↓ Skip to main content
  1. Blog/

New actor: Citrus Ransomware Group

·1 min·

During the investigation of a series of cyberattacks, our experts discovered a new Russian-speaking destructive group calling itself “Citrus Ransomware Group”. As an initial attack vector, the group uses Trusted Relationship (T1199) between the victim and its contractor.

Group’s arsenal:

  • XRay proxy for tunneling between the corporate network and attackers’ servers,
  • Snaffler (a network share scanner for locating credentials and secrets),
  • Metasploit Framework,
  • Sharphound,
  • impacket,
  • mimikatz,
  • fscan network scanner,
  • modified version of the peeping-tom keylogger,
  • Vanessa-family encryptor (Sn00py).

Attackers also use PS scripts and BAT files generated with LLMs.

Network IOCs:

  • 91.210.109[.]118
  • 91.210.108[.]180

We continue the investigation. A more detailed description of this new actor will be published later.

Related