cyber threat actor primarily targeting vulnerable servers, particularly Windows-based systems that are unpatched or misconfigured. Their activities include data breaches and ransomware attacks, where they encrypt files and demand payment for decryption keys. Dalbit's operations impact various sectors globally by exploiting common security weaknesses in server environments.
Goals & Targeting
Dalbit likely targets industries and organizations with poorly maintained or unpatched servers, as these present easy entry points. Their strategic objectives appear to be financial gain through ransomware or data exfiltration rather than targeting specific sectors or countries. Typical victims are organizations regardless of sector but focused on those with server management weaknesses.
Enhanced Description
Dalbit predominantly targets vulnerable servers, including Windows, email, and MS-SQL database servers, leveraging unpatched or mismanaged systems to breach information or deploy ransomware. Their approach often involves data theft or encryption for financial gain. While the primary motivation is not explicitly known, their targeting suggests a focus on exploiting common security flaws across various industries. This group's modus operandi aligns with other cybercriminals using server vulnerabilities but lacks specific details about their long-term strategic goals.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Dalbit's campaigns involve targeting vulnerable servers, likely focusing on ease of access rather than high-profile or critical infrastructure. Their approach is consistent across targets without significant variation observed in their tactics.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in their targeting methods and activities. Limited information on specific campaigns, tools used, or exact targeting patterns across sectors and countries.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics