logo

Report: Ransomware Command-and-Control Providers Unmasked by Halcyon Researchers

ID: ae5bc8e8-a7d5-567d-80a9-57ae045b05e0

STIX ID: report--ae5bc8e8-a7d5-567d-80a9-57ae045b05e0

Feed Name: Halcyon Blog

Threat Score
80/100

Date Published: 2026-03-02

Date Updated: 2026-04-28

...
...

Halcyon Research details novel methods to identify Command-and-Control Providers (C2Ps) and presents evidence that Cloudzy is widely used to host RDP/VPS infrastructure for both nation-state APT operations and criminal ransomware affiliates; the report names two new affiliates (Ghost Clown and Space Kook tied to BlackBasta and Royal), lists IoCs (SHA256 hashes, IPs, domains, and netblocks), and urges defenders to search for identified RDP hostnames and indicators to detect or prevent imminent ransomware activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.