Introducing ToyMaker, an initial access broker working in cahoots with double extortion gangs
ID: d811a2ce-cc39-5d64-804d-f090b115fbc2
STIX ID: report--d811a2ce-cc39-5d64-804d-f090b115fbc2
Feed Name: Cisco Talos
Cisco Talos details an intrusion where an initial access broker called ToyMaker exploited internet-facing vulnerabilities to deploy the LAGTOY backdoor, capture credentials via Magnet RAM Capture, and subsequently hand access to the Cactus ransomware group, which performed network discovery, data collection/exfiltration, deployed remote admin tools and prepared for double-extortion ransomware; the report includes LAGTOY behavioral analysis, timelines, TTP mappings and IOCs (hashes and IPs).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
