Ransomware Roundup: 04.17.23
ID: 2b743013-8cb1-5bdb-b2f8-9e219027c2f9
STIX ID: report--2b743013-8cb1-5bdb-b2f8-9e219027c2f9
Feed Name: Halcyon Blog
The report synthesizes recent ransomware and extortion activity, highlighting how nation-state actors and criminal gangs blur lines by using ransomware and destructive wipers as cover for espionage and disruption (e.g., MuddyWater, NoName). It details active incidents and trends — customer data exfiltration at Yum! Brands, MSI source-code leaks, a Windows CLFS privilege-escalation zero-day (CVE-2023-28252) exploited by Nokoyawa, and the emergence of fast, evasive strains like Rorschach — and recommends shifting defenses to detect long, multi-stage data-exfiltration operations earlier in the kill chain.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
