logo

Interview #8 Benzona

ID: 0787c906-3052-516d-a9e9-ab846c08c92e

STIX ID: report--0787c906-3052-516d-a9e9-ab846c08c92e

Feed Name: deepdarkCTI

Threat Score
75/100

Date Published: 2025-12-23

Date Updated: 2026-05-12

Author: Erez

...
...

Interview with the Benzona ransomware group describing an active double‑extortion operation that encrypts files with a ".benzona" extension, leaves a "RECOVERY_INFO.txt" ransom note with a 72‑hour deadline, exfiltrates roughly ~1 TB of prioritized documents to a public leak site (8 victims declared, four in Romania), avoids targeting healthcare/life‑support, uses phishing/exploits/compromised credentials for access, and plans to roll out a vetted Ransomware‑as‑a‑Service program.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.