Ransomware Roundup: 05.01.23
ID: 306f83d4-fa77-5d62-8ee9-65f67bc2d800
STIX ID: report--306f83d4-fa77-5d62-8ee9-65f67bc2d800
Feed Name: Halcyon Blog
This report catalogs recent ransomware activity and trends: researchers identified a macOS-capable LockBit sample, Vice Society and Play are using custom PowerShell and VSS/Grixba tools to automate data exfiltration, Cl0p executed a large automated exploitation campaign against known GoAnywhere vulnerabilities, and attackers are using BYOVD tools like AuKill/Backstab to disable EDRs. The document emphasizes a shift to data-exfiltration-first operations, growing automation and scale, widespread exploitation of known vulnerabilities, and the resulting high financial and operational impact on victims.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
