Microsoft lifts the lid on a dangerous new hacking group that could pose a major threat to your online accounts

Hacker
(Image credit: Pixabay)

Microsoft has just released an in-depth analysis of a relatively unknown, but highly dangerous, new threat actor.

In its writeup, Microsoft dubbed the group Octo Tempest, and claims it to be a native English, financially motivated, threat actor, with extensive knowledge, plenty of experience, and zero scrupules. 

Octo Tempest was first formed in early 2022 and at the time it was oriented mostly towards selling SIM swaps and stealing accounts belonging to people rich in cryptocurrencies. A few months later, the group expanded its operations and started phishing, social engineering, as well as resetting huge amounts of passwords of hacked service providers. The goal of these campaigns was to steal as much sensitive data as possible.

BlackCat affiliates

Further still, the company became an affiliate of BlackCat (AKA ALPHV), a notorious ransomware-as-a-service provider, and started deploying encryptors on their victims’ endpoints, too. This was particularly surprising to Microsoft given that BlackCat isn’t known for teaming up with native English-speaking criminals.

Octo Tempest’s targets are usually organizations in the gaming, hospitality, retail, manufacturing, technology, and financial industries. Sometimes they will also go for managed service providers (MSPs). 

The group will stop at nothing to gain initial access into their target’s network, going as far as to threaten the victims with physical violence. A couple of chat log screenshots have shown the attacker threatening to send a shooter to the victim’s house to shoot their wife.

After gaining initial access, Octo Tempest will look to expand its reach as much as possible, but at the same time, try to keep a low profile and not raise any alarms. To that end, they were observed suppressing alerts of changes and modifying the mailbox rules.

The end goal of the group is to steal cryptocurrencies, sensitive data, or extort the victim's money through ransomware. The full report can be found here.

More from TechRadar Pro

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
China
Microsoft says Chinese Silk Typhoon hackers are targeting cloud and IT apps to steal business data
A person at a laptop with a cybersecure lock symbol floating above it.
Cybercrime gang targets victims with "triple threat" attacks
Trojan
Microsoft warns of a devious new RAT malware which can avoid detection with apparent ease
Phishing
Russian cyberattackers spotted hitting Microsoft Teams with new phishing campaign
Russia
Major Russian hacking group shifts focus to US and UK targets
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
A new Microsoft 365 phishing service has emerged, so be on your guard
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras