OmniVision disclosed a data breach after the 2023 Cactus ransomware attack
ID: 0057494a-1375-58a8-83c3-338242c13dd7
STIX ID: report--0057494a-1375-58a8-83c3-338242c13dd7
Feed Name: Security Affairs
OmniVision disclosed a data breach following a September 2023 intrusion by the Cactus ransomware group that encrypted systems and exfiltrated personal and corporate documents (including passport images, NDAs, and contracts); the extortion gang published proof and ultimately released the stolen data. The report details the group's TTPs—use of legitimate remote access tools (Splashtop, AnyDesk, SuperOps RMM), Cobalt Strike, Chisel, PowerShell-based discovery and deployment scripts, antivirus removal via batch scripts, and Rclone for exfiltration—and notes mitigation steps taken by OmniVision (increased monitoring, cloud migrations, policy updates, and credit monitoring for affected individuals).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
