#extortion — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #extortion, aggregated by home.social.
-
Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations
Indicators extracted from public reporting. Source: https://www.fortra.com/blog/exfilsquad-data-extortion-group-ransoming-microsoft-d365-data
Pulse ID: 6a7f2d7cd148c2db4f9bb65b
Pulse Link: https://otx.alienvault.com/pulse/6a7f2d7cd148c2db4f9bb65b
Pulse Author: CyberHunter_NL
Created: 2026-08-14 15:00:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Extortion #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations
Indicators extracted from public reporting. Source: https://www.fortra.com/blog/exfilsquad-data-extortion-group-ransoming-microsoft-d365-data
Pulse ID: 6a7f2d7cd148c2db4f9bb65b
Pulse Link: https://otx.alienvault.com/pulse/6a7f2d7cd148c2db4f9bb65b
Pulse Author: CyberHunter_NL
Created: 2026-08-14 15:00:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Extortion #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations
Indicators extracted from public reporting. Source: https://www.fortra.com/blog/exfilsquad-data-extortion-group-ransoming-microsoft-d365-data
Pulse ID: 6a7f2d7cd148c2db4f9bb65b
Pulse Link: https://otx.alienvault.com/pulse/6a7f2d7cd148c2db4f9bb65b
Pulse Author: CyberHunter_NL
Created: 2026-08-14 15:00:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Extortion #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations
Indicators extracted from public reporting. Source: https://www.fortra.com/blog/exfilsquad-data-extortion-group-ransoming-microsoft-d365-data
Pulse ID: 6a7f2d7cd148c2db4f9bb65b
Pulse Link: https://otx.alienvault.com/pulse/6a7f2d7cd148c2db4f9bb65b
Pulse Author: CyberHunter_NL
Created: 2026-08-14 15:00:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Extortion #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations
Indicators extracted from public reporting. Source: https://www.fortra.com/blog/exfilsquad-data-extortion-group-ransoming-microsoft-d365-data
Pulse ID: 6a7f2d7cd148c2db4f9bb65b
Pulse Link: https://otx.alienvault.com/pulse/6a7f2d7cd148c2db4f9bb65b
Pulse Author: CyberHunter_NL
Created: 2026-08-14 15:00:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Extortion #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
Hits Safe Mode: Ransomware Rebooting Around EDR
An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique.
Pulse ID: 6a7ca262c4921e41ead16a57
Pulse Link: https://otx.alienvault.com/pulse/6a7ca262c4921e41ead16a57
Pulse Author: AlienVault
Created: 2026-08-12 16:42:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Akira #AnyDesk #Cloud #CyberSecurity #DomainController #EDR #Encryption #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Troll #VPN #WinRAR #bot #AlienVault
-
Hits Safe Mode: Ransomware Rebooting Around EDR
An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique.
Pulse ID: 6a7ca262c4921e41ead16a57
Pulse Link: https://otx.alienvault.com/pulse/6a7ca262c4921e41ead16a57
Pulse Author: AlienVault
Created: 2026-08-12 16:42:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Akira #AnyDesk #Cloud #CyberSecurity #DomainController #EDR #Encryption #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Troll #VPN #WinRAR #bot #AlienVault
-
Hits Safe Mode: Ransomware Rebooting Around EDR
An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique.
Pulse ID: 6a7ca262c4921e41ead16a57
Pulse Link: https://otx.alienvault.com/pulse/6a7ca262c4921e41ead16a57
Pulse Author: AlienVault
Created: 2026-08-12 16:42:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Akira #AnyDesk #Cloud #CyberSecurity #DomainController #EDR #Encryption #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Troll #VPN #WinRAR #bot #AlienVault
-
Hits Safe Mode: Ransomware Rebooting Around EDR
An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique.
