logo

The Week in Ransomware - May 17th 2024 - Mailbombing is back

ID: 4ffb3e9d-8530-59f3-9591-896d16edd138

STIX ID: report--4ffb3e9d-8530-59f3-9591-896d16edd138

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-05-17

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

This weekly intelligence summary reports active ransomware and cybercrime activity: CISA/FBI attribution that Black Basta affiliates breached over 500 organizations, large-scale phishing via the Phorpiex botnet enabling LockBit Black attacks, attempts to sell INC Ransom source code, and multiple operational impacts including MediSecure and Firstmac data incidents. The report also documents new STOP ransomware variants (several file extensions and ransom notes), observed TTPs such as MS‑SQL brute-force, PureCrypter delivery, and social engineering exploiting Windows Quick Assist, plus industry guidance from NCSC and insurers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.