Skip to content
Open
Show file tree
Hide file tree
Changes from 11 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
24 changes: 24 additions & 0 deletions app/lab/pathtraversal/en.ini
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
information="Most Popular Hacker Groups"
information2="Clop Hacker Group"
click="Click for More"
ex1="Anonymous"
ex2="Lazarus Group"
ex3="Carbanak"
ex4="The Dark Overlord"
ex5="The Equation Group"
ex6="TA505 (Evil Corp)"
ex7="DarkSide"
ex8="Morpho"
ex9="Lapsus$"
details="Details"
Group="Group Name"
des1="Emerging in 2019, Clop specifically targeted large corporate companies in the finance, healthcare, and retail sectors. It gains access to a network using network security vulnerabilities and fraudulent methods, then moves laterally infecting many systems. It steals data and demands ransom in return. Among its victims are users of German software company Software AG, a leading medical research institution, the University of California San Francisco Campus (UCSF), and the Accellion File Transfer Appliance (FTA). Clop's fast and sophisticated tactics continue to pose a serious threat to companies worldwide, highlighting the need for robust cybersecurity measures."
des2="Anonymous is a prime example of a hacktivist collective believing in making the world a better—or at least fairer—place. You might recognize their symbols—Guy Fawkes masks and the slogan 'We are Anonymous. We are Legion. We do not forgive. We do not forget. Expect us.' Their work is claimed to advocate for freedom, government transparency, internet freedom, and social justice. Anonymous' methods include using Distributed Denial of Service (DDoS) attacks to render websites inaccessible. They have also stolen and leaked sensitive information from various organizations. Anonymous gained prominence during events like Occupy Wall Street and the Charlie Hebdo attacks. They are also notable for Operation Payback, targeting companies like PayPal, Visa, and Mastercard when they stopped payment services to Wikileaks. Anonymous played a significant role in the Arab Spring uprisings, developing tools like Tor and VPNs to assist protesters in organizing and sharing information, while disrupting government websites and identifying and arresting hackers claiming allegiance to Anonymous over the years, but the group's decentralized structure makes tracking or prosecuting members difficult. LulzSec, a subgroup believed to be affiliated with Anonymous due to similar attack nature, saw some members arrested and prosecuted for high-profile attacks, including hacks against Sony and News International."
des3="The Lazarus Group is a terrifying North Korean hacker group known for its destructive cyber attacks. It gained worldwide attention in 2014 by hacking Sony Pictures, which was aimed at the movie 'The Interview.' The group is also responsible for the global WannaCry ransomware attack in 2017, which encrypted user files worldwide and demanded ransom in Bitcoin for decryption. The Lazarus Group has stolen billions of dollars from banks in Ecuador, Vietnam, Poland, Mexico, and Bangladesh. They employ various tactics in their operations, but are best known for their in-house phishing campaigns leading to the installation of their custom malware, including Destover and Joanap. Silent Chollima, DarkSeoul, and Whois Team are also believed to be North Korean hackers, with some experts suggesting they could be Lazarus Group subgroups or different names. Their targets include government agencies, media organizations, defense contractors, and supply chains."
des4="Carbanak, also known as Anunak, is a group operating in Eastern Europe that targeted banks and other financial institutions worldwide, resulting in over a billion dollars being stolen. Later, Carbanak expanded its attacks to the hospitality and retail sectors, infiltrating Point of Sale (POS) systems to steal credit card data. This group uses a combination of social engineering, in-house phishing, and Remote Access Trojans (RATs) to execute fraudulent transactions, manipulate account balances, and access sensitive financial data. They often transfer stolen money to fake accounts or prepaid bank cards, but have also used other methods such as manipulating ATMs. The group's main members were arrested and punished in 2018, but POS attacks under the name FIN7 in late that year showed they could still pose a threat."
