Triplestrength hits victims with triple trouble: Ransomware, cloud hijacks, crypto-mining
ID: 49444b01-b5e2-5cfa-9cd3-8485f5c96419
STIX ID: report--49444b01-b5e2-5cfa-9cd3-8485f5c96419
Feed Name: The Register (Security)
Triplestrength is a financially motivated criminal group tracked by Google Threat Intelligence that combines old-school ransomware attacks on on-premises Windows systems (using Phobos, LokiLocker, RCRU64) with hijacking cloud accounts to run cryptocurrency miners. The actors rely on brute-force access to exposed RDP, commodity post-exploitation tools (Mimikatz, NetScan), and Raccoon infostealer to harvest cloud credentials, targeting multiple cloud providers and producing hundreds of observed mining payments and potentially significant cloud-cost impacts to victims.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
