{"id":2835,"date":"2021-05-22T20:48:44","date_gmt":"2021-05-23T01:48:44","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=2835"},"modified":"2021-05-22T20:48:44","modified_gmt":"2021-05-23T01:48:44","slug":"oldgremlin-criminal-group-aiming-russian-companies","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/oldgremlin-criminal-group-aiming-russian-companies\/","title":{"rendered":"OldGremlin criminal group aiming russian companies"},"content":{"rendered":"\n<p>A new group of cybercriminals called OldGremlin has been targeting Russian companies, including banks, industrial companies, and medical companies, with ransomware attacks. OldGremlin relies on a host of tools, including custom back doors called TinyPosh and TinyNode, to gain an initial foothold in the organization.<\/p>\n\n\n\n<p>Attackers insert their hacking tools into networks via malware downloaded via phishing emails, then encrypt the files and demand them as ransom for around $ 50,000, at the moment this group has only targeted Russian companies up to now.<\/p>\n\n\n\n<p>Investigators first discovered the group in August when they targeted a large, unnamed medical company with a phishing email that was allegedly sent by media holding company RBC, and the attackers are believed to be not Russian as it is rare that the attackers are not Russian. A Russian-speaking ransomware group is targeting targets within Russia, but there are precedents, according to Group-IB senior digital forensic analyst Oleg Skulkin, who identified the Silence and Cobalt hacking groups as previous perpetrators.<\/p>\n\n\n\n<p>The attack on the medical company is what put OldGremlin on the investigators&#8217; radar. In that case, the threat group sent the targets a spoofing email with a ZIP file attached, with the subject &#8220;Invoice Pending&#8221; and pretending to be RBC&#8217;s finance department. Once the victim clicked on the .ZIP file, a unique custom malware called TinyNode was used.<\/p>\n\n\n\n<p>After the executable file ran for just 20 seconds, Windows Defender detected and removed the malware, the researchers said. However, these 20 seconds were enough for the Trojan to achieve persistence on the infected system, and thus the victim does not realize it.<\/p>\n\n\n\n<p>In addition to RBC, OldGremlin has mimicked a variety of entities in its spearphishing emails, including Russian microfinance organizations MIR and Edinstvo, a dental clinic, a law office, and a Belarus Tractor Works plant. At the moment no more information on this group has been released but we will see what happens in the future, also this gives us an idea of \u200b\u200bwhat criminals can do, so it is always essential to take measures and be cautious when it comes to to open or enter suspicious places.<\/p>\n\n\n\n<p>Other reads:<br><a href=\"https:\/\/truxgoservers.com\/blog\/fin7-a-dangerous-group-of-hackers\/\">FIN7, a dangerous group of hackers<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/why-cybercriminals-made-attacks-on-these-sectors\/\">Why cybercriminals made attacks on these sectors?<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new group of cybercriminals called OldGremlin has been targeting Russian companies, including banks, industrial companies, and medical companies, with ransomware attacks. OldGremlin relies on a host of tools, including custom back doors called TinyPosh and TinyNode, to gain an initial foothold in the organization. Attackers insert their hacking tools into networks via malware downloaded [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2838,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10,16],"tags":[36,325],"class_list":["post-2835","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-ransomware","tag-cybersecurity","tag-malwaregroup"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>OldGremlin criminal group aiming russian companies - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Hackers are always on the lookout, this time we will see a group of cybercriminals called OldGremlin that targets Russian companies.....\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/oldgremlin-criminal-group-aiming-russian-companies\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"OldGremlin criminal group aiming russian companies - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Hackers are always on the lookout, this time we will see a group of cybercriminals called OldGremlin that targets Russian companies.....\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/oldgremlin-criminal-group-aiming-russian-companies\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-05-23T01:48:44+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/OldGrm.