Pulse ID: 6a7ca262c4921e41ead16a57
Pulse Link: https://otx.alienvault.com/pulse/6a7ca262c4921e41ead16a57
Pulse Author: AlienVault
Created: 2026-08-12 16:42:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Akira #AnyDesk #Cloud #CyberSecurity #DomainController #EDR #Encryption #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Troll #VPN #WinRAR #bot #AlienVault
-
Hits Safe Mode: Ransomware Rebooting Around EDR
An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique.
Pulse ID: 6a7ca262c4921e41ead16a57
Pulse Link: https://otx.alienvault.com/pulse/6a7ca262c4921e41ead16a57
Pulse Author: AlienVault
Created: 2026-08-12 16:42:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Akira #AnyDesk #Cloud #CyberSecurity #DomainController #EDR #Encryption #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Troll #VPN #WinRAR #bot #AlienVault
-
https://www.europesays.com/africa/374912/ Lagos touts harass Comedian Brain Jotter #AreaBoys #BrainJotter #CelebrityNews #Extortion #harassment #LagosCrime #LagosTouts #Nigeria #NigerianComedians #StreetViolence
-
Paul Hastings Expands Global IP Practice With Partner in London
Chloe Kite joined Paul Hastings as a partner in its intellectual property practice in London, the firm announced…
#London #UnitedKingdom #UK #GB #England #Headlines #News #Europe #EU #ArtificialIntelligence #Britain #enterpriseriskmanagement #extortion #GreatBritain #london #Malware #pharmaceuticalresearchanddevelopment #Privateequity #Robotics
https://www.europesays.com/uk/1144597/ -
https://www.europesays.com/uk/1144597/ Paul Hastings Expands Global IP Practice With Partner in London #ArtificialIntelligence #Britain #England #EnterpriseRiskManagement #extortion #GreatBritain #london #Malware #PharmaceuticalResearchAndDevelopment #PrivateEquity #Robotics #UK #UnitedKingdom
-
UNC6671 vishing extortion group rebrands across five names, using AiTM credential phishing to hit financial services and enterprise cloud accounts.
#UNC6671 #Vishing #Phishing #Extortion #CloudSecurity #Cybersecurity
-
UNC6671 vishing extortion group rebrands across five names, using AiTM credential phishing to hit financial services and enterprise cloud accounts.
#UNC6671 #Vishing #Phishing #Extortion #CloudSecurity #Cybersecurity
-
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
DeadLock is an emerging ransomware operation first observed in July 2025, distinguished by its use of decentralized infrastructure combining Session messaging network with blockchain-backed services for victim communications and data leak operations. The encryptor implements double extortion tactics, encrypting files while threatening to leak exfiltrated data, with over 80 organizations published on their leak site as of July 2026. The malware features a resource-aware throttling mechanism to maintain system responsiveness during encryption, language-based geofencing to avoid former Soviet and CIS countries, and hybrid cryptography using Curve25519 and XChaCha20. Its recovery ecosystem leverages Polygon blockchain for configuration storage, Session network for encrypted communications, and Wasabi file hosting, creating resilient infrastructure resistant to traditional takedown efforts. Multiple groups have deployed DeadLock, including affiliates of Lynx and INC ransomware ecosystems, targeting organization...
Pulse ID: 6a7a12d2aa28d8347ab323f6
Pulse Link: https://otx.alienvault.com/pulse/6a7a12d2aa28d8347ab323f6
Pulse Author: AlienVault
Created: 2026-08-10 18:05:06Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Rust #bot #AlienVault
-
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
DeadLock is an emerging ransomware operation first observed in July 2025, distinguished by its use of decentralized infrastructure combining Session messaging network with blockchain-backed services for victim communications and data leak operations. The encryptor implements double extortion tactics, encrypting files while threatening to leak exfiltrated data, with over 80 organizations published on their leak site as of July 2026. The malware features a resource-aware throttling mechanism to maintain system responsiveness during encryption, language-based geofencing to avoid former Soviet and CIS countries, and hybrid cryptography using Curve25519 and XChaCha20. Its recovery ecosystem leverages Polygon blockchain for configuration storage, Session network for encrypted communications, and Wasabi file hosting, creating resilient infrastructure resistant to traditional takedown efforts. Multiple groups have deployed DeadLock, including affiliates of Lynx and INC ransomware ecosystems, targeting organization...
