home.social

#extortion — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #extortion, aggregated by home.social.

fetched live
  1. Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations

    Indicators extracted from public reporting. Source: fortra.com/blog/exfilsquad-dat

    Pulse ID: 6a7f2d7cd148c2db4f9bb65b
    Pulse Link: otx.alienvault.com/pulse/6a7f2
    Pulse Author: CyberHunter_NL
    Created: 2026-08-14 15:00:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  2. Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations

    Indicators extracted from public reporting. Source: fortra.com/blog/exfilsquad-dat

    Pulse ID: 6a7f2d7cd148c2db4f9bb65b
    Pulse Link: otx.alienvault.com/pulse/6a7f2
    Pulse Author: CyberHunter_NL
    Created: 2026-08-14 15:00:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  3. Hits Safe Mode: Ransomware Rebooting Around EDR

    An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique.

    Pulse ID: 6a7ca262c4921e41ead16a57
    Pulse Link: otx.alienvault.com/pulse/6a7ca
    Pulse Author: AlienVault
    Created: 2026-08-12 16:42:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Akira #AnyDesk #Cloud #CyberSecurity #DomainController #EDR #Encryption #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Troll #VPN #WinRAR #bot #AlienVault

  4. Hits Safe Mode: Ransomware Rebooting Around EDR

    An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique.

    Pulse ID: 6a7ca262c4921e41ead16a57
    Pulse Link: otx.alienvault.com/pulse/6a7ca
    Pulse Author: AlienVault
    Created: 2026-08-12 16:42:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Akira #AnyDesk #Cloud #CyberSecurity #DomainController #EDR #Encryption #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Troll #VPN #WinRAR #bot #AlienVault

  5. DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

    DeadLock is an emerging ransomware operation first observed in July 2025, distinguished by its use of decentralized infrastructure combining Session messaging network with blockchain-backed services for victim communications and data leak operations. The encryptor implements double extortion tactics, encrypting files while threatening to leak exfiltrated data, with over 80 organizations published on their leak site as of July 2026. The malware features a resource-aware throttling mechanism to maintain system responsiveness during encryption, language-based geofencing to avoid former Soviet and CIS countries, and hybrid cryptography using Curve25519 and XChaCha20. Its recovery ecosystem leverages Polygon blockchain for configuration storage, Session network for encrypted communications, and Wasabi file hosting, creating resilient infrastructure resistant to traditional takedown efforts. Multiple groups have deployed DeadLock, including affiliates of Lynx and INC ransomware ecosystems, targeting organization...

    Pulse ID: 6a7a12d2aa28d8347ab323f6
    Pulse Link: otx.alienvault.com/pulse/6a7a1
    Pulse Author: AlienVault
    Created: 2026-08-10 18:05:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Rust #bot #AlienVault

  6. DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

    DeadLock is an emerging ransomware operation first observed in July 2025, distinguished by its use of decentralized infrastructure combining Session messaging network with blockchain-backed services for victim communications and data leak operations. The encryptor implements double extortion tactics, encrypting files while threatening to leak exfiltrated data, with over 80 organizations published on their leak site as of July 2026. The malware features a resource-aware throttling mechanism to maintain system responsiveness during encryption, language-based geofencing to avoid former Soviet and CIS countries, and hybrid cryptography using Curve25519 and XChaCha20. Its recovery ecosystem leverages Polygon blockchain for configuration storage, Session network for encrypted communications, and Wasabi file hosting, creating resilient infrastructure resistant to traditional takedown efforts. Multiple groups have deployed DeadLock, including affiliates of Lynx and INC ransomware ecosystems, targeting organization...

    Pulse ID: 6a7a12d2aa28d8347ab323f6
    Pulse Link: otx.alienvault.com/pulse/6a7a1
    Pulse Author: AlienVault
    Created: 2026-08-10 18:05:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Rust #bot #AlienVault

  7. Interlock Ransomware Abuses Forensic Tools for Credential Theft

    Interlock ransomware uses ClickFix social engineering and legitimate
    forensic tools to compromise networks. Attackers abuse Volatility3 and
    WinPmem for credential theft perform Kerberoasting, establish
    persistence, move laterally, exfiltrate data and deploy ransomware for
    double extortion.

