logo

Ransomware Roundup: 05.01.23

ID: 306f83d4-fa77-5d62-8ee9-65f67bc2d800

STIX ID: report--306f83d4-fa77-5d62-8ee9-65f67bc2d800

Feed Name: Halcyon Blog

Threat Score
78/100

Date Published: 2023-05-01

Date Updated: 2026-04-28

...
...

This report catalogs recent ransomware activity and trends: researchers identified a macOS-capable LockBit sample, Vice Society and Play are using custom PowerShell and VSS/Grixba tools to automate data exfiltration, Cl0p executed a large automated exploitation campaign against known GoAnywhere vulnerabilities, and attackers are using BYOVD tools like AuKill/Backstab to disable EDRs. The document emphasizes a shift to data-exfiltration-first operations, growing automation and scale, widespread exploitation of known vulnerabilities, and the resulting high financial and operational impact on victims.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.