Abstract

This paper aims to discuss the recent activities of Financially motivated Threat actors and gather IOCs and Threat Intelligence based on the same. Common TTPs are mapped for 18 FIN threat actor groups along with known mitigations as per MITRE Attack Framework. In particular, FIN 7 is discussed in detail, including the lifecycle of Qakbot Malware and malwares are analyzed to gather IOCs using Static Analysis. Intrusion Detection Systems (Snort and YARA) are drafted for Qakbot. A comprehensive analysis on Diamond Model, Kill Chain and Pyramid of Pain is performed for Qakbot Malware and mitigations are mapped to MITRE ATTACK framework. Threat intelligence is gathered on the 1000 latest samples of Qakbot to deep dive into most commonly used delivery methods, malware file types and a timeline analysis is conducted. Advanced tools like OpenCTI and Cuckoo Sandbox are utilized to give an overall analysis on Financially motivated threat actors

Full Text
Paper version not known

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call

Disclaimer: All third-party content on this website/platform is and will remain the property of their respective owners and is provided on "as is" basis without any warranties, express or implied. Use of third-party content does not indicate any affiliation, sponsorship with or endorsement by them. Any references to third-party content is to identify the corresponding services and shall be considered fair use under The CopyrightLaw.