Ransomware Roundup: 03.13.23
ID: 016a8b86-6440-5685-a6a9-121f76a15c62
STIX ID: report--016a8b86-6440-5685-a6a9-121f76a15c62
Feed Name: Halcyon Blog
Executive summary: This report summarizes recent, active ransomware and extortion activity affecting critical infrastructure, notably healthcare and education, including a CISA/FBI advisory on Royal ransomware, arrests connected to DoppelPaymer, BlackCat/ALPHV leaking sensitive patient images, a RansomHouse attack on a Barcelona hospital, IceFire's Linux ransomware exploiting CVE-2022-47986, and Medusa's exfiltration of Minneapolis Public Schools data; it highlights operational impact, evolving TTPs (anti-analysis, Linux targeting, data exfiltration), and recommended prevention/resilience controls (EPP, patching, backups, segmentation, awareness, and testing).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
