Unleashing the Kraken ransomware group
ID: 24d5608c-f09e-513c-bf60-8b94cb92c1b4
STIX ID: report--24d5608c-f09e-513c-bf60-8b94cb92c1b4
Feed Name: Cisco Talos
Cisco Talos details Kraken, a Russian-speaking cross-platform ransomware group active since early 2025 that conducts big-game hunting and double-extortion attacks: Talos observed SMB exploitation for initial access, credential theft and RDP reuse for lateral movement, Cloudflared tunnels for persistence, SSHFS for exfiltration, distinct Windows/Linux/ESXi encryptors that use ChaCha20 with RSA-4096, encryption benchmarking and anti-analysis techniques, a public data-leak site and new underground forum, and provides IOCs and defensive coverage recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
