Void Balaur is a global hack-for-hire cyber mercenary group targeting email and social media accounts since at least 2016.
Analyst brief
Void Balaur is a global hack-for-hire / cyber mercenary group that has been offering its services online since at least 2016. They target a wide range of countries, including Brazil, Central African Republic, Georgia, Kazakhstan, Moldova, Russia, Spain, Sudan, Taiwan, Ukraine, United Kingdom, and the United States. Their primary TTPs involve collecting private data and gaining unauthorized access to specific email and social media accounts, such as Gmail, Outlook, Telegram, Yandex, Facebook, Instagram, and business emails. Defenders should focus on enhanced monitoring for anomalous login activities, especially from suspicious geographic locations, to these critical communication accounts and strictly enforce multi-factor authentication.
Void Balaur
unknown
Void Balaur is a highly active hack-for-hire / cyber mercenary group with a wide range of known target types across the globe. Their services have been observed for sale to the public online since at least 2016. Services include the collection of private data and access to specific online email and social media services, such as Gmail, Outlook, Telegram, Yandex, Facebook, Instagram, and business emails.
What types of accounts does the Void Balaur group primarily target?+
They primarily target specific email and social media accounts, including Gmail, Outlook, Telegram, Yandex, Facebook, Instagram, and business emails.
What key measures should defenders take against the Void Balaur threat?+
Defenders should enforce multi-factor authentication (MFA) and apply enhanced monitoring for anomalous login activities, especially logins from suspicious geographic locations.