{"id":29071,"date":"2020-09-23T13:10:00","date_gmt":"2020-09-23T10:10:00","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=29071"},"modified":"2025-08-27T14:57:14","modified_gmt":"2025-08-27T11:57:14","slug":"hackers-masquerading-as-rbc-demanded-50000-in-cryptocurrency","status":"publish","type":"post","link":"https:\/\/forklog.com\/en\/hackers-masquerading-as-rbc-demanded-50000-in-cryptocurrency\/","title":{"rendered":"Hackers masquerading as RBC demanded $50,000 in cryptocurrency"},"content":{"rendered":"<p>A major medical company in Russia was targeted by the criminal group OldGremlin. The attackers demanded $50,000 in cryptocurrency for decrypting the corporate network&#8217;s data. This was reported by Group-IB specialists.<!--more--><\/p>\n<p>The Trojan entered the company&#8217;s network through a phishing email allegedly written by a journalist from the RBC media holding.<\/p>\n<blockquote>\n<p>&#8220;The attackers used a self-written backdoor TinyNode, which allows downloading and launching malicious programs. With its help, the attackers gained remote access to the infected victim&#8217;s computer, through which they continued to move laterally through the organization&#8217;s network,&#8221; \u2013 said Group-IB.<\/p>\n<\/blockquote>\n<p>Several weeks later the attackers deleted the organization&#8217;s backups to make data restoration impossible. From the same server they deployed the ransomware TinyCryptor to hundreds of computers across the corporate network and demanded a cryptocurrency ransom.<\/p>\n<blockquote>\n<p>&#8220;In the cybercriminal milieu, there is an unwritten ban on working with Russian companies, but OldGremlin, consisting of Russian-speaking hackers, is actively attacking exactly them \u2014 banks, industrial enterprises, medical organizations and software developers,&#8221; the specialists noted.<\/p>\n<\/blockquote>\n<p>The first OldGremlin attack was recorded in late March \u2013 early April 2020. According to Group-IB experts, since spring 2020 OldGremlin has conducted at least nine campaigns sending malicious emails allegedly on behalf of the Microfinance Union &#8216;MiR&#8217;, the Russian metallurgical holding, &#8216;Minsk Tractor Works&#8217;, a dental clinic, the RBC media holding, and others.<\/p>\n<p>Earlier ForkLog reported that the operators of the Bitcoin ransomware LockBit <a href=\"https:\/\/forklog.com\/en\/news\/lockbit-ransomware-operators-published-stolen-data-of-us-residents\">published<\/a> stolen data of U.S. residents.<\/p>\n<p>Subscribe to ForkLog news on Telegram: <a href=\"https:\/\/t.me\/forklogfeed\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">ForkLog Feed<\/a> \u2014 the full news feed, <a href=\"https:\/\/telegram.me\/forklog\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">ForkLog<\/a> \u2014 the most important news and polls.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A major Russian medical company was hit by an attack by the criminal group OldGremlin. The attackers demanded $50,000 in cryptocurrency for decrypting the corporate network data. This was reported by Group-IB specialists.<\/p>\n","protected":false},"author":1,"featured_media":29072,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1154,1945],"class_list":["post-29071","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-crimes","tag-group-ib"],"aioseo_notices":[],"amp_enabled":true,"views":"12","promo_type":"1","layout_type":"","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/29071","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/comments?post=29071"}],"version-history":[{"count":1,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/29071\/revisions"}],"predecessor-version":[{"id":29073,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/29071\/revisions\/29073"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media\/29072"}],"wp:attachment":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media?parent=29071"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/categories?post=29071"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/tags?post=29071"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}