Campaigns
 Hack For Hire Group Targets Legal, Finance and Travel Institutions

Hack For Hire Group Targets Legal, Finance and Travel Institutions

JannicabDeathstalkerHackforHirePowersingEvilnumRebsecVoid Balaur
Unlike malware-as-a-service (MAAS), hacking-for-hire companies carry out sophisticated, hands-on attacks and exploit vulnerabilities in executing their campaigns, according to a report by researchers Their interest in gathering sensitive business information leads us to believe that DeathStalker is a group of mercenaries offering hacking-for-hire services, or acting as some sort of information broker in financial circles.

Indicators of Compromise

process.name
mizuhogroup.us
vote.anobaka.info
careers.mizuhogroup.us
offerings.cloud
angelbridge.capital
abf-cap.co
bankofamerica.nyc
tptf.us
www.abf-cap.com
docs.azure-protection.cloud
beyondnextventures.co
anobaka.jp
smbcgroup.us
tptf.co
tptf.ltd
mufg.tokyo
kvaladrigrosdrom.top
it.zvc.capital
kerymarynicegross.top
smbc-vc.com
www.capmarketreport.com
avid.lno-prima.lol
www.angelbridge.jp
scellapreambulus.top
bankofamerica.tel
www.onlinecloud.cloud
pillygreamstronh.com
cloud.beyondnextventures.co
smbc.ltd
perseus.bond
cloud.mufg.tokyo
beyondnextventures.com
lbegardingstorque.com
ms.msteam.biz
vppops.com
muasaashishaj.com
edwardpof.com
servicebu.org
wazalpne.com
hubflash.co
azcloudazure.com
8as1s2.com
wizdomofdo.com
printer-hub.com
mslogger.org
rombaic.com
zummaride.com
infntio.com
dnstotal.org
global-imsec.com
msintsvc.com
poccodom.com
coinzre.website
qnmarry.com
windows-accs.live
pinktwinlers.com
travinfor.com
webinfors.com
dustforms.com
borisjns.com
corpxtech.com
superimarkets.com
cdn-msft.com
sirius-market.com
amazoncontent.org
udporm.com
fastnetbrowsing.com
azuredcloud.com
apidevops.org
xre.popmonster.ru
roboecloud.com
luccares.com
ecodll.com
weareukrainepeople.com
rowfus.com
laurentprotector.com
hp-prints.com
zerobitfan.com
mscloudin.com
servicejap.com
officelivecloud.com
onesportinc.com
advflat.com
api-printsvc.co.in
namereslv.org
showsvc.com
ihotel-deals.com
dellscanhw.com
bingapianalytics.com
advertbart.com
voipasst.com
gratedomofrome.com
picodehub.com
cloud-cdn.co.in
mailservicenow.com
mircosoftdoc.com
windowslive-detect.com
polanicia.com
questofma.com
esetupdater.com
www.microsoftbooks.dns-dns.com
moretraveladv.com
msdllopt.com
mediadv.org
earthviehuge.com
shopamzn.org
allrivercenter.com
pngdoma.com
multitrolli.com
applecloudnz.com
cloud-appint.com
b.popmonster.ru
login.webdirectoryuk.com
econfuss.com
dbcallog.com
cdr-soft.com
corstand.com
imgncdn.online
printauthors.com
msftprintsvc.com
atomarket.org
mailservice-ns.com
assistcustody.xyz
admex.org
infcloudnet.com
booknerfix.com
liongracem.com
azure-affiliate.com
diamondncenter.biz
tripadvit.com
covidsrc.com
msftmnvm.com
traveladvnow.com
cloudazureservices.com
n90app.com
am-reader.com
amazonappservice.com
visitaustriaislands.com
navyedu.org
pivotnet.org
govdefi.com
datetime.datetime.now
covdd.org
coreadvc.com
hpcloudlive.com
areteir.com
community-approch.com
realshbe.com
scan-eset.com
cloudappcer.com
covsafezone.com
pal4u.net
api-pixtools.com
bgamifieder.com
ksbyz.jelikob.ru
planetjib.com
gvgnci.com
aidobe-update.com
api-printer-spool.com
murfyslaws.com
bookfinder-ltd.com
adsmachineio.com
shopadvs.com
amzbooks.org
enigmadah.com
yomangaw.com
cosmoscld.com
faxing-mon.best
bukjut11.com
cloudhckpoint.com
mlcrosoft.site
netoode.com
circlett.com
hostboxapp.com
refinance-ltd.com
msftld.com
msftinfo.com
philipfin.com
tomandos.com
deltacldll.com
samsthesis.com
voipreq12.com
squerlyh.com
zalofilescdn.com
chaindefend.bid
amazonpmnt.com
myhomelap.com
informaxima.org
worldchangeos.com
textmaticz.com
musthavethisapp.com
govtoffice.org
alipayglobal.org
covidaff.org
pdfscan-now.com
ns1.microsoftsonline.net
worldsiclock.com
schememicrosoft.com
afftrackmedia.com
installcb.online
msft-cdn.cloud
svclouds.com
amazoncld.com
leads-management.net
eclipso.ch
msftapp.com
agagian.com
webdirectoryuk.com
trvolume.net
streamsrvc.com
bunflun.com
ammaze.org
ezteching.com
upservicemc.com
audio-azure.com
kgcharles.com
refsurface.com
