logo

Jordanian initial access broker pleads guilty to helping target 50 companies

ID: c25dab07-6f83-5a2d-88ee-cf02f9fe40fd

STIX ID: report--c25dab07-6f83-5a2d-88ee-cf02f9fe40fd

Feed Name: The Record from Recorded Future News

Threat Score
75/100

Date Published: 2026-01-16

Date Updated: 2026-05-01

...
...

A Jordanian individual operating as “r1z” pleaded guilty to selling access to the networks of at least 50 companies and distributing powerful malware able to disable multiple EDR products; law enforcement linked the actor’s IP to a June 2023 ransomware attack causing roughly $50M in damage, and the account had previously advertised exploits (including Confluence RCE) and illicit Cobalt Strike builds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.