Ransomware Threats To Vulnerable Industrial Control Systems
ID: 6169810f-f8a2-5566-ac67-f95b191b26af
STIX ID: report--6169810f-f8a2-5566-ac67-f95b191b26af
Feed Name: Cyble Blog
Ransomhub, a Ransomware-as-a-Service operation active since February 2024, claims to have accessed and maintained persistence on the SCADA systems of the Matadero de Gijón bio-energy plant, posting screenshots of digestor and heating controls and alleging encryption and exfiltration of hundreds of gigabytes; Cyble attributes the group's access to purchases from initial access brokers, notes its recruitment activity, and warns that internet-exposed ICS/OT assets (particularly those accessible via VNC) are at heightened risk, providing network segmentation, patching, remote-access hardening, logging, asset visibility, and incident-response recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
