RA Group: A New and Dangerous Ransomware Gang Targeting U.S. and South Korean Organizations.

1 min read
Source: BleepingComputer
RA Group: A New and Dangerous Ransomware Gang Targeting U.S. and South Korean Organizations.
Photo: BleepingComputer
TL;DR Summary

A new ransomware group called RA Group is targeting organizations in the US and South Korea, using a double-extortion tactic and a custom ransom note for each attack. The group's encryptor is based on the leaked source code for the Babuk ransomware, and it uses intermittent encryption to speed up the encryption process. The ransom note requires victims to negotiate a ransom using qTox messenger, and the group threatens to publish stolen data on extortion sites if the ransom is not paid. It is unclear how the group breaches systems and spreads laterally on a network.

Share this article

Reading Insights

Total Reads

0

Unique Readers

12

Time Saved

2 min

vs 3 min read

Condensed

81%

50396 words

Want the full story? Read the original article

Read on BleepingComputer