logo

CosmicBeetle steps up: Probation period at RansomHub

ID: 683c2570-fe60-52d4-8115-d8537a7100ce

STIX ID: report--683c2570-fe60-52d4-8115-d8537a7100ce

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
75/100

Date Published: 2024-09-10

Date Updated: 2026-05-01

...
...

ESET documents CosmicBeetle's ongoing activity deploying ScRansom against SMBs across Europe and Asia, describing its transition from Scarab to ScRansom, use of Delphi-based custom tooling (Spacecolon), experiments with a leaked LockBit builder and impersonation of LockBit, and a possible recent affiliation with RansomHub; the report provides a technical breakdown of ScRansom's partially destructive encryption and fragile decryption process, victimology, IoCs (file hashes, domains, emails, Tox IDs), and mapped MITRE ATT&CK techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.