Ransomware Roundup: 07.08.22
ID: 30c03f97-706e-5299-b023-a49ced869272
STIX ID: report--30c03f97-706e-5299-b023-a49ced869272
Feed Name: Halcyon Blog
This weekly ransomware roundup highlights multiple active threats and trends: AstraLocker operators say they are leaving ransomware (while recent AstraLocker variants were delivering payloads directly via malicious Office documents), U.S. agencies warn Maui ransomware activity linked to North Korean state-sponsored actors targeting healthcare, attackers are shifting from Cobalt Strike to Brute Ratel for post-exploitation evasion, and Hive ransomware has been reimplemented in Rust—collectively underscoring ongoing active ransomware campaigns, improved evasion techniques, and evolving attacker monetization.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
