Albabat, Kasseika, Kuiper: New Ransomware Gangs Rise with Rust and Golang
ID: e1cbad4a-e903-5595-af31-124798232a56
STIX ID: report--e1cbad4a-e903-5595-af31-124798232a56
Feed Name: The Hacker News
Threat Score
Fortinet FortiGuard Labs identified a new Phobos ransomware variant named "Faust" delivered via a malicious XLAM Excel add-in that downloads Base64-encoded payloads from Gitea, drops a faux "AVG updater.exe" downloader, and executes fileless shellcode to perform file encryption; the report also surveys related ransomware families, common TTPs (including TeamViewer and LockBit builder abuse), and declining victim ransom-payment rates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
