Tag

Double Extortion

All articles tagged with #double extortion

RA Group: A New and Dangerous Ransomware Gang Targeting U.S. and South Korean Organizations.
cybersecurity3 years ago

RA Group: A New and Dangerous Ransomware Gang Targeting U.S. and South Korean Organizations.

A new ransomware group called RA Group is targeting organizations in the US and South Korea, using a double-extortion tactic and a custom ransom note for each attack. The group's encryptor is based on the leaked source code for the Babuk ransomware, and it uses intermittent encryption to speed up the encryption process. The ransom note requires victims to negotiate a ransom using qTox messenger, and the group threatens to publish stolen data on extortion sites if the ransom is not paid. It is unclear how the group breaches systems and spreads laterally on a network.

Emerging Ransomware Threats Targeting U.S. and South Korean Organizations.
endpoint-security-ransomware3 years ago

Emerging Ransomware Threats Targeting U.S. and South Korean Organizations.

A new ransomware group called RA Group has emerged, using the leaked Babuk ransomware source code to create its own locker variant. The group has already compromised four organizations in the US and South Korea, using customized ransom notes and a unique link to download exfiltration proofs. RA Group also sells the victim's exfiltrated data on its leak portal by hosting the information on a secured TOR site. The group's ransomware employs intermittent encryption to speed up the process and evade detection, and it runs a data leak site to apply additional pressure on victims into paying ransoms.

CACTUS Ransomware Evades Antivirus and Exploits VPN Flaws to Infiltrate Networks
endpoint-security-ransomware3 years ago

CACTUS Ransomware Evades Antivirus and Exploits VPN Flaws to Infiltrate Networks

Cybersecurity researchers have discovered a new ransomware strain called CACTUS that exploits known flaws in VPN appliances to infiltrate targeted networks. The ransomware has been observed targeting large commercial entities since March 2023, using double extortion tactics to steal sensitive data prior to encryption. CACTUS actors attempt to enumerate local and network user accounts before creating new user accounts and deploying the ransomware encryptor via scheduled tasks. The ransomware also utilizes Cobalt Strike and a tunneling tool referred to as Chisel for command-and-control, alongside remote monitoring and management (RMM) software like AnyDesk to push files to the infected hosts.