Ransomware gang uses ISPsystem VMs for stealthy payload delivery
ID: fe326906-5bb1-522f-9216-05db89d65661
STIX ID: report--fe326906-5bb1-522f-9216-05db89d65661
Feed Name: Bleeping Computer
Sophos researchers found that threat actors (including LockBit, Qilin, Conti, BlackCat/ALPHV, Ursnif, and operators of RedLine and Lummar) are exploiting ISPsystem VMmanager's default Windows VM templates—which reuse identical hostnames and system identifiers—to spin up VMs for C2 and delivery of ransomware and info-stealer payloads; the technique hides malicious systems among legitimate infrastructure and is concentrated in a small set of hosting providers that enable large-scale abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
