During the investigation of a series of cyberattacks, our experts discovered a new Russian-speaking destructive group calling itself “Citrus Ransomware Group”. As an initial attack vector, the group uses Trusted Relationship (T1199) between the victim and its contractor.
Group’s arsenal:
- XRay proxy for tunneling between the corporate network and attackers’ servers,
- Snaffler (a network share scanner for locating credentials and secrets),
- Metasploit Framework,
- Sharphound,
- impacket,
- mimikatz,
- fscan network scanner,
- modified version of the peeping-tom keylogger,
- Vanessa-family encryptor (Sn00py).
Attackers also use PS scripts and BAT files generated with LLMs.
Network IOCs:
91.210.109[.]11891.210.108[.]180
We continue the investigation. A more detailed description of this new actor will be published later.