    Pulse ID: 6a79c66917a813aade9856bf
    Pulse Link: otx.alienvault.com/pulse/6a79c
    Pulse Author: cryptocti
    Created: 2026-08-10 12:39:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #InfoSec #NPM #OTX #OpenThreatExchange #RAT #RansomWare #SocialEngineering #bot #cryptocti

  8. Interlock Ransomware Abuses Forensic Tools for Credential Theft

    Interlock ransomware uses ClickFix social engineering and legitimate
    forensic tools to compromise networks. Attackers abuse Volatility3 and
    WinPmem for credential theft perform Kerberoasting, establish
    persistence, move laterally, exfiltrate data and deploy ransomware for
    double extortion.

    Pulse ID: 6a79c66917a813aade9856bf
    Pulse Link: otx.alienvault.com/pulse/6a79c
    Pulse Author: cryptocti
    Created: 2026-08-10 12:39:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #InfoSec #NPM #OTX #OpenThreatExchange #RAT #RansomWare #SocialEngineering #bot #cryptocti

  9. Spirals: New Stealthy Ransomware Deployed Against Asian IT Company

    Indicators extracted from public reporting. Source: security.com/threat-intelligen

    Pulse ID: 6a79ac894a4507cbc3e19322
    Pulse Link: otx.alienvault.com/pulse/6a79a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 10:48:41

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #CyberSecurity #Extortion #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #RansomWare #bot #CyberHunter_NL

  10. Spirals: New Stealthy Ransomware Deployed Against Asian IT Company

    Indicators extracted from public reporting. Source: security.com/threat-intelligen

    Pulse ID: 6a79ac894a4507cbc3e19322
    Pulse Link: otx.alienvault.com/pulse/6a79a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 10:48:41

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #CyberSecurity #Extortion #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #RansomWare #bot #CyberHunter_NL

  11. Google Links Redact Extortion Group to BlackFile Rebrand

    Indicators extracted from public reporting. Source: infosecurity-magazine.com/news

    Pulse ID: 6a79a07eef5448a6ecac6c64
    Pulse Link: otx.alienvault.com/pulse/6a79a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 09:57:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  12. Google Links Redact Extortion Group to BlackFile Rebrand

    Indicators extracted from public reporting. Source: infosecurity-magazine.com/news

    Pulse ID: 6a79a07eef5448a6ecac6c64
    Pulse Link: otx.alienvault.com/pulse/6a79a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 09:57:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  13. Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

    Pulse ID: 6a7951b6bfc33f720a4723ea
    Pulse Link: otx.alienvault.com/pulse/6a795
    Pulse Author: Tr1sa111
    Created: 2026-08-10 04:21:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #Extortion #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111

  14. Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

    Pulse ID: 6a7951b6bfc33f720a4723ea
    Pulse Link: otx.alienvault.com/pulse/6a795
    Pulse Author: Tr1sa111
    Created: 2026-08-10 04:21:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #Extortion #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111

  15. Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

    UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...

    Pulse ID: 6a75078f7b8e057bc29b8769
    Pulse Link: otx.alienvault.com/pulse/6a750
    Pulse Author: AlienVault
    Created: 2026-08-06 22:15:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #BitCoin #Cloud #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RAT #RCE #bot #AlienVault

  16. Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

    UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...

    Pulse ID: 6a75078f7b8e057bc29b8769
    Pulse Link: otx.alienvault.com/pulse/6a750
    Pulse Author: AlienVault
    Created: 2026-08-06 22:15:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #BitCoin #Cloud #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RAT #RCE #bot #AlienVault

  17. One of the dozens of new #ransomware groups this year is a group calling itself #Orova. Since early May, they appear to have dozens of victims in about half a dozen countries.

    Three of the listings are U.S. medical entities, so, of course, I reached out to them to find out more.

