NoName ransomware gang deploying RansomHub malware in recent attacks
ID: b2a04210-a123-5967-850a-39eb6815b8bf
STIX ID: report--b2a04210-a123-5967-850a-39eb6815b8bf
Feed Name: Bleeping Computer
NoName (tracked as CosmicBeetle) is an active ransomware group targeting small and medium businesses using the ScRansom/Spacecolon family and a combination of brute-force access and exploitation of SMB-related CVEs (e.g., CVE-2017-0144, CVE-2020-1472). ESET and other researchers observed ScRansom's partial-encryption and irreversible 'ERASE' modes, a complex AES-CTR/RSA key exchange that can cause decryption failures, attempts to impersonate LockBit via cloned leak sites, and deployment of RansomHub's EDR-killer—leading researchers to assess a likely RansomHub affiliate relationship.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
