logo

Phobos Ransomware Aggressively Targeting U.S. Critical Infrastructure

ID: 73811ba1-16d2-573a-be67-552f325e8140

STIX ID: report--73811ba1-16d2-573a-be67-552f325e8140

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2024-03-04

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

U.S. agencies (CISA, FBI, MS-ISAC) warned of ongoing Phobos ransomware campaigns operating as RaaS that target government, critical infrastructure, and public-sector organizations; the report outlines initial access via phishing and exposed RDP, post-compromise tools and techniques (process injection, token theft, SeDebugPrivilege), use of BloodHound/SharpHound for AD discovery, exfiltration via WinSCP/Mega, and destruction of shadow copies—additionally noting opportunistic exploitation of CVE-2023-38035 by other ransomware actors and rising ransom demand trends.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.