home.social

#extortion — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #extortion, aggregated by home.social.

fetched live
  1. Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations

    Indicators extracted from public reporting. Source: fortra.com/blog/exfilsquad-dat

    Pulse ID: 6a7f2d7cd148c2db4f9bb65b
    Pulse Link: otx.alienvault.com/pulse/6a7f2
    Pulse Author: CyberHunter_NL
    Created: 2026-08-14 15:00:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  2. Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations

    Indicators extracted from public reporting. Source: fortra.com/blog/exfilsquad-dat

    Pulse ID: 6a7f2d7cd148c2db4f9bb65b
    Pulse Link: otx.alienvault.com/pulse/6a7f2
    Pulse Author: CyberHunter_NL
    Created: 2026-08-14 15:00:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  3. Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations

    Indicators extracted from public reporting. Source: fortra.com/blog/exfilsquad-dat

    Pulse ID: 6a7f2d7cd148c2db4f9bb65b
    Pulse Link: otx.alienvault.com/pulse/6a7f2
    Pulse Author: CyberHunter_NL
    Created: 2026-08-14 15:00:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  4. Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations

    Indicators extracted from public reporting. Source: fortra.com/blog/exfilsquad-dat

    Pulse ID: 6a7f2d7cd148c2db4f9bb65b
    Pulse Link: otx.alienvault.com/pulse/6a7f2
    Pulse Author: CyberHunter_NL
    Created: 2026-08-14 15:00:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  5. Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations

    Indicators extracted from public reporting. Source: fortra.com/blog/exfilsquad-dat

    Pulse ID: 6a7f2d7cd148c2db4f9bb65b
    Pulse Link: otx.alienvault.com/pulse/6a7f2
    Pulse Author: CyberHunter_NL
    Created: 2026-08-14 15:00:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  6. Hits Safe Mode: Ransomware Rebooting Around EDR

    An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique.

    Pulse ID: 6a7ca262c4921e41ead16a57
    Pulse Link: otx.alienvault.com/pulse/6a7ca
    Pulse Author: AlienVault
    Created: 2026-08-12 16:42:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Akira #AnyDesk #Cloud #CyberSecurity #DomainController #EDR #Encryption #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Troll #VPN #WinRAR #bot #AlienVault

  7. Hits Safe Mode: Ransomware Rebooting Around EDR

    An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique.

    Pulse ID: 6a7ca262c4921e41ead16a57
    Pulse Link: otx.alienvault.com/pulse/6a7ca
    Pulse Author: AlienVault
    Created: 2026-08-12 16:42:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Akira #AnyDesk #Cloud #CyberSecurity #DomainController #EDR #Encryption #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Troll #VPN #WinRAR #bot #AlienVault

  8. Hits Safe Mode: Ransomware Rebooting Around EDR

    An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique.

    Pulse ID: 6a7ca262c4921e41ead16a57
    Pulse Link: otx.alienvault.com/pulse/6a7ca
    Pulse Author: AlienVault
    Created: 2026-08-12 16:42:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Akira #AnyDesk #Cloud #CyberSecurity #DomainController #EDR #Encryption #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Troll #VPN #WinRAR #bot #AlienVault

  9. Hits Safe Mode: Ransomware Rebooting Around EDR

    An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique.

    Pulse ID: 6a7ca262c4921e41ead16a57
    Pulse Link: otx.alienvault.com/pulse/6a7ca
    Pulse Author: AlienVault
    Created: 2026-08-12 16:42:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Akira #AnyDesk #Cloud #CyberSecurity #DomainController #EDR #Encryption #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Troll #VPN #WinRAR #bot #AlienVault

  10. Hits Safe Mode: Ransomware Rebooting Around EDR

    An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique.