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"668\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/oldgremlin-criminal-group-aiming-russian-companies\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/oldgremlin-criminal-group-aiming-russian-companies\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"OldGremlin criminal group aiming russian companies\",\"datePublished\":\"2021-05-23T01:48:44+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/oldgremlin-criminal-group-aiming-russian-companies\\\/\"},\"wordCount\":371,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/oldgremlin-criminal-group-aiming-russian-companies\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/OldGrm.jpg\",\"keywords\":[\"Cybersecurity\",\"MalwareGroup\"],\"articleSection\":[\"Cybersecurity\",\"Ransomware\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/oldgremlin-criminal-group-aiming-russian-companies\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/oldgremlin-criminal-group-aiming-russian-companies\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/oldgremlin-criminal-group-aiming-russian-companies\\\/\",\"name\":\"OldGremlin criminal group aiming russian companies - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/oldgremlin-criminal-group-aiming-russian-companies\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/oldgremlin-criminal-group-aiming-russian-companies\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/OldGrm.jpg\",\"datePublished\":\"2021-05-23T01:48:44+00:00\",\"description\":\"Hackers are always on the lookout, this time we will see a group of cybercriminals called OldGremlin that targets Russian companies.....\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/oldgremlin-criminal-group-aiming-russian-companies\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/oldgremlin-criminal-group-aiming-russian-companies\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/oldgremlin-criminal-group-aiming-russian-companies\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/OldGrm.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/OldGrm.jpg\",\"width\":1000,\"height\":668},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/oldgremlin-criminal-group-aiming-russian-companies\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"OldGremlin criminal group aiming russian companies\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"OldGremlin criminal group aiming russian companies - Truxgo Server Blog","description":"Hackers are always on the lookout, this time we will see a group of cybercriminals called OldGremlin that targets Russian companies.....","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/oldgremlin-criminal-group-aiming-russian-companies\/","og_locale":"es_MX","og_type":"article","og_title":"OldGremlin criminal group aiming russian companies - Truxgo Server Blog","og_description":"Hackers are always on the lookout, this time we will see a group of cybercriminals called OldGremlin that targets Russian companies.....","og_url":"https:\/\/truxgoservers.com\/blog\/oldgremlin-criminal-group-aiming-russian-companies\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-05-23T01:48:44+00:00","og_image":[{"width":1000,"height":668,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/OldGrm.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/oldgremlin-criminal-group-aiming-russian-companies\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/oldgremlin-criminal-group-aiming-russian-companies\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"OldGremlin criminal group aiming russian companies","datePublished":"2021-05-23T01:48:44+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/oldgremlin-criminal-group-aiming-russian-companies\/"},"wordCount":371,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/oldgremlin-criminal-group-aiming-russian-companies\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/OldGrm.jpg","keywords":["Cybersecurity","MalwareGroup"],"articleSection":["Cybersecurity","Ransomware"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/oldgremlin-criminal-group-aiming-russian-companies\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/oldgremlin-criminal-group-aiming-russian-companies\/","url":"https:\/\/truxgoservers.com\/blog\/oldgremlin-criminal-group-aiming-russian-companies\/","name":"OldGremlin criminal group aiming russian companies - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/oldgremlin-criminal-group-aiming-russian-companies\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/oldgremlin-criminal-group-aiming-russian-companies\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/OldGrm.jpg","datePublished":"2021-05-23T01:48:44+00:00","description":"Hackers are always on the lookout, this time we will see a group of cybercriminals called OldGremlin that targets Russian companies.....","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/oldgremlin-criminal-group-aiming-russian-companies\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/oldgremlin-criminal-group-aiming-russian-companies\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/oldgremlin-criminal-group-aiming-russian-companies\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/OldGrm.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/OldGrm.jpg","width":1000,"height":668},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/oldgremlin-criminal-group-aiming-russian-companies\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"OldGremlin criminal group aiming russian companies"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2835","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=2835"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2835\/revisions"}],"predecessor-version":[{"id":2842,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2835\/revisions\/2842"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/2838"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=2835"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=2835"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=2835"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}