Cisco: BlackByte ransomware gang only posting 20% to 30% of successful attacks
ID: e3371b57-f775-5553-a429-a51e890de5d8
STIX ID: report--e3371b57-f775-5553-a429-a51e890de5d8
Feed Name: The Record from Recorded Future News
BlackByte, an apparent offshoot of Conti operating as ransomware-as-a-service, remains highly active and has quickly incorporated newly disclosed vulnerabilities—most notably CVE-2024-37085 against VMware ESXi—into attacks against high-value targets such as local governments and major organizations; researchers note the group only publishes a small fraction of successful intrusions on its leak site, and its focus on ESXi and public-facing vulnerabilities increases the potential impact to enterprise infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
