May 24, 2023, 11 a.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

Key Points



  • Agrius continues to operate against Israeli targets, masking destructive influence operations as ransomware attacks.

  • In recent attacks the group deployed Moneybird, a previously unseen ransomware written in C++.

  • Despite presenting themselves as a new group with the name– Moneybird, this is yet another Agrius alias.

  • The data was eventually leaked through one of Agrius previous aliases.

  • As demonstrated in the Moneybird attacks, Agrius’s techniques, tactics and procedures (TTP) remain largely unchanged.


Introduction


While responding to a ransomware attack …

agrius alias attacks data influence influence operations israeli key key points masking name operations organizations ransomware ransomware attacks targeted attacks

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Systems Security Officer (ISSO) (Remote within HR Virginia area)

@ OneZero Solutions | Portsmouth, VA, USA

Security Analyst

@ UNDP | Tripoli (LBY), Libya

Senior Incident Response Consultant

@ Google | United Kingdom

Product Manager II, Threat Intelligence, Google Cloud

@ Google | Austin, TX, USA; Reston, VA, USA

Cloud Security Analyst

@ Cloud Peritus | Bengaluru, India