New Ransomware Groups On The Rise: Key Trends And Threats
ID: 6df47842-68cd-5960-b48c-bf641825121b
STIX ID: report--6df47842-68cd-5960-b48c-bf641825121b
Feed Name: Cyble Blog
**Executive Summary:** This report profiles recent ransomware activity from RedAlert, 0mega, and Lilith, detailing Lilith's static and dynamic behavior (process/service termination, drive enumeration, exclusion lists, CryptGenRandom-based encryption, .lilith extension, and ransom note/drop behavior), describes RedAlert's ESXi-focused operations and Monero payments, notes 0mega's observed file extension and note name, provides IOCs (hashes), MITRE ATT&CK mappings, leak-site screenshots, and recommended defensive measures such as offline backups and endpoint protection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
