Identified a Python-based backdoor used by RansomHub affiliate to spread encryptors
In a recent incident response analysis, GuidePoint Security has uncovered a sophisticated use of a Python-based backdoor by a threat actor affiliated with RansomHub. This development highlights a...
Ransomware claims surge: Akira and RansomHub lead the charge
As ransomware incidents reach unprecedented levels, these groups have gained notoriety for their aggressive tactics and increasing effectiveness in targeting organizations. Ransomware Claims Surge: Akira and RansomHub Lead...
Kawasaki Europe hit by cyberattack, RansomHub group demands ransom
Kawasaki Motors Europe (KME) has confirmed a cyberattack in early September that resulted in disruptions to its operations. While the attack was initially reported as “unsuccessful,” the company...
RansomHub’s malicious use of TDSSKiller to bypass endpoint detection and response (EDR)
Kaspersky Lab’s TDSSKiller is a widely used free utility for detecting and removing rootkits. However, a recent cyberattack campaign by the RansomHub ransomware gang has leveraged TDSSKiller to...