    Pulse ID: 6a7ca262c4921e41ead16a57
    Pulse Link: otx.alienvault.com/pulse/6a7ca
    Pulse Author: AlienVault
    Created: 2026-08-12 16:42:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Akira #AnyDesk #Cloud #CyberSecurity #DomainController #EDR #Encryption #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Troll #VPN #WinRAR #bot #AlienVault

  11. DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

    DeadLock is an emerging ransomware operation first observed in July 2025, distinguished by its use of decentralized infrastructure combining Session messaging network with blockchain-backed services for victim communications and data leak operations. The encryptor implements double extortion tactics, encrypting files while threatening to leak exfiltrated data, with over 80 organizations published on their leak site as of July 2026. The malware features a resource-aware throttling mechanism to maintain system responsiveness during encryption, language-based geofencing to avoid former Soviet and CIS countries, and hybrid cryptography using Curve25519 and XChaCha20. Its recovery ecosystem leverages Polygon blockchain for configuration storage, Session network for encrypted communications, and Wasabi file hosting, creating resilient infrastructure resistant to traditional takedown efforts. Multiple groups have deployed DeadLock, including affiliates of Lynx and INC ransomware ecosystems, targeting organization...

    Pulse ID: 6a7a12d2aa28d8347ab323f6
    Pulse Link: otx.alienvault.com/pulse/6a7a1
    Pulse Author: AlienVault
    Created: 2026-08-10 18:05:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Rust #bot #AlienVault

  12. DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

    DeadLock is an emerging ransomware operation first observed in July 2025, distinguished by its use of decentralized infrastructure combining Session messaging network with blockchain-backed services for victim communications and data leak operations. The encryptor implements double extortion tactics, encrypting files while threatening to leak exfiltrated data, with over 80 organizations published on their leak site as of July 2026. The malware features a resource-aware throttling mechanism to maintain system responsiveness during encryption, language-based geofencing to avoid former Soviet and CIS countries, and hybrid cryptography using Curve25519 and XChaCha20. Its recovery ecosystem leverages Polygon blockchain for configuration storage, Session network for encrypted communications, and Wasabi file hosting, creating resilient infrastructure resistant to traditional takedown efforts. Multiple groups have deployed DeadLock, including affiliates of Lynx and INC ransomware ecosystems, targeting organization...

    Pulse ID: 6a7a12d2aa28d8347ab323f6
    Pulse Link: otx.alienvault.com/pulse/6a7a1
    Pulse Author: AlienVault
    Created: 2026-08-10 18:05:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Rust #bot #AlienVault

  13. DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

    DeadLock is an emerging ransomware operation first observed in July 2025, distinguished by its use of decentralized infrastructure combining Session messaging network with blockchain-backed services for victim communications and data leak operations. The encryptor implements double extortion tactics, encrypting files while threatening to leak exfiltrated data, with over 80 organizations published on their leak site as of July 2026. The malware features a resource-aware throttling mechanism to maintain system responsiveness during encryption, language-based geofencing to avoid former Soviet and CIS countries, and hybrid cryptography using Curve25519 and XChaCha20. Its recovery ecosystem leverages Polygon blockchain for configuration storage, Session network for encrypted communications, and Wasabi file hosting, creating resilient infrastructure resistant to traditional takedown efforts. Multiple groups have deployed DeadLock, including affiliates of Lynx and INC ransomware ecosystems, targeting organization...

    Pulse ID: 6a7a12d2aa28d8347ab323f6
    Pulse Link: otx.alienvault.com/pulse/6a7a1
    Pulse Author: AlienVault
    Created: 2026-08-10 18:05:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Rust #bot #AlienVault

  14. DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

    DeadLock is an emerging ransomware operation first observed in July 2025, distinguished by its use of decentralized infrastructure combining Session messaging network with blockchain-backed services for victim communications and data leak operations. The encryptor implements double extortion tactics, encrypting files while threatening to leak exfiltrated data, with over 80 organizations published on their leak site as of July 2026. The malware features a resource-aware throttling mechanism to maintain system responsiveness during encryption, language-based geofencing to avoid former Soviet and CIS countries, and hybrid cryptography using Curve25519 and XChaCha20. Its recovery ecosystem leverages Polygon blockchain for configuration storage, Session network for encrypted communications, and Wasabi file hosting, creating resilient infrastructure resistant to traditional takedown efforts. Multiple groups have deployed DeadLock, including affiliates of Lynx and INC ransomware ecosystems, targeting organization...

