Emerging Ransomware Threats Targeting U.S. and South Korean Organizations.

TL;DR Summary
A new ransomware group called RA Group has emerged, using the leaked Babuk ransomware source code to create its own locker variant. The group has already compromised four organizations in the US and South Korea, using customized ransom notes and a unique link to download exfiltration proofs. RA Group also sells the victim's exfiltrated data on its leak portal by hosting the information on a secured TOR site. The group's ransomware employs intermittent encryption to speed up the process and evade detection, and it runs a data leak site to apply additional pressure on victims into paying ransoms.
Topics:business#babuk-ransomware#cybersecurity#data-leak#double-extortion#endpoint-security-ransomware#ra-group
- New Ransomware Gang RA Group Hits U.S. and South Korean Organizations The Hacker News
- Ransomware group claims 2.5 terabytes of stolen data less than a month after emerging online CyberScoop
- Hypervisor Jackpotting, Part 3: Lack of Antivirus Support Opens the Door to Adversaries CrowdStrike
- New 'MichaelKors' Ransomware-as-a-Service Targeting Linux and VMware ESXi Systems The Hacker News
- New RA Group ransomware targets U.S. orgs in double-extortion attacks Bleeping Computer
Reading Insights
Total Reads
0
Unique Readers
13
Time Saved
2 min
vs 3 min read
Condensed
81%
524 → 98 words
Want the full story? Read the original article
Read on The Hacker News