Understanding the Emerging Threat of “Helldown Ransomware”
CategoryDetailsThreat ActorsHelldown Ransomware groupCampaign OverviewRecently expanded to target Linux systems in addition to Windows; employs…
OSINT Updates for November 19 , 2024
https://twitter.com/MachinaRecord/status/1858714358534336790 https://twitter.com/MachinaRecord/status/1858704546748658035 https://twitter.com/MachinaRecord/status/1858684648391668071 https://twitter.com/DarkWebVc/status/1858798998829801905 https://twitter.com/cyberfeeddigest/status/1858790761090723894 https://twitter.com/marktsec46065/status/1858764345842323575
Lynx Ransomware Threat Intel
CategoryDetailsThreat ActorsLynx ransomware group, Successor to INC ransomware group.Campaign OverviewEmerged in 2024; ransomware-as-a-service (RaaS) model;…
BLACK BASTA : RANSOMWARE
CategoryDetailsThreat ActorsBlack Basta (Ransomware-as-a-Service Group)Campaign OverviewOperates via phishing, vulnerability exploitation, social engineering (Microsoft Teams impersonation).…
Russian National in US custody in Phobos ransomware investigation
Category Details Threat Actors Phobos ransomware operators, including alleged administrator Evgenii Ptitsyn (aliases: "derxan" and…
Ransomware Gang Akira leaks unprecedented number of victims’ data in one day
Category Details Threat Actors Akira ransomware Group (Ransomware-as-a-Service). Campaign Overview Published data from 35 victims…
Ransomware Group called Hunters Claims attack for Mantinga.
CategoryDetailsThreat ActorsHunters International ( Acquired the Hive source code and website from the Original Developers. )Campaign…
OSINT Updates for November 18, 2024
https://twitter.com/marktsec46065/status/1858429053016912154 https://twitter.com/Ethic10Hackz/status/1858425229480976418 https://twitter.com/FalconFeedsio/status/1858299994794795372 https://twitter.com/DailyRansomware/status/1858422637107560596 https://twitter.com/fuxsociety1337/status/1858362542810190332 https://twitter.com/OSINTMilitia/status/1858371638452011326
Dissecting Sodinokibi Ransomware Attacks: Bringing Incident Response and Intelligence Together in the Fight
Category Details Threat Actors Sodinokibi (REvil), QakBot operators, Valak operators, Ransomware affiliates Campaign Overview Ransomware…
Threat actor believed to be spreading new MedusaLocker variant since 2022
CategoryDetailsThreat ActorsFinancially motivated group, possibly an Initial Access Broker (IAB) or affiliate of a ransomware…