Ransomware Groups, Targeting Preferences, and the Access Economy
ID: a5d63b66-92e4-5c78-8188-937bee13cb30
STIX ID: report--a5d63b66-92e4-5c78-8188-937bee13cb30
Feed Name: Bleeping Computer
This report outlines the ransomware ecosystem’s supply chain, highlighting how infostealer-derived “stealer logs” sold on Telegram and the dark web feed initial access brokers, who in turn provide enterprise access to ransomware groups and affiliates. It explains the operational roles and incentives across this ecosystem, including session cookie abuse, the auction of corporate access on major forums (Exploit, XSS, RAMP), and competition among ransomware groups for top affiliates, while promoting Flare’s CTEM solution for detecting and mitigating these exposures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