    Pulse ID: 6a7a12d2aa28d8347ab323f6
    Pulse Link: otx.alienvault.com/pulse/6a7a1
    Pulse Author: AlienVault
    Created: 2026-08-10 18:05:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Rust #bot #AlienVault

  15. DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

    DeadLock is an emerging ransomware operation first observed in July 2025, distinguished by its use of decentralized infrastructure combining Session messaging network with blockchain-backed services for victim communications and data leak operations. The encryptor implements double extortion tactics, encrypting files while threatening to leak exfiltrated data, with over 80 organizations published on their leak site as of July 2026. The malware features a resource-aware throttling mechanism to maintain system responsiveness during encryption, language-based geofencing to avoid former Soviet and CIS countries, and hybrid cryptography using Curve25519 and XChaCha20. Its recovery ecosystem leverages Polygon blockchain for configuration storage, Session network for encrypted communications, and Wasabi file hosting, creating resilient infrastructure resistant to traditional takedown efforts. Multiple groups have deployed DeadLock, including affiliates of Lynx and INC ransomware ecosystems, targeting organization...

    Pulse ID: 6a7a12d2aa28d8347ab323f6
    Pulse Link: otx.alienvault.com/pulse/6a7a1
    Pulse Author: AlienVault
    Created: 2026-08-10 18:05:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Rust #bot #AlienVault

  16. Interlock Ransomware Abuses Forensic Tools for Credential Theft

    Interlock ransomware uses ClickFix social engineering and legitimate
    forensic tools to compromise networks. Attackers abuse Volatility3 and
    WinPmem for credential theft perform Kerberoasting, establish
    persistence, move laterally, exfiltrate data and deploy ransomware for
    double extortion.

    Pulse ID: 6a79c66917a813aade9856bf
    Pulse Link: otx.alienvault.com/pulse/6a79c
    Pulse Author: cryptocti
    Created: 2026-08-10 12:39:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #InfoSec #NPM #OTX #OpenThreatExchange #RAT #RansomWare #SocialEngineering #bot #cryptocti

  17. Interlock Ransomware Abuses Forensic Tools for Credential Theft

    Interlock ransomware uses ClickFix social engineering and legitimate
    forensic tools to compromise networks. Attackers abuse Volatility3 and
    WinPmem for credential theft perform Kerberoasting, establish
    persistence, move laterally, exfiltrate data and deploy ransomware for
    double extortion.

    Pulse ID: 6a79c66917a813aade9856bf
    Pulse Link: otx.alienvault.com/pulse/6a79c
    Pulse Author: cryptocti
    Created: 2026-08-10 12:39:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #InfoSec #NPM #OTX #OpenThreatExchange #RAT #RansomWare #SocialEngineering #bot #cryptocti

  18. Interlock Ransomware Abuses Forensic Tools for Credential Theft

    Interlock ransomware uses ClickFix social engineering and legitimate
    forensic tools to compromise networks. Attackers abuse Volatility3 and
    WinPmem for credential theft perform Kerberoasting, establish
    persistence, move laterally, exfiltrate data and deploy ransomware for
    double extortion.

