Last Week in Ransomware: 09.16.2024
ID: cfc13a4f-71f2-536d-9290-9d545939dbc6
STIX ID: report--cfc13a4f-71f2-536d-9290-9d545939dbc6
Feed Name: Halcyon Blog
Executive summary: This report is a ransomware news roundup detailing Iranian-linked groups selling network access to ransomware affiliates, recent disruptive attacks against a UK school and a US health network (resulting in a $65M settlement), RansomHub’s new TTPs using TDSSKiller and LaZagne to disable EDR and steal credentials, and a Kransom strain employing DLL side-loading with a legitimate certificate — highlighting increased sophistication, cross-over between nation-state and criminal activity, and broad sectoral impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
