Business Ransomware: ongoing reorganisation
Ransomware ecosystem reorganisation following law-enforcement pressure: rebrandings, splinter groups, affiliate movement and intelligence priorities for defenders.
Tag
Ransomware ecosystem reorganisation following law-enforcement pressure: rebrandings, splinter groups, affiliate movement and intelligence priorities for defenders.
There is no excerpt because this is a protected post.
In April 2021, an unidentified Gold Southfield operator carried out a Ransomware attack against a European company. The initial access is performed by Gold Cabin, an access broker, that deploys IceID (Bokbot), a Remote Access Tool (RAT) malware[link]. Once inside the company, the access broker passes privileges to the main operator who deploys the REvil ransomware. This threat actor … Read more