MSP cybersecurity news digest, March 31, 2025
ID: a5ab86a6-914c-51ae-83af-38161f451e3d
STIX ID: report--a5ab86a6-914c-51ae-83af-38161f451e3d
Feed Name: TRU Security by Acronis
Researchers reported multiple active threats: RedCurl (aka Earth Kapre/Red Wolf) has for the first time deployed QWCrypt ransomware via spear-phishing and ISO/PDF sideloading, capable of encrypting VMs; RansomHub’s EDRKillShifter (an EDR bypass tool exploiting vulnerable drivers) links attacks across several ransomware groups and demonstrates the growing BYOVD trend; Chinese actor FamousSparrow used SparrowDoor and ShadowPad against U.S. and Mexican targets via web shell implants; additionally, the FBI warned about fake online file converters that deliver malware/ransomware, and phishing campaigns (fake Semrush and DeepSeek ads) are stealing Google credentials and distributing infostealers like Heracles.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
