Threats Tagged 'gost'
View all threats tagged with 'gost'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'gost'
Click on any threat for detailed analysis and mitigation recommendations
In September, an organization was targeted by the Akira ransomware, where attackers gained initial access via Remote Desktop Protocol (RDP). The adversary disabled antivirus protections on the compromised endpoint, used Rclone for data exfiltration, and employed a GOST tunneling tool to maintain persistence. After these preparatory steps, the ransomware payload was deployed. Forensic analysis identified key indicators of compromise including specific file paths, SHA256 hashes of malicious binaries, and the command and control (C2) server IP address used for tunnel communications. Join the discussion | AlienVault OTX General | 10/07/2026, 09:45:46 UTC Added: 10/07/2026, 10:03:26 UTC |
Showing 1 to 1 of 1 result