Pulse ID: 6a7a12d2aa28d8347ab323f6
Pulse Link: https://otx.alienvault.com/pulse/6a7a12d2aa28d8347ab323f6
Pulse Author: AlienVault
Created: 2026-08-10 18:05:06Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Rust #bot #AlienVault
-
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
DeadLock is an emerging ransomware operation first observed in July 2025, distinguished by its use of decentralized infrastructure combining Session messaging network with blockchain-backed services for victim communications and data leak operations. The encryptor implements double extortion tactics, encrypting files while threatening to leak exfiltrated data, with over 80 organizations published on their leak site as of July 2026. The malware features a resource-aware throttling mechanism to maintain system responsiveness during encryption, language-based geofencing to avoid former Soviet and CIS countries, and hybrid cryptography using Curve25519 and XChaCha20. Its recovery ecosystem leverages Polygon blockchain for configuration storage, Session network for encrypted communications, and Wasabi file hosting, creating resilient infrastructure resistant to traditional takedown efforts. Multiple groups have deployed DeadLock, including affiliates of Lynx and INC ransomware ecosystems, targeting organization...
Pulse ID: 6a7a12d2aa28d8347ab323f6
Pulse Link: https://otx.alienvault.com/pulse/6a7a12d2aa28d8347ab323f6
Pulse Author: AlienVault
Created: 2026-08-10 18:05:06Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Rust #bot #AlienVault
-
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
DeadLock is an emerging ransomware operation first observed in July 2025, distinguished by its use of decentralized infrastructure combining Session messaging network with blockchain-backed services for victim communications and data leak operations. The encryptor implements double extortion tactics, encrypting files while threatening to leak exfiltrated data, with over 80 organizations published on their leak site as of July 2026. The malware features a resource-aware throttling mechanism to maintain system responsiveness during encryption, language-based geofencing to avoid former Soviet and CIS countries, and hybrid cryptography using Curve25519 and XChaCha20. Its recovery ecosystem leverages Polygon blockchain for configuration storage, Session network for encrypted communications, and Wasabi file hosting, creating resilient infrastructure resistant to traditional takedown efforts. Multiple groups have deployed DeadLock, including affiliates of Lynx and INC ransomware ecosystems, targeting organization...
Pulse ID: 6a7a12d2aa28d8347ab323f6
Pulse Link: https://otx.alienvault.com/pulse/6a7a12d2aa28d8347ab323f6
Pulse Author: AlienVault
Created: 2026-08-10 18:05:06Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Rust #bot #AlienVault
-
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
DeadLock is an emerging ransomware operation first observed in July 2025, distinguished by its use of decentralized infrastructure combining Session messaging network with blockchain-backed services for victim communications and data leak operations. The encryptor implements double extortion tactics, encrypting files while threatening to leak exfiltrated data, with over 80 organizations published on their leak site as of July 2026. The malware features a resource-aware throttling mechanism to maintain system responsiveness during encryption, language-based geofencing to avoid former Soviet and CIS countries, and hybrid cryptography using Curve25519 and XChaCha20. Its recovery ecosystem leverages Polygon blockchain for configuration storage, Session network for encrypted communications, and Wasabi file hosting, creating resilient infrastructure resistant to traditional takedown efforts. Multiple groups have deployed DeadLock, including affiliates of Lynx and INC ransomware ecosystems, targeting organization...