    Pulse ID: 6a79c66917a813aade9856bf
    Pulse Link: otx.alienvault.com/pulse/6a79c
    Pulse Author: cryptocti
    Created: 2026-08-10 12:39:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #InfoSec #NPM #OTX #OpenThreatExchange #RAT #RansomWare #SocialEngineering #bot #cryptocti

  19. Interlock Ransomware Abuses Forensic Tools for Credential Theft

    Interlock ransomware uses ClickFix social engineering and legitimate
    forensic tools to compromise networks. Attackers abuse Volatility3 and
    WinPmem for credential theft perform Kerberoasting, establish
    persistence, move laterally, exfiltrate data and deploy ransomware for
    double extortion.

    Pulse ID: 6a79c66917a813aade9856bf
    Pulse Link: otx.alienvault.com/pulse/6a79c
    Pulse Author: cryptocti
    Created: 2026-08-10 12:39:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #InfoSec #NPM #OTX #OpenThreatExchange #RAT #RansomWare #SocialEngineering #bot #cryptocti

  20. Interlock Ransomware Abuses Forensic Tools for Credential Theft

    Interlock ransomware uses ClickFix social engineering and legitimate
    forensic tools to compromise networks. Attackers abuse Volatility3 and
    WinPmem for credential theft perform Kerberoasting, establish
    persistence, move laterally, exfiltrate data and deploy ransomware for
    double extortion.

    Pulse ID: 6a79c66917a813aade9856bf
    Pulse Link: otx.alienvault.com/pulse/6a79c
    Pulse Author: cryptocti
    Created: 2026-08-10 12:39:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #InfoSec #NPM #OTX #OpenThreatExchange #RAT #RansomWare #SocialEngineering #bot #cryptocti

  21. Spirals: New Stealthy Ransomware Deployed Against Asian IT Company

    Indicators extracted from public reporting. Source: security.com/threat-intelligen

    Pulse ID: 6a79ac894a4507cbc3e19322
    Pulse Link: otx.alienvault.com/pulse/6a79a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 10:48:41

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #CyberSecurity #Extortion #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #RansomWare #bot #CyberHunter_NL

  22. Spirals: New Stealthy Ransomware Deployed Against Asian IT Company

    Indicators extracted from public reporting. Source: security.com/threat-intelligen

    Pulse ID: 6a79ac894a4507cbc3e19322
    Pulse Link: otx.alienvault.com/pulse/6a79a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 10:48:41

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #CyberSecurity #Extortion #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #RansomWare #bot #CyberHunter_NL

  23. Spirals: New Stealthy Ransomware Deployed Against Asian IT Company

    Indicators extracted from public reporting. Source: security.com/threat-intelligen

    Pulse ID: 6a79ac894a4507cbc3e19322
    Pulse Link: otx.alienvault.com/pulse/6a79a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 10:48:41

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #CyberSecurity #Extortion #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #RansomWare #bot #CyberHunter_NL

  24. Spirals: New Stealthy Ransomware Deployed Against Asian IT Company

    Indicators extracted from public reporting. Source: security.com/threat-intelligen

    Pulse ID: 6a79ac894a4507cbc3e19322
    Pulse Link: otx.alienvault.com/pulse/6a79a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 10:48:41

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #CyberSecurity #Extortion #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #RansomWare #bot #CyberHunter_NL

  25. Spirals: New Stealthy Ransomware Deployed Against Asian IT Company

    Indicators extracted from public reporting. Source: security.com/threat-intelligen

    Pulse ID: 6a79ac894a4507cbc3e19322
    Pulse Link: otx.alienvault.com/pulse/6a79a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 10:48:41

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #CyberSecurity #Extortion #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #RansomWare #bot #CyberHunter_NL

  26. Google Links Redact Extortion Group to BlackFile Rebrand

    Indicators extracted from public reporting. Source: infosecurity-magazine.com/news

    Pulse ID: 6a79a07eef5448a6ecac6c64
    Pulse Link: otx.alienvault.com/pulse/6a79a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 09:57:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  27. Google Links Redact Extortion Group to BlackFile Rebrand

    Indicators extracted from public reporting. Source: infosecurity-magazine.com/news

