logo

Halcyon Threat Insights 008: August 2024 Ransomware Report

ID: 3f02cd19-116b-5872-b224-9ddfa5dd1ce0

STIX ID: report--3f02cd19-116b-5872-b224-9ddfa5dd1ce0

Feed Name: Halcyon Blog

Threat Score
75/100

Date Published: 2026-03-02

Date Updated: 2026-04-28

...
...

**Executive Summary:** Halcyon's August 2024 report highlights a persistent and active ransomware ecosystem with 470 alleged leak-site postings (396 confirmed), top-targeted industries including Information & Technology, Education, and Finance, numerous precursor trojans (e.g., Formbook, Cosmu/Xpiro, Hesperbot), multiple active ransomware families (LockBit/BlackMatter, Black Basta, Phobos/Crysis, Maze/RanPack, DarkRace/IMPS), and emerging groups (Mad Liberator, Ransomcortex, VanirGroup) employing TTPs like AnyDesk misuse, RDP abuse, lateral discovery tools, exploitation of known vulnerabilities, data exfiltration, and double-extortion tactics.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.