Interview #8 Benzona
ID: 0787c906-3052-516d-a9e9-ab846c08c92e
STIX ID: report--0787c906-3052-516d-a9e9-ab846c08c92e
Feed Name: deepdarkCTI
Threat Score
Interview with the Benzona ransomware group describing an active double‑extortion operation that encrypts files with a ".benzona" extension, leaves a "RECOVERY_INFO.txt" ransom note with a 72‑hour deadline, exfiltrates roughly ~1 TB of prioritized documents to a public leak site (8 victims declared, four in Romania), avoids targeting healthcare/life‑support, uses phishing/exploits/compromised credentials for access, and plans to roll out a vetted Ransomware‑as‑a‑Service program.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