Pulse ID: 6a7a12d2aa28d8347ab323f6
Pulse Link: https://otx.alienvault.com/pulse/6a7a12d2aa28d8347ab323f6
Pulse Author: AlienVault
Created: 2026-08-10 18:05:06Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Rust #bot #AlienVault
-
BlackFile Rebrand: Google Links Extortion Group to Redact - https://www.redpacketsecurity.com/google-links-redact-extortion-group-to-blackfile-rebrand/
-
BlackFile Rebrand: Google Links Extortion Group to Redact - https://www.redpacketsecurity.com/google-links-redact-extortion-group-to-blackfile-rebrand/
-
BlackFile Rebrand: Google Links Extortion Group to Redact - https://www.redpacketsecurity.com/google-links-redact-extortion-group-to-blackfile-rebrand/
-
BlackFile Rebrand: Google Links Extortion Group to Redact - https://www.redpacketsecurity.com/google-links-redact-extortion-group-to-blackfile-rebrand/
-
BlackFile Rebrand: Google Links Extortion Group to Redact - https://www.redpacketsecurity.com/google-links-redact-extortion-group-to-blackfile-rebrand/
-
CW: NSFW, GenAI
“Non-canonical Enodia Adventure”
#bigboobs #bigbreasts #boobs #breasts #caption #chastity #cleavage #chastitycage #chastitydevice #chastitycaption #chastityslave #enodia #meta #noncanonical #elseworlds #latex #latexbodysuit #bodysuit #frombehind #buttcheeks #latexbutt #latexcatsuit #catsuit #extortion #backfire #femdom #femaledomination #dominantwoman #mistress #domination
-
CW: NSFW, GenAI
“Non-canonical Enodia Adventure”
#bigboobs #bigbreasts #boobs #breasts #caption #chastity #cleavage #chastitycage #chastitydevice #chastitycaption #chastityslave #enodia #meta #noncanonical #elseworlds #latex #latexbodysuit #bodysuit #frombehind #buttcheeks #latexbutt #latexcatsuit #catsuit #extortion #backfire #femdom #femaledomination #dominantwoman #mistress #domination
-
CW: NSFW, GenAI
“Non-canonical Enodia Adventure”
#bigboobs #bigbreasts #boobs #breasts #caption #chastity #cleavage #chastitycage #chastitydevice #chastitycaption #chastityslave #enodia #meta #noncanonical #elseworlds #latex #latexbodysuit #bodysuit #frombehind #buttcheeks #latexbutt #latexcatsuit #catsuit #extortion #backfire #femdom #femaledomination #dominantwoman #mistress #domination
-
CW: NSFW, GenAI
“Non-canonical Enodia Adventure”
#bigboobs #bigbreasts #boobs #breasts #caption #chastity #cleavage #chastitycage #chastitydevice #chastitycaption #chastityslave #enodia #meta #noncanonical #elseworlds #latex #latexbodysuit #bodysuit #frombehind #buttcheeks #latexbutt #latexcatsuit #catsuit #extortion #backfire #femdom #femaledomination #dominantwoman #mistress #domination
-
Interlock Ransomware Abuses Forensic Tools for Credential Theft
Interlock ransomware uses ClickFix social engineering and legitimate
forensic tools to compromise networks. Attackers abuse Volatility3 and
WinPmem for credential theft perform Kerberoasting, establish
persistence, move laterally, exfiltrate data and deploy ransomware for
double extortion.Pulse ID: 6a79c66917a813aade9856bf
Pulse Link: https://otx.alienvault.com/pulse/6a79c66917a813aade9856bf
Pulse Author: cryptocti
Created: 2026-08-10 12:39:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Extortion #InfoSec #NPM #OTX #OpenThreatExchange #RAT #RansomWare #SocialEngineering #bot #cryptocti
-
Interlock Ransomware Abuses Forensic Tools for Credential Theft
Interlock ransomware uses ClickFix social engineering and legitimate
forensic tools to compromise networks. Attackers abuse Volatility3 and
WinPmem for credential theft perform Kerberoasting, establish
persistence, move laterally, exfiltrate data and deploy ransomware for
double extortion.Pulse ID: 6a79c66917a813aade9856bf
Pulse Link: https://otx.alienvault.com/pulse/6a79c66917a813aade9856bf
Pulse Author: cryptocti
Created: 2026-08-10 12:39:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Extortion #InfoSec #NPM #OTX #OpenThreatExchange #RAT #RansomWare #SocialEngineering #bot #cryptocti
