RANSOMWARE · Unknown
Group exploiting zero-day vulnerabilities in file transfer appliances to exfiltrate data before deploying ransomware.
Псевдонимы: TA505, FIN11
Мотивация: Financial extortion and data theft
Боковое перемещение
Field telemetry from São Paulo correlates with Lazarus Fake Job Offer Campaign Targets Crypto Engineers.
Эксфильтрация данных
Field telemetry from Kyiv correlates with BlackCat Resurfaces with New Leak Site Infrastructure.
Повышение привилегий
Field telemetry from Tehran correlates with Manufacturing Giant Hit by Supply Chain Ransomware.
Эксфильтрация данных
Field telemetry from São Paulo correlates with Lazarus Fake Job Offer Campaign Targets Crypto Engineers.
Требование выкупа
Field telemetry from Kyiv correlates with BlackCat Resurfaces with New Leak Site Infrastructure.
Боковое перемещение
Field telemetry from Tehran correlates with Manufacturing Giant Hit by Supply Chain Ransomware.
Ликвидация инцидента
Field telemetry from Kyiv correlates with BlackCat Resurfaces with New Leak Site Infrastructure.
Эксфильтрация данных
Field telemetry from Tehran correlates with Manufacturing Giant Hit by Supply Chain Ransomware.
Требование выкупа
Field telemetry from São Paulo correlates with Lazarus Fake Job Offer Campaign Targets Crypto Engineers.