HELLCAT Ransomware Group Strikes Again: Four New Victims Breached via Jira Credentials from Infostealer Logs
ID: fb74e7ad-edd0-5a18-a333-529bffa9f1dc
STIX ID: report--fb74e7ad-edd0-5a18-a333-529bffa9f1dc
Feed Name: infostealers.com
Hudson Rock reports that the HellCat ransomware group recently compromised Atlassian Jira instances at HighWire Press, Asseco Poland, Racami, and LeoVegas by leveraging Jira credentials harvested from victims' machines by infostealer malware; the group exfiltrated sensitive data, published breach proofs with countdown timers on its leak site, and issued extortion demands. The article links these attacks to infostealer logs in Hudson Rock’s database, documents HellCat’s repeated use of this playbook, and recommends detection and mitigation steps such as EDR monitoring, immediate credential resets, MFA for Jira, network segmentation, and employee training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
