JavaGhost logo

JavaGhost

0 incidentes 0 paises 0 sectores apt ID Ultimo: -
Ver en IntelTracker → APTTrail →
JavaGhost is a persistent phishing threat actor that emerged around 2020, initially focusing on website defacement before pivoting in 2022 to target misconfigured Amazon Web Services (AWS) environments for financially motivated phishing campaigns. The group is distinguished by its operational model of leveraging compromised cloud resources, such as AWS Simple Email Service (SES) and WorkMail, for email delivery and infrastructure without engaging in data extortion, a unique characteristic compared to many other financially driven groups. This group is also tracked as TGR-UNK-0011. There is no confirmed nation-state or cybercriminal group attribution for JavaGhost.
Tecnicas MITRE
T1098 -, T1566 -, T1078 -

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Tipo
apt
Pais origen
ID
Motivacion
-
Impacto
6
Actualizado
Tue, 06 Ja

Sectores objetivo (SOCRadar)

Information ServicesOtherOther Information ServicesComputer Systems Design Services