RansomHouse RaaS Service Upgraded with Double Extortion Strategy that Steals and Encrypt Data
ID: e8bbea13-c561-5f3d-af85-d7e0d1d60c27
STIX ID: report--e8bbea13-c561-5f3d-af85-d7e0d1d60c27
Feed Name: cybersecurityNews.com
RansomHouse (Jolly Scorpius) is a ransomware-as-a-service operation that combines data theft and encryption to extort victims; it uses MrAgent for deployment and the Mario encryptor which employs two-stage, sparse chunked encryption and targets VMware ESXi hypervisors to encrypt large numbers of virtual machines. The campaign has affected at least 123 organizations across critical sectors (healthcare, finance, transportation, government) since December 2021, demonstrating high sophistication and significant operational impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
