DarkVishnya

MITRE ATT&CK: G0105 View on attack.mitre.org

Aliases: DarkVishnya

First seen
2017-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
expert
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 11:55:59

Targeted industries: financial-services

Targeted regions: country_code:ua country_code:ru country_code:pl country_code:by country_code:cz

Context

DarkVishnya is a financially motivated threat actor targeting financial institutions in Eastern Europe. In 2017-2018 the group attacked at least 8 banks in this region.

Detection coverage

  • 297 Sigma rules

Malware & tools used

  • Hardware Additions (attack-pattern)
  • Tool (attack-pattern)
  • Windows Service (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • Network Share Discovery (attack-pattern)
  • Brute Force (attack-pattern)
  • Remote Access Tools (attack-pattern)
  • PowerShell (attack-pattern)
  • Network Sniffing (attack-pattern)
  • Non-Standard Port (attack-pattern)
  • Winexe (malware)
  • PsExec (malware)

Reports & references

  • bleepingcomputer.com — Netbooks Rpis And Bash Bunny Gear Attacking Banks From The Inside (report)
  • MITRE ATT&CK — G0105 (report)
  • Kaspersky — 89169 (report)

External references