-
Interlock Ransomware Abuses Forensic Tools for Credential Theft
Interlock ransomware uses ClickFix social engineering and legitimate
forensic tools to compromise networks. Attackers abuse Volatility3 and
WinPmem for credential theft perform Kerberoasting, establish
persistence, move laterally, exfiltrate data and deploy ransomware for
double extortion.Pulse ID: 6a79c66917a813aade9856bf
Pulse Link: https://otx.alienvault.com/pulse/6a79c66917a813aade9856bf
Pulse Author: cryptocti
Created: 2026-08-10 12:39:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Extortion #InfoSec #NPM #OTX #OpenThreatExchange #RAT #RansomWare #SocialEngineering #bot #cryptocti
-
Interlock Ransomware Abuses Forensic Tools for Credential Theft
Interlock ransomware uses ClickFix social engineering and legitimate
forensic tools to compromise networks. Attackers abuse Volatility3 and
WinPmem for credential theft perform Kerberoasting, establish
persistence, move laterally, exfiltrate data and deploy ransomware for
double extortion.Pulse ID: 6a79c66917a813aade9856bf
Pulse Link: https://otx.alienvault.com/pulse/6a79c66917a813aade9856bf
Pulse Author: cryptocti
Created: 2026-08-10 12:39:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Extortion #InfoSec #NPM #OTX #OpenThreatExchange #RAT #RansomWare #SocialEngineering #bot #cryptocti
-
Interlock Ransomware Abuses Forensic Tools for Credential Theft
Interlock ransomware uses ClickFix social engineering and legitimate
forensic tools to compromise networks. Attackers abuse Volatility3 and
WinPmem for credential theft perform Kerberoasting, establish
persistence, move laterally, exfiltrate data and deploy ransomware for
double extortion.Pulse ID: 6a79c66917a813aade9856bf
Pulse Link: https://otx.alienvault.com/pulse/6a79c66917a813aade9856bf
Pulse Author: cryptocti
Created: 2026-08-10 12:39:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Extortion #InfoSec #NPM #OTX #OpenThreatExchange #RAT #RansomWare #SocialEngineering #bot #cryptocti
-
Spirals: New Stealthy Ransomware Deployed Against Asian IT Company
Indicators extracted from public reporting. Source: https://www.security.com/threat-intelligence/ransomware-spirals-extortion
Pulse ID: 6a79ac894a4507cbc3e19322
Pulse Link: https://otx.alienvault.com/pulse/6a79ac894a4507cbc3e19322
Pulse Author: CyberHunter_NL
Created: 2026-08-10 10:48:41Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CyberSecurity #Extortion #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #RansomWare #bot #CyberHunter_NL
-
Spirals: New Stealthy Ransomware Deployed Against Asian IT Company
Indicators extracted from public reporting. Source: https://www.security.com/threat-intelligence/ransomware-spirals-extortion
Pulse ID: 6a79ac894a4507cbc3e19322
Pulse Link: https://otx.alienvault.com/pulse/6a79ac894a4507cbc3e19322
Pulse Author: CyberHunter_NL
Created: 2026-08-10 10:48:41Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CyberSecurity #Extortion #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #RansomWare #bot #CyberHunter_NL
-
Spirals: New Stealthy Ransomware Deployed Against Asian IT Company
Indicators extracted from public reporting. Source: https://www.security.com/threat-intelligence/ransomware-spirals-extortion
Pulse ID: 6a79ac894a4507cbc3e19322
Pulse Link: https://otx.alienvault.com/pulse/6a79ac894a4507cbc3e19322
Pulse Author: CyberHunter_NL
Created: 2026-08-10 10:48:41Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CyberSecurity #Extortion #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #RansomWare #bot #CyberHunter_NL
-
Spirals: New Stealthy Ransomware Deployed Against Asian IT Company
Indicators extracted from public reporting. Source: https://www.security.com/threat-intelligence/ransomware-spirals-extortion
Pulse ID: 6a79ac894a4507cbc3e19322
Pulse Link: https://otx.alienvault.com/pulse/6a79ac894a4507cbc3e19322
