Security shop pwns ransomware gang, passes insider info to authorities
ID: 80781ef8-dd3c-5fc4-9b97-05ee3e7c0ada
STIX ID: report--80781ef8-dd3c-5fc4-9b97-05ee3e7c0ada
Feed Name: The Register (Security)
Resecurity discovered and exploited an LFI misconfiguration in the BlackLock ransomware gang’s TOR-based data leak site, recovering server configs, credentials and operator command histories. Using that access they cracked hashes, tracked operator activity, alerted CERT-FR and Canadian authorities to imminent leaks for several victims, and linked BlackLock to other ransomware brands (El Dorado, Mamona, DragonForce) while documenting TTPs such as use of Mega and rclone for exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
