DarkVishnya is a threat group targeting banks with physical intrusion devices.
Analyst brief
DarkVishnya is a threat group that targets banks using physical intrusion devices. They utilize hardware like Bash Bunny, netbooks, or Raspberry Pi for initial access, then deploy tools such as PsExec and PowerShell to create Windows Services for persistence and lateral movement. Defenders should prioritize physical security against unauthorized USB devices, monitor for creation of suspicious Windows services, and inspect network traffic for remote access tools communicating over non-standard ports.
DarkVishnya
unknown
Dubbed DarkVishnya, the attacks targeted at least eight banks using readily-available gear such as netbooks or inexpensive laptops, Raspberry Pi mini-computers, or a Bash Bunny - a USB-sized piece hardware for penetration testing purposes that can pose as a keyboard, flash storage, network adapter, or as any serial device.
Monitor network traffic to detect Remote Access Tools using Non-Standard Port.
FAQ2
What physical devices does the DarkVishnya group use for initial access to banks?+
DarkVishnya uses USB-based devices such as Bash Bunny, netbooks, or Raspberry Pi for initial access. The Bash Bunny can pose as a keyboard, flash storage, network adapter, or any serial device.
What defensive measures should be taken against DarkVishnya attacks?+
Defenders should prioritize physical security against unauthorized USB devices, monitor for creation of suspicious Windows services, and inspect network traffic for remote access tools communicating over non-standard ports.