Pulse Author: CyberHunter_NL
Created: 2026-08-10 10:48:41Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CyberSecurity #Extortion #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #RansomWare #bot #CyberHunter_NL
-
Spirals: New Stealthy Ransomware Deployed Against Asian IT Company
Indicators extracted from public reporting. Source: https://www.security.com/threat-intelligence/ransomware-spirals-extortion
Pulse ID: 6a79ac894a4507cbc3e19322
Pulse Link: https://otx.alienvault.com/pulse/6a79ac894a4507cbc3e19322
Pulse Author: CyberHunter_NL
Created: 2026-08-10 10:48:41Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CyberSecurity #Extortion #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #RansomWare #bot #CyberHunter_NL
-
Google Links Redact Extortion Group to BlackFile Rebrand
Indicators extracted from public reporting. Source: https://www.infosecurity-magazine.com/news/redact-extortion-group-blackfile/
Pulse ID: 6a79a07eef5448a6ecac6c64
Pulse Link: https://otx.alienvault.com/pulse/6a79a07eef5448a6ecac6c64
Pulse Author: CyberHunter_NL
Created: 2026-08-10 09:57:18Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Extortion #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
Google Links Redact Extortion Group to BlackFile Rebrand
Indicators extracted from public reporting. Source: https://www.infosecurity-magazine.com/news/redact-extortion-group-blackfile/
Pulse ID: 6a79a07eef5448a6ecac6c64
Pulse Link: https://otx.alienvault.com/pulse/6a79a07eef5448a6ecac6c64
Pulse Author: CyberHunter_NL
Created: 2026-08-10 09:57:18Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Extortion #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
Google Links Redact Extortion Group to BlackFile Rebrand
Indicators extracted from public reporting. Source: https://www.infosecurity-magazine.com/news/redact-extortion-group-blackfile/
Pulse ID: 6a79a07eef5448a6ecac6c64
Pulse Link: https://otx.alienvault.com/pulse/6a79a07eef5448a6ecac6c64
Pulse Author: CyberHunter_NL
Created: 2026-08-10 09:57:18Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Extortion #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
Google Links Redact Extortion Group to BlackFile Rebrand
Indicators extracted from public reporting. Source: https://www.infosecurity-magazine.com/news/redact-extortion-group-blackfile/
Pulse ID: 6a79a07eef5448a6ecac6c64
Pulse Link: https://otx.alienvault.com/pulse/6a79a07eef5448a6ecac6c64
Pulse Author: CyberHunter_NL
Created: 2026-08-10 09:57:18Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Extortion #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
Google Links Redact Extortion Group to BlackFile Rebrand
Indicators extracted from public reporting. Source: https://www.infosecurity-magazine.com/news/redact-extortion-group-blackfile/
Pulse ID: 6a79a07eef5448a6ecac6c64
Pulse Link: https://otx.alienvault.com/pulse/6a79a07eef5448a6ecac6c64
Pulse Author: CyberHunter_NL
Created: 2026-08-10 09:57:18Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Extortion #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
Pulse ID: 6a7951b6bfc33f720a4723ea
Pulse Link: https://otx.alienvault.com/pulse/6a7951b6bfc33f720a4723ea
Pulse Author: Tr1sa111
Created: 2026-08-10 04:21:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #Extortion #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111
-
Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
Pulse ID: 6a7951b6bfc33f720a4723ea
Pulse Link: https://otx.alienvault.com/pulse/6a7951b6bfc33f720a4723ea
Pulse Author: Tr1sa111
Created: 2026-08-10 04:21:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #Extortion #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111
-
Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
Pulse ID: 6a7951b6bfc33f720a4723ea
Pulse Link: https://otx.alienvault.com/pulse/6a7951b6bfc33f720a4723ea
Pulse Author: Tr1sa111
