Threat Actors Attacking Systems with 240+ Exploits Before Ransomware Deployment
ID: ae1d344d-8b6b-5b75-b4ef-c0044547a0b1
STIX ID: report--ae1d344d-8b6b-5b75-b4ef-c0044547a0b1
Feed Name: cybersecurityNews.com
Threat Score
Between December 25–28 a single operator conducted an industrial-scale reconnaissance campaign—using Nuclei-like tooling and Interactsh OAST infrastructure—to test over 240 exploits across internet-facing systems, collect confirmed vulnerable targets, and profile them for sale to ransomware groups; detections tie activity to two CTG Server Limited IPs (134.122.136.119, 134.122.136.96) and many OAST domains, indicating high likelihood of follow-on intrusions in 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
