home.social

#sophosxops — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #sophosxops, aggregated by home.social.

fetched live
  1. A year ago, Sophos X-Ops published our research into threat actor attitudes towards AI. We went into the underground forums to see what they were saying about AI.
    At the time, we found threat actors were skeptical, grappling with the same issues, problems, and concerns everyone was.
    A year later, we've returned to see what, if anything has changed. Overall, we've seen a slight shift, but the song remains the same overall: skeptical.
    Get more details in our latest report here:

    news.sophos.com/en-us/2025/01/
    #sophosxops #threatintel #ai

  2. A year ago, Sophos X-Ops published our research into threat actor attitudes towards AI. We went into the underground forums to see what they were saying about AI.
    At the time, we found threat actors were skeptical, grappling with the same issues, problems, and concerns everyone was.
    A year later, we've returned to see what, if anything has changed. Overall, we've seen a slight shift, but the song remains the same overall: skeptical.
    Get more details in our latest report here:

    news.sophos.com/en-us/2025/01/
    #sophosxops #threatintel #ai

  3. A year ago, Sophos X-Ops published our research into threat actor attitudes towards AI. We went into the underground forums to see what they were saying about AI.
    At the time, we found threat actors were skeptical, grappling with the same issues, problems, and concerns everyone was.
    A year later, we've returned to see what, if anything has changed. Overall, we've seen a slight shift, but the song remains the same overall: skeptical.
    Get more details in our latest report here:

    news.sophos.com/en-us/2025/01/
    #sophosxops #threatintel #ai

  4. A year ago, Sophos X-Ops published our research into threat actor attitudes towards AI. We went into the underground forums to see what they were saying about AI.
    At the time, we found threat actors were skeptical, grappling with the same issues, problems, and concerns everyone was.
    A year later, we've returned to see what, if anything has changed. Overall, we've seen a slight shift, but the song remains the same overall: skeptical.
    Get more details in our latest report here:

    news.sophos.com/en-us/2025/01/
    #sophosxops #threatintel #ai

  5. Additionally, case data reveals a 3-week delay before Akira posts victim information on their leaksite. Research indicates 127 victims have been posted to their leak site over the last 6 months. Sophos X-Ops is tracking 2 active Akira threat clusters (STAC5881, STAC5397), with the STAC5397 also deploying Fog ransomware. We commonly observe them leveraging PsExec, Advanced IP Scanner, SoftPerfect Network Scanner, 7-zip, Rclone, AnyDesk, WinRAR, WInSCP and Filezilla software during intrusions.#Akira #ransomware #threatintel #Sophosxops

  6. Additionally, case data reveals a 3-week delay before Akira posts victim information on their leaksite. Research indicates 127 victims have been posted to their leak site over the last 6 months. Sophos X-Ops is tracking 2 active Akira threat clusters (STAC5881, STAC5397), with the STAC5397 also deploying Fog ransomware. We commonly observe them leveraging PsExec, Advanced IP Scanner, SoftPerfect Network Scanner, 7-zip, Rclone, AnyDesk, WinRAR, WInSCP and Filezilla software during intrusions.#Akira #ransomware #threatintel #Sophosxops

  7. Additionally, case data reveals a 3-week delay before Akira posts victim information on their leaksite. Research indicates 127 victims have been posted to their leak site over the last 6 months. Sophos X-Ops is tracking 2 active Akira threat clusters (STAC5881, STAC5397), with the STAC5397 also deploying Fog ransomware. We commonly observe them leveraging PsExec, Advanced IP Scanner, SoftPerfect Network Scanner, 7-zip, Rclone, AnyDesk, WinRAR, WInSCP and Filezilla software during intrusions.#Akira #ransomware #threatintel #Sophosxops

  8. Additionally, case data reveals a 3-week delay before Akira posts victim information on their leaksite. Research indicates 127 victims have been posted to their leak site over the last 6 months. Sophos X-Ops is tracking 2 active Akira threat clusters (STAC5881, STAC5397), with the STAC5397 also deploying Fog ransomware. We commonly observe them leveraging PsExec, Advanced IP Scanner, SoftPerfect Network Scanner, 7-zip, Rclone, AnyDesk, WinRAR, WInSCP and Filezilla software during intrusions.#Akira #ransomware #threatintel #Sophosxops

  9. Sophos X-Ops has just released a brand-new Active Adversary Report, covering the first six months of 2024 – a little light holiday reading, as one does. For the first time ever, data from MDR's customer-facing Incident Response team is fully incorporated with data from our dedicated Incident Response team. The result is our largest dataset ever, with 190 entries normalized across 63 fields.

