Related Families: AsyncRAT
Verticals Targeted: Consumer Services
DcRAT Distributed Via Adult Content Themed Lures
Jun 26, 2023, 1:57:42 PM / by The Hivemind posted in Threat Bulletin, Ransomware, Infostealer, RAT, DcRAT, AsyncRAT
BlackSuit Ransomware
Jun 12, 2023, 2:55:54 PM / by The Hivemind posted in Ransomware, Windows, Linux, Royal, BlackSuit, encryption
Related Families: Royal
Executive Summary
BlackSuit ransomware targets both Windows and Linux systems and bears a striking resemblance to Royal ransomware.
BlackByte NT
May 30, 2023, 2:01:00 PM / by The Hivemind posted in BlackByte, Ransomware, BlackByte NT
Related Families: BlackByte
Executive Summary
BlackByte NT, the most recently discovered variant of BlackByte ransomware, was recently reported by DuskRise. BlackByte NT is written in C++ and contains a variety of anti-analysis techniques in an attempt to thwart malware analysts.
LockBit MacOS Variant
Apr 24, 2023, 3:36:34 PM / by The Hivemind posted in Threat Bulletin, Ransomware, LockBit, MacOS, Mac, Apple
Related Families: LockBit
Iranian Threat Actors Target Hybrid Environment
Apr 21, 2023, 2:39:06 PM / by The Hivemind posted in Threat Bulletin, Ransomware, Iran, Muddy Water, Static Kitten, DEV-1084, Mercury
Executive Summary
Iranian threat actors were observed targeting a hybrid environment using ransomware as a decoy for destructive attacks.
Key Takeaways
Rorschach Ransomware
Apr 14, 2023, 2:25:33 PM / by The Hivemind posted in Threat Bulletin, Ransomware, Rorschach
Executive Summary
Rorschach is a newly discovered ransomware family with the fastest encryption to date. While the developers seemed to borrow TTPs from other ransomware strains, Rorschach is unique and points to a sophisticated threat actor.
Trigonia Ransomware
Mar 31, 2023, 2:10:27 PM / by The Hivemind posted in Threat Bulletin, Ransomware, Trigonia, crylock
Related Families: CryLock
Verticals Targeted: Manufacturing, Finance, Construction, Agriculture, Marketing, Technology
CatB Ransomware
Mar 28, 2023, 3:49:33 PM / by The Hivemind posted in Threat Bulletin, Ransomware, CatB, CatB99, Baxtoy, Pandora
Related Families: Pandora
Executive Summary
Sentinel One recently reported on CatB ransomware. CatB, also known as CatB99 or Baxtoy, was first seen in the wild in late 2022.