    My new report:

    Cardiology Associates of Port Huron remains silent although they were allegedly hacked and had patient data stolen in June.

    databreaches.net/2026/08/06/ca

    #databreach #healthsec #cybersecurity #extortion #encryption

  18. One of the dozens of new #ransomware groups this year is a group calling itself #Orova. Since early May, they appear to have dozens of victims in about half a dozen countries.

    Three of the listings are U.S. medical entities, so, of course, I reached out to them to find out more.

    My new report:

    Cardiology Associates of Port Huron remains silent although they were allegedly hacked and had patient data stolen in June.

    databreaches.net/2026/08/06/ca

    #databreach #healthsec #cybersecurity #extortion #encryption

  19. RE: infosec.exchange/@mle/11701998

    As of ~yesterday, a leak warning has appeared on Cl0p's site for 42 alleged victims of this campaign. Total estimated amount of data stolen across all orgs reaches roughly 23TB and appears to include data like CAD files, databases and backups, engineering drawings, and various other documents.

    Their total estimate of value for the data seems a bit...off, though, considering one org's valuation is listed at over 2 trillion dollars. Without that outlier, the rest of their estimate for company revenue comes to roughly $192 billion. It's in their best interest to provide estimates on the high side, though, so that's an important consideration.

    #security #ransomware #extortion #cl0p

  20. RE: infosec.exchange/@mle/11701998

    As of ~yesterday, a leak warning has appeared on Cl0p's site for 42 alleged victims of this campaign. Total estimated amount of data stolen across all orgs reaches roughly 23TB and appears to include data like CAD files, databases and backups, engineering drawings, and various other documents.

    Their total estimate of value for the data seems a bit...off, though, considering one org's valuation is listed at over 2 trillion dollars. Without that outlier, the rest of their estimate for company revenue comes to roughly $192 billion. It's in their best interest to provide estimates on the high side, though, so that's an important consideration.

    #security #ransomware #extortion #cl0p

  21. New from me: analysis of a June #Cl0p extortion campaign. In a departure from their previous targeting, the data stolen in this campaign may be a bit different than what they've taken in the past. The campaign targeted PTC's Windchill and FlexPLM products, product lifecycle management tools used in manufacturing and industrial engineering.

    Rather than financial, HR, or customer data, the compromised data in this case may include things like supply chain details, product designs and schematics, and other intellectual property. This is particularly notable given the adoption of Windchill across the energy, electronics, medical device tech, and defense sectors.

    Read more: censys.com/blog/cl0p-targets-w

    #infosec #extortion #ICS #energy

  22. New from me: analysis of a June #Cl0p extortion campaign. In a departure from their previous targeting, the data stolen in this campaign may be a bit different than what they've taken in the past. The campaign targeted PTC's Windchill and FlexPLM products, product lifecycle management tools used in manufacturing and industrial engineering.

    Rather than financial, HR, or customer data, the compromised data in this case may include things like supply chain details, product designs and schematics, and other intellectual property. This is particularly notable given the adoption of Windchill across the energy, electronics, medical device tech, and defense sectors.

    Read more: censys.com/blog/cl0p-targets-w

    #infosec #extortion #ICS #energy

  23. Microsoft Teams Vishing Campaign Abuses Quick Assist to Deploy GoGRPC Backdoor

    Microsoft Teams vishing campaign targeting enterprises between January and June 2026. Attackers use email bombing, Teams impersonation and Quick Assist to deploy the GoGRPC backdoor, enabling ersistent access, reconnaissance and potential ransomware or extortion through compromised enterprise networks.

    Pulse ID: 6a693ba0eaf729fe7f4805da
    Pulse Link: otx.alienvault.com/pulse/6a693
    Pulse Author: cryptocti
    Created: 2026-07-28 23:30:40

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #Email #Extortion #InfoSec #Microsoft #MicrosoftTeams #OTX #OpenThreatExchange #RPC #RansomWare #bot #cryptocti

  24. Microsoft Teams Vishing Campaign Abuses Quick Assist to Deploy GoGRPC Backdoor

    Microsoft Teams vishing campaign targeting enterprises between January and June 2026. Attackers use email bombing, Teams impersonation and Quick Assist to deploy the GoGRPC backdoor, enabling ersistent access, reconnaissance and potential ransomware or extortion through compromised enterprise networks.

