Critical Advisory On RansomHub Ransomware
ID: debfb027-0ca4-5192-a80d-e6f902d35339
STIX ID: report--debfb027-0ca4-5192-a80d-e6f902d35339
Feed Name: Cyble Blog
Threat Score
The advisory summarizes RansomHub (aka Cyclops/Knight), a fast-emerging double‑extortion ransomware active since February 2024 that targets a wide range of sectors including critical infrastructure; it documents initial access methods (phishing, CVE exploitation, password spraying), internal reconnaissance and lateral movement tools, exfiltration techniques (cloud storage, HTTP POST), encryption details, IOCs, and recommended mitigations endorsed by FBI/CISA/MS‑ISAC/HHS.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
