CRYSTALRAY is a threat actor known for large-scale vulnerability scanning and credential collection using open source tools.
Analyst brief
CRYSTALRAY is a threat actor that uses open source tools to conduct large-scale vulnerability scanning and exploitation, primarily to gather and sell credentials, deploy cryptominers, and maintain persistence in compromised environments. They target victims for credential collection and subsequent network propagation using tools like SSH-Snake. Key TTPs and tools include scanning with zmap, maintaining access with multiple backdoors, and managing victims with Platypus to extract sensitive information. Defenders should prioritize monitoring for SSH key propagation, anomalous scanning patterns, and unauthorized cryptomining processes, while conducting threat hunting for misuse of open source tools.
CRYSTALRAY
unknown
CRYSTALRAY is a threat actor known for leveraging open source tools like zmap and SSH-Snake to conduct widespread vulnerability scanning and exploitation. They target victims to collect and sell credentials, deploy cryptominers, and maintain persistence in compromised environments. CRYSTALRAY uses multiple backdoors to control access and spreads through victim networks using SSH-Snake. The actor also uses tools like Platypus for managing victims and extracting sensitive information from compromised systems.