
Palo Alto Network’s Unit 42 details the disturbing rise of a ransomware group Luna Moth, (aka) the Silent Ransom Group that has invested in call centers and infrastructure to target individual victims.
It starts its campaign with a breach that uses fake subscription renewals. The group used phishing campaigns that deliver remote-access tools to enable corporate data theft. It will threaten the victim with ransom and if not paid it will leak the data
This ransomware engages in callback phishing (telephone-oriented attack delivery), a social engineering attack that requires a threat actor to interact with the target to accomplish its objectives. The attack style is more resource-intensive but less complex than script-based attacks and is said to have a much higher success rate.
Luna Moth uses legitimate tools to ensure the activity isn’t detected as malicious and hence unlikely to be flagged by traditional security products.
Recent campaigns are a phishing email with an invoice indicating that the recipient’s credit card has been charged for a service, typically under $1,000. The phishing email is personalized to the recipient, contains no malware, and is sent using a legitimate email service.
Attached to the email is a PDF file with a unique ID and phone number, often written with extra characters or formatting to prevent data loss prevention platforms from recognizing it. When recipients call the number, they’re routed to a Luna Moth-controlled call center and connected to a live agent.
On the call, the victim is persuaded to download and run a remote support tool to allow the attacker to manage the victim’s computer. Having gained access, the attacker then downloads and installs a RAT that allows them to achieve persistence and find files for exfiltration.
To prevent these type of social engineering attacks, employee cybersecurity awareness training is the first line of defense. The researchers conclude that they expect callback phishing attacks to increase in popularity thanks to the low per-target cost, low risk of detection and fast monetization.
Indicators of Compromise
Domain | IP Address |
dictumst.xyz | 23.254.229.90 |
tincidunt.xyz | 192.119.110.47 |
deserunt.xyz | 192.119.110.22 |
mczoho.com | 192.119.111.25 |
masterzohoclass.com | 192.236.178.3 |
zohocook.com | 192.236.177.251 |
molestie.xyz | 192.236.193.152 |
adipiscing.xyz | 192.236.193.150 |
fringilla.xyz | 192.236.193.148 |
volutpat.xyz | 192.236.193.151 |
ultrices.xyz | 192.236.193.149 |
cookwithzoho.com | 192.236.193.141 |
cookingbyzoho.com | 192.236.193.140 |
massay.xyz | 192.236.177.20 |
masaay.xyz | 192.236.176.79 |
myaaas.xyz | 192.236.192.84 |
myaasa.xyz | 192.236.179.76 |
myasaa.xyz | 192.236.178.135 |
masyaa.xyz | 192.236.193.86 |
maysaa.xyz | 192.236.193.81 |
msaaay.xyz | 192.236.192.215 |
maaays.xyz | 192.236.194.2 |
maaasy.xyz | 192.236.194.31 |
cookingzoho.com | 192.236.195.42 |
zohomclass.com | 192.236.195.83 |
zohocooking.com | 192.236.198.22 |
studyzoho.com | 192.236.198.23 |
molesste.xyz | 192.236.208.56 |
zohocookingmeals.com | 192.236.199.2 |
zohokitchen.com | 192.236.192.2 |
ullamm.xyz | 23.254.227.79 |
zohokitchenmaster.com | 192.236.192.9 |
zohoteachingmaster.com | 192.236.192.69 |
zohoteaching.com | 192.236.192.73 |
tincidut.xyz | 142.11.215.104 |
masterclassgold.com | 142.11.215.25 |
proodee.xyz | 192.236.179.217 |
zohocookingclass.com | 198.54.117.244 |
zohoclasspro.com | 142.11.215.212 |
deerunt.xyz | 142.11.206.153 |
nostuud.xyz | 192.236.147.234 |
aliuuip.xyz | 23.254.228.211 |
zohoduolingo.com | 192.236.209.36 |
duolingoclass.com | 192.236.209.34 |
acsyruse.xyz | 192.236.155.81 |
zoholanguageclass.com | 142.11.209.198 |
zoholanguage.com | 104.168.164.244 |
duo-lingo-class.com | 104.168.204.231 |
caaom.xyz | 192.236.155.151 |
caaof.xyz | 192.236.155.106 |
caaog.xyz | 192.236.155.138 |
caaor.xyz | 192.236.155.103 |
caaon.xyz | 192.236.155.102 |
duolingo-class.com | 192.236.192.33 |
studyduolingo.com | 192.236.177.18 |
masterclass-cook.com | 192.236.193.171 |
duuis.xyz | 192.236.249.78 |
eeeaa.xyz | 192.236.249.80 |
veelit.xyz | 192.236.249.79 |
eesse.xyz | 192.236.249.76 |
moolit.xyz | 192.236.249.75 |
premiumduolingo.com | 104.168.201.129 |
cook-masterclass.com | 104.168.201.121 |
yourduolingo.com | 104.168.201.87 |
masterclasscooking.com | 192.119.111.51 |
duolingoeducation.com | 192.119.111.21 |
educationduolingo.com | 192.119.111.197 |
masterclass-chef.com | 104.168.201.100 |
allduolingo.com | 192.236.194.113 |
allredoo.xyz | 192.236.194.42 |
aredo.xyz | 192.236.160.132 |
aeedo.xyz | 192.236.193.182 |
allreedo.xyz | 104.168.218.242 |
alloout.xyz | 104.168.135.71 |
subscriptionduolingo.com | 192.236.195.74 |
germanbyduolingo.com | 192.236.208.44 |
duolingo-italianclass.com | 104.168.171.231 |
aeecc.xyz | 23.238.40.29 |
eceee.xyz | 23.238.40.28 |
aeocc.xyz | 23.238.40.31 |
aedcc.xyz | 23.238.40.30 |
aeucc.xyz | 23.238.40.32 |
duolingoitalian.com | 192.236.155.243 |
duolingoit.com | 192.236.176.197 |
duolingoitclass.com | 104.168.171.104 |
duolingo-it.com | 192.236.176.199 |
italian-duolingo.com | 192.119.110.112 |
masterclass-design.com | 192.119.110.166 |
masterclass-design.com | 192.119.110.166 |
masterclass-design.com | 192.119.110.166 |
masterclass-design.com | 192.119.110.166 |
masterclass-design.com | 192.119.110.166 |
masterclass-design.com | 192.119.110.166 |
aaeece.xyz | 142.11.210.14 |
aaeeci.xyz | 108.174.195.199 |
aaeeco.xyz | 108.174.197.196 |
aaeecu.xyz | 104.168.145.45 |
aaeecy.xyz | 142.11.194.201 |
eebna.xyz | 192.236.194.76 |
eecna.xyz | 192.236.194.77 |
eedna.xyz | 192.236.194.78 |
eegna.xyz | 192.236.194.80 |
eetna.xyz | 192.236.194.81 |
brightmasterclass.com | 192.236.192.193 |
effectivemasterclass.com | 192.236.176.143 |
happymasterclass.com | 192.119.110.131 |
masterclass-business.com | 192.119.110.166 |
masterclasscources.com | 23.254.225.145 |
masterclassworld.com | 192.236.198.164 |
rainbowmasterclass.com | 192.236.192.192 |
strongmasterclass.com | 23.254.227.9 |
unitedmasterclass.com | 192.236.179.2 |
westsidemasterclass.com | 23.254.228.85 |
westernmasterclass.com | 23.254.225.145 |