RansomHub Taps FakeUpdates to Target US Government Sector
ID: 26a5059c-364c-548d-a66f-182900291eef
STIX ID: report--26a5059c-364c-548d-a66f-182900291eef
Feed Name: Dark Reading
Date Published: 2025-03-17
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Trend Micro researchers describe a multi-stage campaign dubbed "Water Scylla" in which SocGholish/FakeUpdates malvertising and rogue Keitaro TDS instances deliver RansomHub ransomware to victims—primarily US government organizations, with impacts also in banking, consulting, Japan, and Taiwan. The activity leverages compromised legitimate websites, obfuscated JavaScript loaders, domain shadowing, and rotating C2 infrastructure to increase infection success; the report highlights active exploitation, actor collaboration (including RaaS affiliates and ties to Scattered Spider), and recommends XDR, endpoint hardening, web reputation services, and network detection controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
