The specialists from London-headquartered global security solutions provider Positive Technologies said government organisations in India, Brazil, Kazakhstan, Russia, Thailand and Turkey have suffered damage as a result of the group’s attacks.
The investigation by Positive Technologies found that the attackers moved along the network either by exploiting Remote Code Execution vulnerability (MS17-010) or by using stolen credentials.