logo

Mad Liberator extortion crew emerges on the cyber-crook scene

ID: baa6da9b-039e-5014-aad7-be15fc6cac5d

STIX ID: report--baa6da9b-039e-5014-aad7-be15fc6cac5d

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-08-15

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Sophos X-Ops identified a new extortion group, Mad Liberator, which uses social engineering and the remote-access tool AnyDesk to obtain interactive access to victims' machines, deploy a fake "Microsoft Windows Update" binary (SHA256 provided), exfiltrate files via AnyDesk and mapped shares, and threaten disclosure via a leak site — employing double-extortion tactics though widespread file encryption was not confirmed in the observed cases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.