Last Year in Ransomware: Major Developments, Targeted Industries, Linux Variants
ID: fb1a98dc-8b55-574e-8e0e-9edff76ff312
STIX ID: report--fb1a98dc-8b55-574e-8e0e-9edff76ff312
Feed Name: Halcyon Blog
The report reviews 2024 ransomware developments: major law-enforcement disruptions of BlackCat/ALPHV and LockBit (Operation Cronos) provided decryption keys and operational intelligence, but a new RaaS group, RansomHub, rapidly filled the void and became highly active; concurrently Linux-targeted ransomware variants (ESXi-focused strains, Mallox Linux, Helldown) expanded the attack surface. It highlights industry impacts (notably healthcare, manufacturing, construction), attack methods (phishing, vuln exploitation, credential theft, network mapping), published IoCs and advisories, and emphasizes that while takedowns demonstrated international cooperation success, persistent and evolving threats require continued vigilance and cross-sector defensive improvements.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
