Attack trend alert: REvil ransomware
ID: 3a211baa-fa7c-543b-b2df-fe934143029a
STIX ID: report--3a211baa-fa7c-543b-b2df-fe934143029a
Feed Name: Expel Blog
This Expel report describes an active REvil (SODINOKIBI) RaaS campaign observed targeting law firms in Germany and the United States, where attackers boosted malicious pages in Google search results to trick users into downloading ZIPs with JScript that stages a Cobalt Strike BEACON and leads to privilege escalation, lateral movement, and ransomware deployment. The post includes actionable detection rules (e.g., wscript/cscript executing scripts from user profiles, PowerShell base64 with external connections), containment and remediation steps (isolate hosts, re-image, timeline via C2/network traffic), and hardening advice (associate WSH files with Notepad, enable PowerShell Constrained Language, avoid exposing RDP, and maintain offline backups).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
