Silent Ransom Group (SRG): Uncovering DNS Fast Flux Infrastructure
ID: 68128ecf-cc84-50ad-abcb-edbb4e0c35b5
STIX ID: report--68128ecf-cc84-50ad-abcb-edbb4e0c35b5
Feed Name: DataBreaches.Net
Resecurity's analysis and related reporting identify the 'Silent Ransom Group' (SRG) as an active extortion-focused criminal actor targeting U.S. law firms and other sectors. The group employs social engineering and in-person physical intrusions to steal data and publishes stolen data on Clearnet Data Leak Sites while hiding its infrastructure using DNS Fast Flux backed by a geographically distributed network of compromised IoT and CPE devices across Latin America, Eastern Europe, Central Asia, Middle East/Africa, East Asia and the Caribbean; law enforcement agencies (including the FBI) and multiple national cybersecurity organizations have issued advisories about the threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
