Amateurish 'CosmicBeetle' Ransomware Stings SMBs in Turkey
ID: 24fffa46-538b-5b29-9898-a746f1cf22a8
STIX ID: report--24fffa46-538b-5b29-9898-a746f1cf22a8
Feed Name: Dark Reading
ESET analysis describes CosmicBeetle, a likely Turkey-based ransomware actor targeting SMBs by exploiting older, unpatched vulnerabilities (including Veeam CVE-2023-27532 and AD CVE-2021-42278/42287) across Turkey, Spain, India, South Africa and other countries; the group uses custom ScRansom (under active development) and RansomHub affiliates, demonstrates operational immaturity that sometimes causes faulty encryption/decryption, and opportunistically targets businesses with weak patch management.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