    Pulse ID: 6a79a07eef5448a6ecac6c64
    Pulse Link: otx.alienvault.com/pulse/6a79a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 09:57:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  28. Google Links Redact Extortion Group to BlackFile Rebrand

    Indicators extracted from public reporting. Source: infosecurity-magazine.com/news

    Pulse ID: 6a79a07eef5448a6ecac6c64
    Pulse Link: otx.alienvault.com/pulse/6a79a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 09:57:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  29. Google Links Redact Extortion Group to BlackFile Rebrand

    Indicators extracted from public reporting. Source: infosecurity-magazine.com/news

    Pulse ID: 6a79a07eef5448a6ecac6c64
    Pulse Link: otx.alienvault.com/pulse/6a79a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 09:57:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  30. Google Links Redact Extortion Group to BlackFile Rebrand

    Indicators extracted from public reporting. Source: infosecurity-magazine.com/news

    Pulse ID: 6a79a07eef5448a6ecac6c64
    Pulse Link: otx.alienvault.com/pulse/6a79a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 09:57:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Extortion #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  31. Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

    Pulse ID: 6a7951b6bfc33f720a4723ea
    Pulse Link: otx.alienvault.com/pulse/6a795
    Pulse Author: Tr1sa111
    Created: 2026-08-10 04:21:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #Extortion #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111

  32. Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

    Pulse ID: 6a7951b6bfc33f720a4723ea
    Pulse Link: otx.alienvault.com/pulse/6a795
    Pulse Author: Tr1sa111
    Created: 2026-08-10 04:21:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #Extortion #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111

  33. Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

    Pulse ID: 6a7951b6bfc33f720a4723ea
    Pulse Link: otx.alienvault.com/pulse/6a795
    Pulse Author: Tr1sa111
    Created: 2026-08-10 04:21:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #Extortion #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111

  34. Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

    Pulse ID: 6a7951b6bfc33f720a4723ea
    Pulse Link: otx.alienvault.com/pulse/6a795
    Pulse Author: Tr1sa111
    Created: 2026-08-10 04:21:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #Extortion #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111

  35. Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

    Pulse ID: 6a7951b6bfc33f720a4723ea
    Pulse Link: otx.alienvault.com/pulse/6a795
    Pulse Author: Tr1sa111
    Created: 2026-08-10 04:21:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #Extortion #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111

  36. Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

    UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...

    Pulse ID: 6a75078f7b8e057bc29b8769
    Pulse Link: otx.alienvault.com/pulse/6a750
    Pulse Author: AlienVault
    Created: 2026-08-06 22:15:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #BitCoin #Cloud #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RAT #RCE #bot #AlienVault

  37. Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

    UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...

    Pulse ID: 6a75078f7b8e057bc29b8769
    Pulse Link: otx.alienvault.com/pulse/6a750
    Pulse Author: AlienVault
    Created: 2026-08-06 22:15:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #BitCoin #Cloud #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RAT #RCE #bot #AlienVault

  38. Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

    UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...

    Pulse ID: 6a75078f7b8e057bc29b8769
    Pulse Link: otx.alienvault.com/pulse/6a750
    Pulse Author: AlienVault
    Created: 2026-08-06 22:15:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #BitCoin #Cloud #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RAT #RCE #bot #AlienVault

  39. Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

    UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...

    Pulse ID: 6a75078f7b8e057bc29b8769
    Pulse Link: otx.alienvault.com/pulse/6a750
    Pulse Author: AlienVault
    Created: 2026-08-06 22:15:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #BitCoin #Cloud #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RAT #RCE #bot #AlienVault

  40. Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

    UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...

    Pulse ID: 6a75078f7b8e057bc29b8769
    Pulse Link: otx.alienvault.com/pulse/6a750
    Pulse Author: AlienVault
    Created: 2026-08-06 22:15:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #BitCoin #Cloud #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RAT #RCE #bot #AlienVault