logo

Ransomware Roundup: 09.11.23

ID: a875b852-57c1-5185-9111-acfb4e4496b0

STIX ID: report--a875b852-57c1-5185-9111-acfb4e4496b0

Feed Name: Halcyon Blog

Threat Score
75/100

Date Published: 2023-09-11

Date Updated: 2026-04-28

...
...

Ransomware activity spiked against the education sector and other critical infrastructure in August, with attackers using MSSQL brute-force access to deploy Cobalt Strike, RATs and a Mimic/FreeWorld ransomware variant, establishing SMB shares and employing tools like AnyDesk, Mimikatz and network scanners; the report also highlights US/UK sanctions against Conti-Trickbot members and the resurgence of Monti with a Linux variant based on leaked Conti code, signaling growing sophistication and nation-state overlap.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.