NEW: Group Profiler — instant APT intel lookup. Try it →

DarkVishnya

Overview

DarkVishnya is a financially motivated threat actor targeting financial institutions in Eastern Europe. In 2017-2018 the group attacked at least 8 banks in this region.

Naming & attribution

DarkVishnya is tracked under 1 names across the industry. It uses 10 documented ATT&CK techniques — more than 30% of the 174 groups tracked here.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
DarkVishnyaGolovanov, S

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1200 Hardware Additions — used by 1 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Carbanak — 3 shared techniques (19% overlap)
  • Cobalt Group — 5 shared techniques (13% overlap)
  • INC Ransom — 4 shared techniques (13% overlap)
  • Cinnamon Tempest China — 3 shared techniques (12% overlap)
  • APT33 Iran — 4 shared techniques (11% overlap)
  • APT19 China — 3 shared techniques (11% overlap)

TTPs — 10 techniques across 7 tactics

Resource Development

Initial Access

Execution

Persistence

Credential Access

Command and Control

Tools & malware (2)

Winexe · PsExec

Reporting (1)