Ransomware Roundup: 09.11.23
ID: a875b852-57c1-5185-9111-acfb4e4496b0
STIX ID: report--a875b852-57c1-5185-9111-acfb4e4496b0
Feed Name: Halcyon Blog
Ransomware activity spiked against the education sector and other critical infrastructure in August, with attackers using MSSQL brute-force access to deploy Cobalt Strike, RATs and a Mimic/FreeWorld ransomware variant, establishing SMB shares and employing tools like AnyDesk, Mimikatz and network scanners; the report also highlights US/UK sanctions against Conti-Trickbot members and the resurgence of Monti with a Linux variant based on leaked Conti code, signaling growing sophistication and nation-state overlap.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
