Last Year in Ransomware: Top Ransomware Groups and Emerging Threat Actors
ID: 1e6bf171-bb95-5c0d-bdb7-95209f875ad8
STIX ID: report--1e6bf171-bb95-5c0d-bdb7-95209f875ad8
Feed Name: Halcyon Blog
This report surveys the 2024 ransomware landscape, profiling dominant and emerging RaaS and data-broker groups (RansomHub, Play, Akira, BlackBasta, Volcano Demon, and others), their advanced TTPs (double extortion, EDR evasion, ChaCha20/AES/Curve25519 encryption, intermittent encryption, Linux/ESXi targeting), exploited vulnerabilities (Fortinet SSL-VPN CVE-2023-27997, ConnectWise CVE-2024-1709, Microsoft Exchange flaws), targeted sectors (healthcare, government, finance, manufacturing), and operational scale including large ransom demands, affiliate economics, and instances of APT collaboration that increase overall risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
