RANSOMWARE · Unknown
Group exploiting zero-day vulnerabilities in file transfer appliances to exfiltrate data before deploying ransomware.
Aliases: TA505, FIN11
Motivation: Financial extortion and data theft
Lateral Movement
Field telemetry from São Paulo correlates with Lazarus Fake Job Offer Campaign Targets Crypto Engineers.
Data Exfiltration
Field telemetry from Kyiv correlates with BlackCat Resurfaces with New Leak Site Infrastructure.
Privilege Escalation
Field telemetry from Tehran correlates with Manufacturing Giant Hit by Supply Chain Ransomware.
Data Exfiltration
Field telemetry from São Paulo correlates with Lazarus Fake Job Offer Campaign Targets Crypto Engineers.
Ransom Demand
Field telemetry from Kyiv correlates with BlackCat Resurfaces with New Leak Site Infrastructure.
Lateral Movement
Field telemetry from Tehran correlates with Manufacturing Giant Hit by Supply Chain Ransomware.
Resolution
Field telemetry from Kyiv correlates with BlackCat Resurfaces with New Leak Site Infrastructure.
Data Exfiltration
Field telemetry from Tehran correlates with Manufacturing Giant Hit by Supply Chain Ransomware.
Ransom Demand
Field telemetry from São Paulo correlates with Lazarus Fake Job Offer Campaign Targets Crypto Engineers.