Created: 2026-08-10 04:21:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #Extortion #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111
-
Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
Pulse ID: 6a7951b6bfc33f720a4723ea
Pulse Link: https://otx.alienvault.com/pulse/6a7951b6bfc33f720a4723ea
Pulse Author: Tr1sa111
Created: 2026-08-10 04:21:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #Extortion #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111
-
Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
Pulse ID: 6a7951b6bfc33f720a4723ea
Pulse Link: https://otx.alienvault.com/pulse/6a7951b6bfc33f720a4723ea
Pulse Author: Tr1sa111
Created: 2026-08-10 04:21:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #Extortion #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111
-
https://www.europesays.com/iran/242000/ Former Iraqi MP al-Sayyadi rejects arrest warrant reports – Shafaq News #AntiCorruption #ArrestWarrant #breaking #Extortion #FormerIraqiMPAlSayyadiRejectsArrestWarrantReports #Iraq #KadhimAlSayyadi
-
https://www.europesays.com/africa/369381/ Monitor shows gang extortion spreading beyond Cape Town #AlanWinde #bacsa #BusinessAgainstCrime #CapeTown #Crime #Extortion #GiToc #GlobalInitiativeAgainstTransnationalOrganisedCrime #HubertPaulse #SouthAfrica #WesternCape
-
Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...
Pulse ID: 6a75078f7b8e057bc29b8769
Pulse Link: https://otx.alienvault.com/pulse/6a75078f7b8e057bc29b8769
Pulse Author: AlienVault
Created: 2026-08-06 22:15:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #BitCoin #Cloud #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RAT #RCE #bot #AlienVault
-
Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...
Pulse ID: 6a75078f7b8e057bc29b8769
Pulse Link: https://otx.alienvault.com/pulse/6a75078f7b8e057bc29b8769
Pulse Author: AlienVault
Created: 2026-08-06 22:15:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #BitCoin #Cloud #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RAT #RCE #bot #AlienVault
-
Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...
Pulse ID: 6a75078f7b8e057bc29b8769
Pulse Link: https://otx.alienvault.com/pulse/6a75078f7b8e057bc29b8769
Pulse Author: AlienVault
Created: 2026-08-06 22:15:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #BitCoin #Cloud #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RAT #RCE #bot #AlienVault
-
Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...
Pulse ID: 6a75078f7b8e057bc29b8769
Pulse Link: https://otx.alienvault.com/pulse/6a75078f7b8e057bc29b8769
Pulse Author: AlienVault
Created: 2026-08-06 22:15:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #BitCoin #Cloud #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RAT #RCE #bot #AlienVault
-
Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...
Pulse ID: 6a75078f7b8e057bc29b8769
Pulse Link: https://otx.alienvault.com/pulse/6a75078f7b8e057bc29b8769
Pulse Author: AlienVault
Created: 2026-08-06 22:15:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #BitCoin #Cloud #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Microsoft #OTX #OpenThreatExchange #Phishing #RAT #RCE #bot #AlienVault
-
Snowflake Extortion Campaign: Canadian Hacker Pleads Guilty in US Court - https://www.redpacketsecurity.com/canadian-hacker-pleads-guilty-over-snowflake-extortion-campaign/
-
Snowflake Extortion Campaign: Canadian Hacker Pleads Guilty in US Court - https://www.redpacketsecurity.com/canadian-hacker-pleads-guilty-over-snowflake-extortion-campaign/
-
Snowflake Extortion Campaign: Canadian Hacker Pleads Guilty in US Court - https://www.redpacketsecurity.com/canadian-hacker-pleads-guilty-over-snowflake-extortion-campaign/
-
Snowflake Extortion Campaign: Canadian Hacker Pleads Guilty in US Court - https://www.redpacketsecurity.com/canadian-hacker-pleads-guilty-over-snowflake-extortion-campaign/