DarkVishnya
Overview
DarkVishnya is a financially motivated threat actor targeting financial institutions in Eastern Europe. In 2017-2018 the group attacked at least 8 banks in this region.
Naming & attribution
DarkVishnya is tracked under 1 names across the industry. It uses 10 documented ATT&CK techniques — more than 30% of the 174 groups tracked here.
| Name | First reported by |
|---|---|
| DarkVishnya | Golovanov, S |
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1200Hardware Additions — used by 1 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Carbanak — 3 shared techniques (19% overlap)
- Cobalt Group — 5 shared techniques (13% overlap)
- INC Ransom — 4 shared techniques (13% overlap)
- Cinnamon Tempest China — 3 shared techniques (12% overlap)
- APT33 Iran — 4 shared techniques (11% overlap)
- APT19 China — 3 shared techniques (11% overlap)
TTPs — 10 techniques across 7 tactics
Resource Development
-
T1588.002Tool
Initial Access
-
T1200Hardware Additions
Execution
-
T1059.001PowerShell
Persistence
-
T1543.003Windows Service
Credential Access
-
T1040Network Sniffing -
T1110Brute Force
Discovery
-
T1046Network Service Discovery -
T1135Network Share Discovery
Command and Control
-
T1219Remote Access Tools -
T1571Non-Standard Port
Tools & malware (2)
Winexe · PsExec