RansomHub Actors Exploit ZeroLogon Vuln in Recent Ransomware Attacks
ID: ad232244-4f51-589e-9fa4-780edefea232
STIX ID: report--ad232244-4f51-589e-9fa4-780edefea232
Feed Name: Dark Reading
Threat Score
RansomHub is an emerging ransomware-as-a-service that has rapidly victimized dozens of organizations by exploiting the ZeroLogon (CVE-2020-1472) flaw and leveraging remote-access tools (Atera, Splashtop) and network scanners; its payload shows extensive code overlap with the older Knight ransomware, and the group is actively recruiting affiliates and expanding operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
