Intezer, an Israeli cybersecurity company, published a blog post on May 29, 2018, stating that it had discovered a previously unknown backdoor when monitoring public data streams in April 2018.Β The back door was developed by the cybercrime group behind Iron Ransomware. Intezer called the organization the “Iron Cybercrime Group,” and suspected that the hacking organization originated in China.
It is speculated that Iron Cybercrime Group has been active for the past 18 months.Β The organization used theΒ RCS source code leaked byΒ the Italian spying software vendorΒ HackingTeamΒ in this back door.
Intezer noted that:
“the Iron group has developed multiple types of malware (backdoors, crypto-miners, and ransomware) for Windows, Linux and Android platforms. They have used their malware to successfully infect, at least, a few thousand victims.”
Ari Eitan, head of research with Intezer said “This is likely an advanced Chinese criminal group. Itβs rare to see people using the old HT [HackingTeam] code, today, because with stuff like this itβs not as simple as a copy and paste. Lotβs of other source code is effective and easier to adopt. β¦ What we see is a big operation with recently written tools.”
Source:Β cyberscoop
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!