Remote Encryption Attacks Surge: How One Vulnerable Device Can Spell Disaster
ID: 0bfe4876-c780-579d-a2f7-da043da3fd08
STIX ID: report--0bfe4876-c780-579d-a2f7-da043da3fd08
Feed Name: The Hacker News
Ransomware actors are increasingly using remote encryption—leveraging compromised unmanaged endpoints to encrypt devices across a network—to minimize footprint and evade process-based detection. Microsoft and Sophos data indicate this technique now appears in a majority of ransomware attacks, with families such as Akira, ALPHV/BlackCat, BlackMatter, LockBit, and Royal using it; adversaries are also professionalizing operations, expanding targets beyond Windows, timing attacks to avoid detection, and engaging with media to pressure victims.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
