Phobos Ransomware Aggressively Targeting U.S. Critical Infrastructure
ID: 73811ba1-16d2-573a-be67-552f325e8140
STIX ID: report--73811ba1-16d2-573a-be67-552f325e8140
Feed Name: The Hacker News
U.S. agencies (CISA, FBI, MS-ISAC) warned of ongoing Phobos ransomware campaigns operating as RaaS that target government, critical infrastructure, and public-sector organizations; the report outlines initial access via phishing and exposed RDP, post-compromise tools and techniques (process injection, token theft, SeDebugPrivilege), use of BloodHound/SharpHound for AD discovery, exfiltration via WinSCP/Mega, and destruction of shadow copies—additionally noting opportunistic exploitation of CVE-2023-38035 by other ransomware actors and rising ransom demand trends.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