    Pulse ID: 6a693ba0eaf729fe7f4805da
    Pulse Link: otx.alienvault.com/pulse/6a693
    Pulse Author: cryptocti
    Created: 2026-07-28 23:30:40

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #Email #Extortion #InfoSec #Microsoft #MicrosoftTeams #OTX #OpenThreatExchange #RPC #RansomWare #bot #cryptocti

  25. DATE: July 28, 2026 at 03:45PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #MedicalBilling Vendor Hack Affects 1.3M Patients:
    #Extortion Gang #PEAR Claims Theft of 3.3TB of #MCBS LLC's Client and Patient Data
    t.co/81VDJg1fKz
    #HIPAA

    Here are any URLs found in the article text:

    t.co/81VDJg1fKz

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  26. DATE: July 28, 2026 at 03:45PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #MedicalBilling Vendor Hack Affects 1.3M Patients:
    #Extortion Gang #PEAR Claims Theft of 3.3TB of #MCBS LLC's Client and Patient Data
    t.co/81VDJg1fKz
    #HIPAA

    Here are any URLs found in the article text:

    t.co/81VDJg1fKz

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  27. A New Name in the Data Extortion Ecosystem?

    Pulse ID: 6a62e89a5f79710194cc0a1d
    Pulse Link: otx.alienvault.com/pulse/6a62e
    Pulse Author: Tr1sa111
    Created: 2026-07-24 04:22:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111

  28. A New Name in the Data Extortion Ecosystem?

    Pulse ID: 6a62e89a5f79710194cc0a1d
    Pulse Link: otx.alienvault.com/pulse/6a62e
    Pulse Author: Tr1sa111
    Created: 2026-07-24 04:22:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111

  29. #Schiff said that #trump used the leverage that he had over the social media companies to "help or hurt their businesses" and extorted the social media companies "to the tune of $60 million." 👀

    The cost of Trump's corruption with the social media companies to the American public is "more false claims, more false information, more social harms from an unregulated social media, and potentially more incitement of violence around our elections."

    /4
    #USA #US #USpol #corruption #PayToPlay #extortion

  30. #Schiff said that #trump used the leverage that he had over the social media companies to "help or hurt their businesses" and extorted the social media companies "to the tune of $60 million." 👀

    The cost of Trump's corruption with the social media companies to the American public is "more false claims, more false information, more social harms from an unregulated social media, and potentially more incitement of violence around our elections."

    /4
    #USA #US #USpol #corruption #PayToPlay #extortion

  31. #Schiff said that #trump has received ~$60 million in "big tech settlements" after suing big social media companies Meta, Twitter, and YouTube (he had been suspended from these platforms for "conduct related to the attack he incited on the Capitol"), then settling with the companies.

    "One by one, these companies paid up — to him personally and to his pet projects like the golden ballroom" via "creative accounting."

    Schiff called Trump's actions #extortion

    /3
    #USA #USpol #corruption #PayToPlay

  32. #Schiff said that #trump has received ~$60 million in "big tech settlements" after suing big social media companies Meta, Twitter, and YouTube (he had been suspended from these platforms for "conduct related to the attack he incited on the Capitol"), then settling with the companies.

    "One by one, these companies paid up — to him personally and to his pet projects like the golden ballroom" via "creative accounting."

    Schiff called Trump's actions #extortion

    /3
    #USA #USpol #corruption #PayToPlay

  33. A New Name in the Data Extortion Ecosystem?

    A data extortion group called Helix has been identified conducting multi-target campaigns using vishing, device code phishing, and automated SharePoint exfiltration. The group likely emerged from the BlackFile and ShinyHunters ecosystem after BlackFile shut down in April 2026. Helix uses sophisticated social engineering, impersonating managers by name during vishing calls to initiate device code authentication flows. The operation employs shared infrastructure including phishing domains registered through NICENIC with target-specific subdomains. After gaining access, attackers register MFA on compromised accounts, enumerate SharePoint using automated tools with python-requests user-agent, and conduct bulk data exfiltration. Infrastructure analysis reveals connections to BlackFile through hosting on the same autonomous system. The group demonstrates operational flexibility with varying dwell times and uses residential proxies geo-matched to targets to evade detection.

