Ransomware Roundup 02.13.23
ID: dbc61b00-141e-550a-88e8-b6b6e88245ee
STIX ID: report--dbc61b00-141e-550a-88e8-b6b6e88245ee
Feed Name: Halcyon Blog
The report describes a recent surge of ransomware activity: an updated ESXiArgs variant is actively encrypting VMware ESXi servers (including flat files), defeating a previously released CISA recovery script and exploiting a long-patched ESXi vulnerability; a Cl0p Linux ransomware variant was identified (noted as buggy but potentially dangerous as it matures); and BlackCat/ALPHV posted alleged Five Guys data as part of a double-extortion scheme—underscoring patching challenges, high impact of ransomware on infrastructure, and growing risks from Linux-targeted attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
