Ransomware Roundup: 05.15.23
ID: b08c98e4-edf2-5f7c-a1ba-9dbe5150da70
STIX ID: report--b08c98e4-edf2-5f7c-a1ba-9dbe5150da70
Feed Name: Halcyon Blog
This briefing details several active ransomware operations: Royal's claimed attack on the City of Dallas that disrupted 911 and other critical services; Akira's emergent extortion-focused ransomware that exfiltrates data and provides victims a negotiation/chat portal; and Cactus, which gains persistence via exploited VPN appliances and SSH backdoors. The report emphasizes common TTPs (VPN/RDP abuse, exploitation of unpatched vulnerabilities, data exfiltration before encryption), rising sophistication of ransomware actors, impacts to critical infrastructure, and recommends preparedness, resilience planning, tabletop exercises, and improved communications while noting policy discussions about banning ransom payments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
