Rewterz

Rewterz Threat Alert – Redaman/RTM Banking Trojan Campaigns

March 5, 2019
Rewterz

Rewterz Threat Alert – Threat Actors Targeting Banks Using Tools to Bypass Cyber Security Controls

March 6, 2019

Rewterz Threat Alert “Beyond The Grave” Virus – Threat Indicators

Severity

Medium

Analysis Summary


‘Beyond The Grave (BYTG) virus has surfaced in a phishing campaign that executes a malicious code initiated by a malicious URL. The campaign aims to alter data confidentiality in the targeted hedge funds and a post by the phisher says that BYTG will continue to attack banking and financial institutions.

Impact


Data breach


Indicators of Compromise

IP(s) / Hostname(s)

46.226.108[.]201

URLs

  • aksia[.]co
  • hxxp[:]//aksia[.]co/research/report/interim?id=4547b495-1863-4e5c-8613-ab38dd121144

Email Address

kmorgan[@]aksia[.]co

bill.trust.88992[@]mail[.]com

Remediation


Block the threat indicators at their respective controls.

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.