CosmicBeetle steps up: Probation period at RansomHub
ID: 683c2570-fe60-52d4-8115-d8537a7100ce
STIX ID: report--683c2570-fe60-52d4-8115-d8537a7100ce
Feed Name: WeLiveSecurity (ESET Research)
ESET documents CosmicBeetle's ongoing activity deploying ScRansom against SMBs across Europe and Asia, describing its transition from Scarab to ScRansom, use of Delphi-based custom tooling (Spacecolon), experiments with a leaked LockBit builder and impersonation of LockBit, and a possible recent affiliation with RansomHub; the report provides a technical breakdown of ScRansom's partially destructive encryption and fragile decryption process, victimology, IoCs (file hashes, domains, emails, Tox IDs), and mapped MITRE ATT&CK techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
