logo

Halcyon Threat Insights 005: May 2024 Ransomware Report

ID: 34a5e53b-584d-5421-8471-914e952b1e69

STIX ID: report--34a5e53b-584d-5421-8471-914e952b1e69

Feed Name: Halcyon Blog

Threat Score
80/100

Date Published: 2026-03-02

Date Updated: 2026-04-28

...
...

Halcyon’s May 2024 intelligence brief describes an active and evolving ransomware landscape: Information Technology, Education, and Finance were the most targeted sectors while a range of trojans (dropper/infostealer families) frequently serve as precursors to ransomware deployment. The report profiles multiple active ransomware families (Phobos, LockBit, BlackBasta, Akira, BlackSuit), highlights common vectors and TTPs such as compromised RDP, exploitation of ESXi and Citrix, use of Cobalt Strike/SmokeLoader, RaaS models, and double extortion tactics, and spotlights the INC Ransom group’s behaviors and tooling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.