des5="The Dark Overlord group gained notoriety for ruthless extortion and high-profile data breaches. They target organizations and individuals to steal sensitive data, which they then use to blackmail them. They have focused on medical databases and Hollywood production studios, often demanding large sums of money to withhold stolen data from the public. One of their most famous attacks was the hacking of Netflix's 'Orange Is the New Black,' leaking unaired episodes and demanding ransom. However, their worst attacks have targeted healthcare providers, where they stole sensitive patient information and threatened to expose it if their demands weren't met (some sold on the dark web), as well as sending threats to parents to blackmail school districts. Their methods include sophisticated cyber espionage tools, as well as social engineering, in-house phishing, zero-day exploits, and ransomware distribution. Although Nathan Wyatt was identified and sentenced as The Dark Overlord, some cybersecurity researchers believe he founded other hacker groups like Gnostic Players, NSFW, and Shiny Hunters."
des6="The Equation Group is a cyber espionage group associated with the Tailored Access Operations (TAO) unit of the United States National Security Agency (NSA). Active since at least 2001, the group is suspected to be involved in the Stuxnet worm attack on Iran's nuclear facilities and targeting governments, military organizations, financial institutions, and telecommunications companies in Russia, Pakistan, Afghanistan, India, Syria, and Mali. One of their main methods is exploiting zero-day vulnerabilities to gain access to systems, allowing the deployment of highly sophisticated and persistent malware like Flame, EquationDrug, and GrayFish, which reprograms drive firmware to create hidden disk areas and virtual disk systems. The group's name comes from their heavy use of encryption methods making detection difficult. In 2015, a group called Shadow Brokers claimed to have hacked Equation Group, releasing some hacking tools, causing serious concern in the cybersecurity community."
des7="TA505, also known as Evil Corp, has been active since at least 2009 and is associated with Russia. They are known for cyber attacks on financial institutions, healthcare organizations, government agencies, and educational institutions in the United States, United Kingdom, and Germany. One of their main tools is the banking Trojan Dridex, which they used to steal login credentials, financial information, and other sensitive data from banks and financial institutions. TA505 has also engaged in widescale wire fraud schemes to steal from victims. They also distribute various types of ransomware using social engineering techniques, sending millions of malicious emails often impersonating reputable companies or entities to trick victims into opening malicious attachments or clicking malicious links."
des8="DarkSide is believed to operate primarily in Russia, focusing on ransomware attacks and extortion. In fact, the group operates on a 'ransomware-as-a-service' model, providing affiliates with access to ransomware in exchange for a percentage of the ransom payments, reportedly around 25% for amounts below $500,000 and around 10% for larger amounts exceeding $5 million. DarkSide claims to lack a political identity and avoids targeting specific geographical regions to exclude former Soviet countries. They also refrain from targeting healthcare centers, schools, and non-profit organizations. One of their most notable attacks was the Colonial Pipeline cyberattack, after which they announced ceasing operations and distributing their affiliate programs. However, cybersecurity experts suggested this could be a ruse to allow the group to reemerge under a different name."
des9="The origins and exact location of Morpho are largely unknown. Exploiting primarily zero-day vulnerabilities, they target intellectual property of government agencies, financial institutions, technology companies, and healthcare providers. Their most notable attacks occurred in 2013 against Microsoft, Apple, Twitter, and Facebook. Morpho also attacks their targets using social engineering and specially crafted malware to breach defenses and remain undetected for extended periods. Capturing Morpho members has proven to be a challenging task for cybersecurity experts and law enforcement."
des10="Lapsus$ (also known as DEV-0537) is an international hacker group focused on extortion. The group uses Telegram, with over 50,000 subscribers, for public communication, which includes recruitment and publishing their victims' sensitive data. In 2021, the group targeted the Brazilian Ministry of Health, crashing its website and deleting sensitive data. Bolder attacks occurred in 2022, first in March against major tech companies like Microsoft, Nvidia, and Samsung, and then in September against Uber and Rockstar Games. Lapsus$ used social engineering to hack into access management company Okta, gained unauthorized access to Nvidia's systems, and accessed user data from online marketplace Mercado Libre. They also used multi-factor authentication (MFA) fatigue as a tactic in their attack on Uber. The group's key figure was revealed to be a 16-year-old in Oxford, UK. Although arrested in 2022, Lapsus$ still poses a threat, with most of its members appearing to be teenagers from the UK and Portugal."
Loading