DarkVishnya
MITRE ATT&CK: G0105 View on attack.mitre.org
Aliases: DarkVishnya
- First seen
- 2017-01-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- expert
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 11:55:59
Targeted industries: financial-services
Targeted regions: country_code:ua country_code:ru country_code:pl country_code:by country_code:cz
Context
DarkVishnya is a financially motivated threat actor targeting financial institutions in Eastern Europe. In 2017-2018 the group attacked at least 8 banks in this region.
Detection coverage
- 297 Sigma rules
Malware & tools used
- Hardware Additions (attack-pattern)
- Tool (attack-pattern)
- Windows Service (attack-pattern)
- Network Service Discovery (attack-pattern)
- Network Share Discovery (attack-pattern)
- Brute Force (attack-pattern)
- Remote Access Tools (attack-pattern)
- PowerShell (attack-pattern)
- Network Sniffing (attack-pattern)
- Non-Standard Port (attack-pattern)
- Winexe (malware)
- PsExec (malware)
Reports & references
- bleepingcomputer.com — Netbooks Rpis And Bash Bunny Gear Attacking Banks From The Inside (report)
- MITRE ATT&CK — G0105 (report)
- Kaspersky — 89169 (report)