logo

Amateurish 'CosmicBeetle' Ransomware Stings SMBs in Turkey

ID: 24fffa46-538b-5b29-9898-a746f1cf22a8

STIX ID: report--24fffa46-538b-5b29-9898-a746f1cf22a8

Feed Name: Dark Reading

Threat Score
68/100

Date Published: 2024-09-12

Date Updated: 2026-04-21

Author: Robert Lemos, Contributing Writer

...
...

ESET analysis describes CosmicBeetle, a likely Turkey-based ransomware actor targeting SMBs by exploiting older, unpatched vulnerabilities (including Veeam CVE-2023-27532 and AD CVE-2021-42278/42287) across Turkey, Spain, India, South Africa and other countries; the group uses custom ScRansom (under active development) and RansomHub affiliates, demonstrates operational immaturity that sometimes causes faulty encryption/decryption, and opportunistically targets businesses with weak patch management.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.