Rewterz

Rewterz Threat Alert – New Molerats Malware Targets Governments in the Middle East – Active IOCs

June 21, 2021
Rewterz

Rewterz Threat Alert – Nanocore Rat – Active IOCs

June 21, 2021

Rewterz Threat Alert – DarkSide Ransomware Targets Energy and Food Sectors – Active IOCs

Severity

High

Analysis Summary

We’ve recently observed the emergence of a new ransomware operation named DarkSide threat actor, once again thrusting the group’s name into the spotlight. Threat actors are taking advantages from social engineering campaigns. DarkSide Campaign is targeting food and energy industry by sending threatening emails. In this emails threat actor declare they have successfully exploit networks and gain unauthorized access to sensitive information, which will be disclosed publicly if a ransom of 100 bitcoins (BTC) is not paid.

This campaign is started on June 4 and hitting a few targets every day. Here is a sample of the email text.

Figure 1.. Sample content from the email sent by threat actors posing as DarkSide

Energy and food industries are attractive targets threat actor is interested in energy (oil,gas,and/or petroleum) and food industries.

Figure 2. The industries targeted by the fake DarkSide campaign

Impact

  • Information Theft
  • File encryption
  • Unauthorized Access

Indicators of Compromise

Email

  • darkside@99email[.]xyz
  • darkside@solpatu[.]space

IP

  • 205[.]185[.]127[.]35

Remediation

  • Increase awareness of how ransomware spreads, i.e., through spammed emails and attachments.
  • Monitor and audit network traffic for any suspicious behaviors or anomalies..
  • Do not download files from untrusted sources or emails
  • Block all threat indicators at your respective controls.
  • Search for IOCs in your environment.

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.