Cyber Toufan goes Oprah mode, with free Linux system wipes of over 100 organisations
ID: ccaa1052-69b4-5b6e-ad53-c09df4496324
STIX ID: report--ccaa1052-69b4-5b6e-ad53-c09df4496324
Feed Name: DoublePulsar
This report documents an ongoing destructive campaign attributed to "Cyber Toufan" that has compromised and wiped servers for over 100 organizations (including Radware, MAX Security, PTS Tools / Berkshire eSupply, IKEA Israel, Toyota Israel, and Israeli government entities), exfiltrated customer data which has been published on Telegram, and abused victims' SMTP systems to send threatening emails to customers; the author provides timeline updates and actionable mitigations (Linux/EDR monitoring, outbound network controls, TLS certificate invalidation, and MSP risk management).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
