Ransomware Roundup: 08.14.23
ID: 59f5ffad-2edf-517a-a1bd-f2634e9a5a76
STIX ID: report--59f5ffad-2edf-517a-a1bd-f2634e9a5a76
Feed Name: Halcyon Blog
Halcyon Research reveals that ostensibly legitimate ISPs acting as Command‑and‑Control Providers (C2Ps) — exemplified by Cloudzy — are being used to provision infrastructure for nation‑state APTs and ransomware affiliates; researchers identified affiliates (Ghost Clown, Space Kook) deploying BlackBasta and Royal, demonstrated a method to detect C2Ps and provide IOCs, warned about Linux ransomware (Abyss Locker) targeting VMware ESXi, and documented real‑world healthcare disruptions tied to ransomware activity while providing defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
