#RansomwareAsAService

2025-05-20

SAP Zero – Frostbite: How Russian RaaS Actor Qilin Exploited CVE-2025-31324 Weeks Before its Public Disclosure

CVE-2025-31324 hit the security world like a tsunami – an easily exploitable SAP vulnerability affecting enterprise environments across the globe. But while most assumed its exploitation began post-disclosure, new evidence suggests otherwise.
During an incident response led by OP Innovate for a major global enterprise, we uncovered proof that this vulnerability was actively exploited nearly three weeks before it was made public. While recent articles point the finger towards China-Linked APTs, we identified communication with known Cobalt Strike C2 infrastructure and IP addresses linked directly to Qilin, a notorious Russian-speaking Ransomware-as-a-Service group.

Pulse ID: 682cc36c603a5683307d027d
Pulse Link: otx.alienvault.com/pulse/682cc
Pulse Author: AlienVault
Created: 2025-05-20 18:01:16

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#China #CobaltStrike #CyberSecurity #InfoSec #OTX #OpenThreatExchange #RaaS #RansomWare #RansomwareAsAService #Russia #Vulnerability #bot #AlienVault

2025-04-09

For the latest discoveries in cyber research for the week of 24th March, please check our Threat Intelligence Report:

research.checkpoint.com/2025/2

#CyberSecurity #Ransomware #ransomwareasaservice #vulnerability #patches

gtbarrygtbarry
2023-04-28

How LockBit Changed Cybersecurity Forever

LockBit put affiliates in charge of negotiations and payments. By doing so, trust was established and the fear of being swindled was removed. This shift, coupled with an improved ransomware product, made LockBit the preferred choice - the group is now responsible for almost half of all ransomware attacks worldwide

securityintelligence.com/artic

2023-01-27

#RansomwareAsAService
#Hive

U.S. Department of Justice Disrupts Hive Ransomware Variant

FBI Covertly Infiltrated Hive Network, Thwarting Over $130 Million in Ransom Demands

justice.gov/opa/pr/us-departme

Cybercrime: Polizei zerschlägt Ransomware-Gruppe "Hive"
von Volker Briegleb

heise.de/news/Cybercrime-Poliz

2023-01-27

#RansomwareAsAService
#Hive

U.S. Department of Justice Disrupts Hive Ransomware Variant

FBI Covertly Infiltrated Hive Network, Thwarting Over $130 Million in Ransom Demands

justice.gov/opa/pr/us-departme

Cybercrime: Polizei zerschlägt Ransomware-Gruppe "Hive"
von Volker Briegleb

heise.de/news/Cybercrime-Poliz

heise online (inoffiziell)heiseonline@squeet.me
2022-09-05
Trend Micro sieht im ersten Halbjahr 2022 ein Wachstum bei Ransomware-Angriffen. Linux-Umgebungen sind 75 Prozent häufiger ein Ziel als im Vorjahreszeitraum.
Ransomware: Der Trend geht zum Angriff auf Linux-Server
heise online (inoffiziell)heiseonline@squeet.me
2022-05-24
Die "zerstörerischste Ransomware" soll verschwinden; der Angriff auf Costa Rica ist offenbar nur das Grande Finale. Doch im Hintergrund wird weiter erpresst.
Cybercrime: Ransomware-Gruppe Conti löst sich auf und erfindet sich neu
heise online (inoffiziell)heiseonline@squeet.me
2022-03-01
Nachdem die Cybergang Conti sich im Ukraine-Konflikt auf russische Seite stellte, veröffentlichte ein Mitglied interne Chats und Daten der vergangenen Jahre.
Cybergang Conti: Interne Daten geleakt - 2,8 Milliarden US-Dollar erbeutet

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst