Sunday, September 8, 2024
HomeComputer SecurityHacker on Underground Forum Claims to have an RDP and Network Access...

Hacker on Underground Forum Claims to have an RDP and Network Access of Anti Virus Giants Comodo & Symantec

Published on

A threat actor goes by name “Achilles” selling Internal accounts of multinational corporate networks data on various underground hacking forums. His primary targets include private companies and government organizations.

His recent posts show that he has access to corporate networks of popular organizations such as UNICEF, Transat, and access to Cybersecurity Companies that includes Comodo Group & Symantec.

Achilles uses living-off-the land tactics to gain access within the organization’s network; they use to compromise Remote Desktop Protocol (RDP) or use stolen credentials to connect with the victim network using VPN.

- Advertisement - EHA

The threat actor gains access to the network through brute-force attacks targeting remote services and external portal, later the actor tries to elevate privileges.

Threat Actor Activities Targeting Corporate Networks

According to AdvIntel, Achilles posted On May 4, 2019, claimed to have access to UNICEF network and two other private sector companies. UNICEF data was priced for $ 4,000, and later the price was dropped o $2,000.

corporate networks
Exposed Corporate Networks Data

“The majority of Achilles offers are related to breaches into multinational corporate networks via external VPN and compromised RDPs. Targets include private companies and government organizations, primarily in the British Commonwealth.”

Achilles found to be active on underground forums for the last seven months, and he attempted to sell access to several multinational companies.

In April 2019, he posted another set of records that includes 600 GB of data from UK companies, RDP & network access.

On May 15, 2019, Achilles posted that he had access to following organizations, but have not provided any evidence proving that they had access to these networks.

corporate networks
High-profile Security Companies
  • Transat (Transat[.]com)
  • Comodo Group
  • Symantec

The threat actor gains high reputation within the underground community, by offering highly sensitive data and the evidence provided.

“AdvIntel investigators assess with a high degree of confidence that Achilles is a credible threat actor which may attempt to escalate and advance their offensive activities against corporate entities and international organizations.”

Last month a hacking group, Fxmsp contains collective of Russian- and English-speaking hackers, claims they have hacked three antivirus companies and extracted sensitive source code from antivirus software, AI, and security plugins from the companies.

According to the hacker, Transat was breached on May 12 or May 13. However, they have not provided any evidence proving that they actually have access to these networks, AdvIntel reported.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Vulnerabilities in IBM Products Let Attackers Exploit & Launch DOS Attack

IBM has issued a security bulletin addressing critical vulnerabilities in its MQ Operator and...

BBTok Abuses Legitimate Windows Utility Command Tool to Stay Undetected

Cybercriminals in Latin America have increased their use of phishing scams targeting business transactions...

Predator Spyware Exploiting “one-click” & “zero-click” Flaws

Recent research indicates that the Predator spyware, once thought to be inactive due to...

Tropic Trooper Attacks Government Organizations to Steal Sensitive Data

Tropic Trooper (aka KeyBoy, Pirate Panda, and APT23) is a sophisticated cyberespionage APT group,...

Free Webinar

Decoding Compliance | What CISOs Need to Know

Non-compliance can result in substantial financial penalties, with average fines reaching up to $4.5 million for GDPR breaches alone.

Join us for an insightful panel discussion with Chandan Pani, CISO - LTIMindtree and Ashish Tandon, Founder & CEO – Indusface, as we explore the multifaceted role of compliance in securing modern enterprises.

Discussion points

The Role of Compliance
The Alphabet Soup of Compliance
Compliance
SaaS and Compliance
Indusface's Approach to Compliance

More like this

Vulnerabilities in IBM Products Let Attackers Exploit & Launch DOS Attack

IBM has issued a security bulletin addressing critical vulnerabilities in its MQ Operator and...

BBTok Abuses Legitimate Windows Utility Command Tool to Stay Undetected

Cybercriminals in Latin America have increased their use of phishing scams targeting business transactions...

Predator Spyware Exploiting “one-click” & “zero-click” Flaws

Recent research indicates that the Predator spyware, once thought to be inactive due to...