meetomoves.com
konyork.com
weatherlocate.com
msftcd.com
bookaustriavisit.com
api.win640.com
moreofestonia.com
orbiz.me
book-advp.com
flightpassist.com
covidsvcrc.com
www.atomicmatryoshka.com
msft-domains.com
rocketcht.ru
json.ama-prime-client.com
orklaus.com
estoniaforall.com
www.mlcrosoft.site
azueracademy.com
netpixelds.com
kamikirim.my.id
jarviservice.org
flyingpackagetrack.com
prodeload.com
vvxtech.net
telefx.net
938jss.com
msftcrs.com
9356.popmonster.ru
apple-sdk.com
msfsvctassist.com
outlooksyn.com
networkcanner.com
api.adobe.com.kz
mstreamvc.com
estimefm.org
inetp-service.com
fxmt4x.com
advideoc.org
firedomez.com
plantgrn.com
dn-mcrosoft.com
check-avg.com
sherence.ru
netrcmapi.com
realmacblog.com
pcamanalytics.com
emobileservices.club
trquotesys.com
searchvpics.com
extrasectr.com
driver-wds.com
symantecq.com
cloudamazonft.com
canopustr.com
appcellor.com
thesailormaid.com
olymacademy.com
eu-mcrosoft.com
appdllsvc.com
mailgunltd.com
xlmfx.com
invgov.org
csmmmsp099q.com
praxpay.org
cargoargs.com
isbigfish.xyz
jmarrycs.com
msft-dev.com
azurecontents.com
amzncldn.com
msfastbrowse.com
futureggs.com
robmkg.com
anypicsave.com
iteamates.com
azureservicesapi.com
trvol.com
ananoka.com
6b4s.popmonster.ru
netwebsoc.com
oauth-azure.com
pallomnareraebrazo.com
qeliabhat.com
forceground.co
bookingitnow.org
goalrom.com
lgnsyjcm9801.open
appronto.in
ntlmsvc.com
cspapop110.com
globaladdressbook.cloud
crm-domain.net
procyonstr.com
cashcores.org
auzebook.com
adsoftpic.com
ns.mircosoftdoc.com
www.ciphertechsolutions.com
mcafee-secd.com
oglmart.com
dnserviceapp.com
wicommerece.com
hostedl.com
iserverxmlhttprequest2.open
kalpoipolpmi.net
nvidiaupdater.com
storangefilecloud.vip
affijay.com
kdr.zarkada.ru
nortonalytics.com
rocketchat.ga
thismads.com
leandroascierto.com
eroclasp.com
covidgov.org
azuredllservices.com
quotingtrx.com
roblexmeet.com
apiygate.com
elitefocuc.com
allmyad.com
apple-cdrp.com
service-azure.com
cloudreg-email.com
mailcloudservices.org
amzn-services.com
deuoffice.org
ve0.popmonster.ru
veritechx.com
sellcoread.com
dogeofcoin.com
mevcsft.com
plancetron.com
ssl-certinfo.eu
azurecfd.com
aka7newmalp23.com
print-hpcloud.com
missft.com
msftprint.com
telecomwl.com
cyphschool.com
cloudpdom.com
windnetap.com
airmail.cc
soundstuner.com
findmypcs.com
travelbooknow.org
rocketcht.cf
khnga.com
multizoom.org
printfiledn.com
flowerads.cloud
amznapis.com
imageztun.com
mainsingular.com
oautho.com
sysconfwmi.com
msfbckupsc.com
imagegyne.com
freepbxs.com
mullticon.com
getappcloud.com
outlookfnd.com
netmsvc.com
newedgeso.com
svcscom.com
eroeurovc.com
windows-ddnl.com
anyfoodappz.com
moneybac.ru
totaledgency.com
voipssupport.com
microsft-community.com
checkpoint-ds.com

Campaign Guidance

Remediation, mitigation, notes, history and related intelligence

Remediations
  • Ensure your website is HTTPs. Most sites I've seen in this realm use a combination of contact email and/or web form. You don't want sensitive information intercepted because of insecure websites. As few people as possible should have admin access to the site, and anything related to publishing. Use as few extensions and plugins as possible. Paying for domain anonymity services is useful if required.
  • Consider using an alias for public facing email addresses. Additionally, lock down all email addresses with multifactor authentication (MFA). The same goes for backup/recovery emails tied to the main account(s).
  • If you have the choice of SMS codes or authentication apps/hardware based security keys for 2FA, choose the latter. SMS won't work with no signal reception, and fraudsters may divert your SMS codes via SIM swapping.
  • Consider using a password manager for organization-specific passwords. If you need to share logins, use a management tool which allows you to share logins without revealing the password itself. Should you land on a phishing site, your password manager won't pre-fill your details into the bogus portal.

Observed Countries14

AE (921)
AR (878)
CH (700)
CN (246)
CY (847)
EG (822)
GB (393)
GE (90)
IL (519)
LB (126)
RU (887)
SA (402)
TR (212)
TW (441)