home.social

#rhysidaransomware — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #rhysidaransomware, aggregated by home.social.

fetched live
  1. Rhysida Ransomware: Multi-Tiered Infrastructure and Early Detection Analysis

    Insikt Group unveiled Rhysida's complex infrastructure, comprising typo-squatted domains for SEO poisoning, payload servers, CleanUpLoader C2 infrastructure, and higher-tier components including an admin panel and Zabbix monitoring server. This multi-tiered setup enables early victim identification, averaging 30 days before their appearance on extortion sites. CleanUpLoader, a backdoor associated with Rhysida, is often distributed as fake software installers for popular applications, signed with valid digital certificates. The analysis demonstrates the potential for early ransomware activity detection using network intelligence, applicable to various ransomware groups with detectable infrastructure.

    Pulse ID: 67078d7cebbee66f1979f6d5
    Pulse Link: otx.alienvault.com/pulse/67078
    Pulse Author: AlienVault
    Created: 2024-10-10 08:17:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Rhysida #RhysidaRansomware #SEOPoisoning #bot #AlienVault

  2. Another medical ransomware situation where the thieves are selling people's information to highest bidder.
    #RhysidaRansomware wants $3.6 million for children’s stolen data
    bleepingcomputer.com/news/secu

  3. Another medical ransomware situation where the thieves are selling people's information to highest bidder.
    #RhysidaRansomware wants $3.6 million for children’s stolen data
    bleepingcomputer.com/news/secu

  4. Another medical ransomware situation where the thieves are selling people's information to highest bidder.
    #RhysidaRansomware wants $3.6 million for children’s stolen data
    bleepingcomputer.com/news/secu

  5. Another medical ransomware situation where the thieves are selling people's information to highest bidder.
    #RhysidaRansomware wants $3.6 million for children’s stolen data
    bleepingcomputer.com/news/secu

  6. Rhysida Ransomware Attacking Windows Machines

    Pulse ID: 655dee07111a736cf120fc0f
    Pulse Link: otx.alienvault.com/pulse/655de
    Pulse Author: cryptocti
    Created: 2023-11-22 12:03:19

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #RansomWare #Windows #Rhysida #RhysidaRansomware #cryptocti

  7. Investigating the New Rhysida Ransomware

    The Rhysida Ransomware Group is a new threat that targets the virtual infrastructure of VMware and other virtual systems, according to a report from FortiGuard Labs and the PSIRT Collective.

    Pulse ID: 655b37f8107caf1f475259e5
    Pulse Link: otx.alienvault.com/pulse/655b3
    Pulse Author: AlienVault
    Created: 2023-11-20 10:41:59

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #RansomWare #Rhysida #RhysidaRansomware #AlienVault

  8. Rhysida Ransomware Double Extortion Attacks

    Pulse ID: 655747ec81281c0bc848c9c7
    Pulse Link: otx.alienvault.com/pulse/65574
    Pulse Author: cryptocti
    Created: 2023-11-17 11:01:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #RansomWare #Rhysida #RhysidaRansomware #Extortion #cryptocti

  9. #StopRansomware: Rhysida Ransomware

    Threat actors leveraging Rhysida ransomware are known to impact “targets of opportunity,” including victims in the education, healthcare, manufacturing, information technology, and government sectors. Open source reporting details similarities between Vice Society (DEV-0832)[1] activity and the actors observed deploying Rhysida ransomware.

    Pulse ID: 655537ff05840a2a8d7b3d3d
    Pulse Link: otx.alienvault.com/pulse/65553
    Pulse Author: AlienVault
    Created: 2023-11-15 21:28:31

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #RansomWare #government #Rce #Rhysida #RhysidaRansomware #AlienVault