Emerging Threat Actor: Arcus Media Ransomware
ID: 8897e82d-5ab7-5618-9dd2-67fc7c2ca096
STIX ID: report--8897e82d-5ab7-5618-9dd2-67fc7c2ca096
Feed Name: Halcyon Blog
Arcus Media is a rapidly emerging ransomware-as-a-service (RaaS) operation (launched May 2024) that uses custom-built ransomware and a closed, vetted affiliate model; it has been linked to dozens of high-impact incidents worldwide and employs double-extortion by exfiltrating data before selective AES encryption with RSA key exchange. The group leverages phishing and brokered credentials for initial access, uses tools like Mimikatz and process injection to evade defenses, sabotages recovery (shadow copy deletion, registry and scheduled task persistence), and targets a broad range of industries while tailoring ransom demands to victims.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
