Harvester APT

General News

Summary

The hacker group is tracked as Harvester, and its detected threatening operations consist of espionage attacks against targets in South Asia, mainly in Afghanistan. The focus on Afghanistan, in particular, is interesting, having in mind the recent major events that took place there, such as the decision of the U.S. to withdraw its army after maintaining a presence in the country for two decades. Although at the moment there isnt enough data to pinpoint the exact nation-state that is backing Harvesters activities, certain evidence such as the groups attacks not being financially motivated and the use of several custom-built threatening tools point towards it being a state-sponsored cybercrime outfit definitely. The Harvester APT employs a mix of custom malware and publicly available tools to create a backdoor on the compromised machines and then siphon information from them. These include a custom screenshot grabber, the Cobalt Strike Beacon tool, commonly abused by cybercriminals, and Metasploit, a modular framework that can be used for numerous intrusive purposes.

Classifications

industries
Entertainment
applications
Customer Service & Support

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M