
Emerging Ransomware Threats Targeting U.S. and South Korean Organizations.
A new ransomware group called RA Group has emerged, using the leaked Babuk ransomware source code to create its own locker variant. The group has already compromised four organizations in the US and South Korea, using customized ransom notes and a unique link to download exfiltration proofs. RA Group also sells the victim's exfiltrated data on its leak portal by hosting the information on a secured TOR site. The group's ransomware employs intermittent encryption to speed up the process and evade detection, and it runs a data leak site to apply additional pressure on victims into paying ransoms.