    Perhaps the most startling finding of all is that abuse of LOLbins was up, way up, in the first half of the year. The AAR analysis team thought it might be a hallucination brought on by ingesting all that MDR data but... it isn't. The report has details, including what (besides RDP) is getting a workout. (Spoiler: You name it. Some of these attackers are just odd.)

    We worked on a great number of ransomware cases in 1H24, as you'd expect. What you might not expect is which ransomware brands were most often involved, especially if you follow the headlines about high-profile law-enforcement activities. The new report looks at how the scene shaped up after the February 2024 LockBit takedown and points out a data pattern that you might not have glimpsed in the usual day-to-day news coverage.

    Finally, as AAR stands on the cusp of its sixth year of data (the first AAR was published in 2021, covering 2020 and the then-new IR team), we revisited some of our older investigations -- dwell time, time-to-Active-Directory, and many more. Updated information on these topics and many more is in the report. Enjoy!

    news.sophos.com/en-us/2024/12/

    #threatintel #Sophosxops

  10. Sophos X-Ops has just released a brand-new Active Adversary Report, covering the first six months of 2024 – a little light holiday reading, as one does. For the first time ever, data from MDR's customer-facing Incident Response team is fully incorporated with data from our dedicated Incident Response team. The result is our largest dataset ever, with 190 entries normalized across 63 fields.

    Perhaps the most startling finding of all is that abuse of LOLbins was up, way up, in the first half of the year. The AAR analysis team thought it might be a hallucination brought on by ingesting all that MDR data but... it isn't. The report has details, including what (besides RDP) is getting a workout. (Spoiler: You name it. Some of these attackers are just odd.)

    We worked on a great number of ransomware cases in 1H24, as you'd expect. What you might not expect is which ransomware brands were most often involved, especially if you follow the headlines about high-profile law-enforcement activities. The new report looks at how the scene shaped up after the February 2024 LockBit takedown and points out a data pattern that you might not have glimpsed in the usual day-to-day news coverage.

    Finally, as AAR stands on the cusp of its sixth year of data (the first AAR was published in 2021, covering 2020 and the then-new IR team), we revisited some of our older investigations -- dwell time, time-to-Active-Directory, and many more. Updated information on these topics and many more is in the report. Enjoy!

    news.sophos.com/en-us/2024/12/

    #threatintel #Sophosxops

  11. Sophos X-Ops has just released a brand-new Active Adversary Report, covering the first six months of 2024 – a little light holiday reading, as one does. For the first time ever, data from MDR's customer-facing Incident Response team is fully incorporated with data from our dedicated Incident Response team. The result is our largest dataset ever, with 190 entries normalized across 63 fields.

    Perhaps the most startling finding of all is that abuse of LOLbins was up, way up, in the first half of the year. The AAR analysis team thought it might be a hallucination brought on by ingesting all that MDR data but... it isn't. The report has details, including what (besides RDP) is getting a workout. (Spoiler: You name it. Some of these attackers are just odd.)

    We worked on a great number of ransomware cases in 1H24, as you'd expect. What you might not expect is which ransomware brands were most often involved, especially if you follow the headlines about high-profile law-enforcement activities. The new report looks at how the scene shaped up after the February 2024 LockBit takedown and points out a data pattern that you might not have glimpsed in the usual day-to-day news coverage.

