RA Group: A New and Dangerous Ransomware Gang Targeting U.S. and South Korean Organizations.

TL;DR Summary
A new ransomware group called RA Group is targeting organizations in the US and South Korea, using a double-extortion tactic and a custom ransom note for each attack. The group's encryptor is based on the leaked source code for the Babuk ransomware, and it uses intermittent encryption to speed up the encryption process. The ransom note requires victims to negotiate a ransom using qTox messenger, and the group threatens to publish stolen data on extortion sites if the ransom is not paid. It is unclear how the group breaches systems and spreads laterally on a network.
- New RA Group ransomware targets U.S. orgs in double-extortion attacks BleepingComputer
- New 'MichaelKors' Ransomware-as-a-Service Targeting Linux and VMware ESXi Systems The Hacker News
- Hypervisor Jackpotting, Part 3: Lack of Antivirus Support Opens the Door to Adversaries CrowdStrike
- New ransomware gang RA Group quickly expanding operations CSO Online
- New Ransomware Gang RA Group Hits U.S. and South Korean Organizations The Hacker News
Reading Insights
Total Reads
0
Unique Readers
12
Time Saved
2 min
vs 3 min read
Condensed
81%
503 → 96 words
Want the full story? Read the original article
Read on BleepingComputer