Tracking Adversaries: EvilCorp, the RansomHub affiliate
ID: 487e08cb-dabe-59c0-88d8-8b855276eaf8
STIX ID: report--487e08cb-dabe-59c0-88d8-8b855276eaf8
Feed Name: BushidoToken Blog
Threat Score
This CTI blog links the sanctioned Russia-based cybercriminal EvilCorp with the RansomHub ransomware-as-a-service operation, documenting that SocGholish (FakeUpdates) infections frequently lead to deployment of a custom Python backdoor (VIPERTUNNEL) and ultimately RansomHub ransomware; it synthesizes reporting from Microsoft, Google, Guidepoint, and Trend Micro and highlights operational, legal (sanctions) and response implications for victims and defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