    Pulse ID: 6a623272a8b581c080b0aee0
    Pulse Link: otx.alienvault.com/pulse/6a623
    Pulse Author: AlienVault
    Created: 2026-07-23 15:25:38

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #InfoSec #MFA #OTX #OpenThreatExchange #Phishing #Python #RAT #SocialEngineering #bot #AlienVault

  34. A New Name in the Data Extortion Ecosystem?

    A data extortion group called Helix has been identified conducting multi-target campaigns using vishing, device code phishing, and automated SharePoint exfiltration. The group likely emerged from the BlackFile and ShinyHunters ecosystem after BlackFile shut down in April 2026. Helix uses sophisticated social engineering, impersonating managers by name during vishing calls to initiate device code authentication flows. The operation employs shared infrastructure including phishing domains registered through NICENIC with target-specific subdomains. After gaining access, attackers register MFA on compromised accounts, enumerate SharePoint using automated tools with python-requests user-agent, and conduct bulk data exfiltration. Infrastructure analysis reveals connections to BlackFile through hosting on the same autonomous system. The group demonstrates operational flexibility with varying dwell times and uses residential proxies geo-matched to targets to evade detection.

    Pulse ID: 6a623272a8b581c080b0aee0
    Pulse Link: otx.alienvault.com/pulse/6a623
    Pulse Author: AlienVault
    Created: 2026-07-23 15:25:38

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #InfoSec #MFA #OTX #OpenThreatExchange #Phishing #Python #RAT #SocialEngineering #bot #AlienVault

  35. HP, a fine instrument* and then computer and then printer manufacturer. Then they decided that ink and services were the route to board enrichment.

    Happy to say I have not lost a minutes sleep to never buying one after I left the company many moons ago (but my LaserJet 5 is still going strong — a different era)

    theregister.com/legal/2026/07/

    *yes I know that went off to Agilent

    #HP #Printers #Ink #Extortion #Shoddy #Avoid

  36. HP, a fine instrument* and then computer and then printer manufacturer. Then they decided that ink and services were the route to board enrichment.

    Happy to say I have not lost a minutes sleep to never buying one after I left the company many moons ago (but my LaserJet 5 is still going strong — a different era)

    theregister.com/legal/2026/07/

    *yes I know that went off to Agilent

    #HP #Printers #Ink #Extortion #Shoddy #Avoid

  37. Spirals: New Stealthy Ransomware Deployed Against Asian IT Company

    A previously unseen ransomware family named Spirals was deployed in a double extortion attack against an IT services company in South Asia in June 2026. The Rust-based payload demonstrated sophisticated capabilities including defense evasion, encryption, lateral movement, and privilege escalation. Attackers gained initial access through a compromised internet-facing IIS web server via an ASP.NET web shell, moving rapidly to deploy ransomware within 24 hours. They established persistence using multiple tunneling tools, disabled endpoint security, harvested credentials through SAM hive and LSASS dumps, and deployed reverse-SOCKS proxies for covert command-and-control. The ransomware was distributed across the network using PsExec, encrypting files with AES-128 keys and threatening data publication within six days. The skilled execution suggests potential for wider campaigns, though the threat actor remains unidentified.

    Pulse ID: 6a58c2ecd43c8e98d4bdd2e0
    Pulse Link: otx.alienvault.com/pulse/6a58c
    Pulse Author: AlienVault
    Created: 2026-07-16 11:39:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #CyberSecurity #Encryption #Endpoint #Extortion #InfoSec #NET #OTX #OpenThreatExchange #PsExec #RAT #RansomWare #Rust #SouthAsia #bot #AlienVault