Recorded Future
GrayCharlie Cyber Threat Activity Analysis
Pages
36
Time to read
29 mins
Publication
Language
English
Pages
36
Time to read
29 mins
Publication
Language
English
This document is a cyber threat analysis report focusing on the threat actor GrayCharlie, which has been active since mid-2023. The report details the group's tactics, techniques, and procedures (TTPs), particularly its method of compromising WordPress sites by injecting malicious JavaScript. This JavaScript redirects users to fake browser update pages or ClickFix pop-ups, ultimately delivering malware such as NetSupport RAT, Stealc, and SectopRAT. Insikt Group has identified extensive infrastructure associated with GrayCharlie, including command-and-control servers and staging infrastructure linked to MivoCloud and HZ Hosting Ltd. The report outlines two primary attack chains utilized by GrayCharlie and emphasizes the need for security measures such as blocking IP addresses associated with these threats and implementing updated detection rules. Additionally, it provides mitigation strategies and a comprehensive list of indicators of compromise (IoCs) to aid in defending against these cyber threats.