Hacker groupG0105

DarkVishnya

DarkVishnya is a financially motivated threat actor targeting financial institutions in Eastern Europe. In 2017-2018 the group attacked at least 8 banks in this region.

Known attack methods
10
Motive
Financial gain
Source
MITRE ATT&CK

How they break in

Techniques MITRE has documented this group using, mapped onto the ATT&CK matrix. Each one is a behaviour you can look for in your own logs, and a control you can test.

Tools

Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.

PsExecWinexe