    Finally, as AAR stands on the cusp of its sixth year of data (the first AAR was published in 2021, covering 2020 and the then-new IR team), we revisited some of our older investigations -- dwell time, time-to-Active-Directory, and many more. Updated information on these topics and many more is in the report. Enjoy!

    news.sophos.com/en-us/2024/12/

    #threatintel #Sophosxops

  12. Sophos X-Ops has just released a brand-new Active Adversary Report, covering the first six months of 2024 – a little light holiday reading, as one does. For the first time ever, data from MDR's customer-facing Incident Response team is fully incorporated with data from our dedicated Incident Response team. The result is our largest dataset ever, with 190 entries normalized across 63 fields.

    Perhaps the most startling finding of all is that abuse of LOLbins was up, way up, in the first half of the year. The AAR analysis team thought it might be a hallucination brought on by ingesting all that MDR data but... it isn't. The report has details, including what (besides RDP) is getting a workout. (Spoiler: You name it. Some of these attackers are just odd.)

    We worked on a great number of ransomware cases in 1H24, as you'd expect. What you might not expect is which ransomware brands were most often involved, especially if you follow the headlines about high-profile law-enforcement activities. The new report looks at how the scene shaped up after the February 2024 LockBit takedown and points out a data pattern that you might not have glimpsed in the usual day-to-day news coverage.

    Finally, as AAR stands on the cusp of its sixth year of data (the first AAR was published in 2021, covering 2020 and the then-new IR team), we revisited some of our older investigations -- dwell time, time-to-Active-Directory, and many more. Updated information on these topics and many more is in the report. Enjoy!

    news.sophos.com/en-us/2024/12/

    #threatintel #Sophosxops

  13. Sophos X-Ops teams are monitoring and responding to attacks against Cleo products VLTrader, Harmony, and LexiCom prior to version 5.8.0.23 in each as outlined in this advisory: support.cleo.com/hc/en-us/arti.

    Sophos MDR and Labs teams can confirm seeing 50+ unique hosts targeted by these attacks at this time.

    All observed impacted customers have a branch or operate within the North Americas, primarily the US. We note the majority of observed affected customers are retail organizations.

    Sophos MDR threat hunting currently shows the first attack on 2024-12-06 at 17:47 UTC.

    We will continue to monitor and provide updates as we have more information.

    #Sophosxops #threatintel

  14. Sophos X-Ops teams are monitoring and responding to attacks against Cleo products VLTrader, Harmony, and LexiCom prior to version 5.8.0.23 in each as outlined in this advisory: support.cleo.com/hc/en-us/arti.

    Sophos MDR and Labs teams can confirm seeing 50+ unique hosts targeted by these attacks at this time.

    All observed impacted customers have a branch or operate within the North Americas, primarily the US. We note the majority of observed affected customers are retail organizations.

    Sophos MDR threat hunting currently shows the first attack on 2024-12-06 at 17:47 UTC.

    We will continue to monitor and provide updates as we have more information.

    #Sophosxops #threatintel

  15. Sophos X-Ops teams are monitoring and responding to attacks against Cleo products VLTrader, Harmony, and LexiCom prior to version 5.8.0.23 in each as outlined in this advisory: support.cleo.com/hc/en-us/arti.

    Sophos MDR and Labs teams can confirm seeing 50+ unique hosts targeted by these attacks at this time.

    All observed impacted customers have a branch or operate within the North Americas, primarily the US. We note the majority of observed affected customers are retail organizations.

    Sophos MDR threat hunting currently shows the first attack on 2024-12-06 at 17:47 UTC.

    We will continue to monitor and provide updates as we have more information.

    #Sophosxops #threatintel

  16. Sophos X-Ops teams are monitoring and responding to attacks against Cleo products VLTrader, Harmony, and LexiCom prior to version 5.8.0.23 in each as outlined in this advisory: support.cleo.com/hc/en-us/arti.

    Sophos MDR and Labs teams can confirm seeing 50+ unique hosts targeted by these attacks at this time.

    All observed impacted customers have a branch or operate within the North Americas, primarily the US. We note the majority of observed affected customers are retail organizations.

    Sophos MDR threat hunting currently shows the first attack on 2024-12-06 at 17:47 UTC.

    We will continue to monitor and provide updates as we have more information.

    #Sophosxops #threatintel