CosmicBeetleCosmicBeetle

Also known as: CosmicBeetle

Known aliases
1

Profile

CosmicBeetle is a threat actor known for deploying the ScRansom ransomware, which has replaced its previous variant, Scarab. The actor utilizes a custom toolset called Spacecolon, consisting of ScHackTool, ScInstaller, and ScService, to gain initial access through RDP brute forcing and exploiting vulnerabilities like CVE-2020-1472 and FortiOS SSL-VPN. CosmicBeetle has been observed impersonating the LockBit ransomware gang to leverage its reputation and has shown a tendency to leave artifacts on compromised systems. The group primarily targets SMBs globally, employing techniques such as credential dumping and data destruction.

Aliases· 1

CosmicBeetle

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
ScorpionLocker
Actor
SCARLETEEL
Software
Badbeeteam
Actor
Carderbee
Actor
Scarab
Software
Scrabber
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.