logo

Cloud Ransomware Flexes Fresh Scripts Against Web Apps

ID: 5d475053-bff4-5e31-8420-1b740d011051

STIX ID: report--5d475053-bff4-5e31-8420-1b740d011051

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-11-14

Date Updated: 2026-04-21

Author: Becky Bracken, Senior Editor, Dark Reading

...
...

SentinelOne's analysis shows a shift in cloud ransomware toward exploiting unprotected web applications—especially PHP apps—to drop encryptors (examples include the Pandora Python script and an IndoSec PHP-based encryptor) and a trend of using legitimate cloud-native services (S3, Azure Storage Explorer) for data exfiltration; the report highlights discovered scripts (including RansomES) and recommends enforcing service control policies, strong identity management (MFA), and runtime protection for cloud workloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.