The Week in Ransomware - May 17th 2024 - Mailbombing is back
ID: 4ffb3e9d-8530-59f3-9591-896d16edd138
STIX ID: report--4ffb3e9d-8530-59f3-9591-896d16edd138
Feed Name: Bleeping Computer
This weekly intelligence summary reports active ransomware and cybercrime activity: CISA/FBI attribution that Black Basta affiliates breached over 500 organizations, large-scale phishing via the Phorpiex botnet enabling LockBit Black attacks, attempts to sell INC Ransom source code, and multiple operational impacts including MediSecure and Firstmac data incidents. The report also documents new STOP ransomware variants (several file extensions and ransom notes), observed TTPs such as MS‑SQL brute-force, PureCrypter delivery, and social engineering exploiting Windows Quick Assist, plus industry guidance from NCSC and insurers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
