Threat Landscape Update on Grandoreiro and Luna Tempest
Jun 5, 2024
auto_awesome
Sherrod DeGrippo discusses the Grandoreiro banking Trojan's global expansion and the Luna Tempest extortion group targeting startups. The evolving tactics of threat actors, challenges in disrupting them, and the rise of identity-based attacks are highlighted. Collaboration and industry unity are emphasized in combating cyber threats.
Grandoreiro banking Trojan has expanded globally targeting US and UK with phishing emails.
Luna Tempest focuses on targeted extortion without ransomware, showing a shift in threat landscape.
Deep dives
Financially Motivated Threats: Grand Oréro Banking Trojan Activity Profile
Microsoft has observed an increase in financially motivated threats, focusing on banking trojans. The Grand Oréro banking Trojan, active since at least 2017, expanded globally in 2024, targeting regions like the UK and Australia. The trojan initiates through phishing emails impersonating trusted sources, leading victims to download malicious files. It operates similarly to older banking trojans like Dana bot, aiming to steal financial data, even adapting to bypass two-factor authentication.
Extortion-Based Threat Actor: Luna Tempest
Luna Tempest, an extortion-based group, primarily targets startups and companies in finance, biotech, and pharmaceutical sectors. This relatively small US and UK-based group focuses on extorting these organizations for financial gain. Different from traditional crime actors, Luna Tempest shows a trend towards targeted aggressive approaches, including personal harassment tactics, showcasing a shift in the threat landscape towards more personalized attacks.
Collaborative Threat Intelligence Efforts and Community Involvement
Effective threat intelligence involves collaboration and information sharing among cybersecurity professionals to combat threat actors. Companies like Microsoft engage in partnerships and share insights with law enforcement agencies to disrupt malicious activities. The cybersecurity community's collective effort aims to build comprehensive threat profiles, leveraging shared knowledge to enhance responses and mitigate cyber threats effectively.
On this week's episode of The Microsoft Threat Intelligence Podcast, Sherrod DeGrippo is joined by two of MSTIC’s finest analysts. They discuss recent trends in financially motivated cyber threats observed by Microsoft, focusing particularly on two cases: the Grandoreiro banking Trojan and the Luna Tempest crimeware actor. The Grandoreiro Trojan, active since 2017, has expanded globally beyond its initial Latin American focus, now targeting countries like the U.S. and the UK. This Trojan typically starts with phishing emails to steal financial information. Despite efforts to disrupt this activity, new clusters have emerged. The discussion also covers Luna Tempest, a U.S.- and UK-based extortion group targeting startups and smaller companies, particularly in sectors like insurance, FinTech, and biotech, seeking high payouts by threatening to release sensitive data.
In this episode you’ll learn:
The resilience and adaptability of threat actors in response to global disruption efforts
Why Luna Tempest focuses solely on extortion without deploying ransomware
How the Grandoreiro Banking Trojan has expanded globally
Some questions we ask:
How do we distinguish between the various threat actor groups and their malware?
What can businesses do to protect themselves from identity-based attacks?
Have these cybercriminals perfected an extortion program?