Chester Wisniewski · @chetwisniewski
738 followers · 478 posts · Server securitycafe.ca

If the FBI and Europol had infiltrated Hive in July, why was the takedown now? Sure, they intercepted encryption keys, but they allowed hundreds of orgs to be victimized costing untold millions of dollars in damages. Combined with the lack of arrests, can it be justified as having been worth it in the end?

#infosec #hiveransomware

Last updated 2 years ago

Geekmaster ๐Ÿ‘ฝ:system76: · @Geekmaster
136 followers · 1033 posts · Server ioc.exchange

Woke up to some interesting news today. It would appear that the Gang has been taken down. scmagazine.com/analysis/ransom

I checked around some forums, and it would appear this actually happened in a joint, international effort. The claims to have "hacked the hackers", took down their site, and have apparently 1500 companies. If it sticks, this is a big win for the . Bye bye !

#hiveransomware #darkweb #usdoj #tor #decrypted #goodguys #hive

Last updated 2 years ago

DarkWebMallCop · @DarkWebMallCop
10 followers · 66 posts · Server infosec.exchange

Good morning whats all this then

#hiveransomware #ransomware

Last updated 2 years ago

Metacurity · @metacurity
1343 followers · 1614 posts · Server infosec.exchange
Geekmaster ๐Ÿ‘ฝ · @Geekmaster
68 followers · 397 posts · Server ioc.exchange

I have been seeing A LOT of verified compromises circulating hacker forums because of , , , , , , , , - I'm talking multiple terabytes of data, hundreds of millions of account details, across pretty much every single sector. Most common method of infection? ! Be super mindful of the links you click on, the attachments you download, and the sites you visit

#blackcat #lockbit #hiveransomware #Mallox #blackbasta #royalransomware #bianlian #cubaransomware #bloodyransomwaregang #RANSOMEXX #Businessemailcompromise

Last updated 2 years ago

Colin Cowie · @th3_protoCOL
469 followers · 82 posts · Server infosec.exchange

Additional coverage and attribution to ๐Ÿ‘‡โ€‹
SentinelOne: sentinelone.com/labs/driving-t

Mandiant: mandiant.com/resources/blog/hu

S1 observed "deployment of Hive ransomware against a target in the medical industry" :blobcatnotlikethis:โ€‹

#hiveransomware

Last updated 2 years ago

Daru003 · @daru003
29 followers · 76 posts · Server infosec.exchange

advisory with @FBI and @HHSGov that provides technical details and on being ๐Ÿ‘‡๐Ÿพ

cisa.gov/uscert/sites/default/

#cisa #iocs #hiveransomware

Last updated 2 years ago

Geekmaster · @Geekmaster
15 followers · 39 posts · Server ioc.exchange

Since this an @ioc.exchange here's a list TTPs and IOCs from CISA/FBI/HHS for the published today: cisa.gov/uscert/ncas/alerts/aa

#hiveransomware

Last updated 2 years ago

imp0rtp3 · @imp0rtp3
50 followers · 6 posts · Server infosec.exchange

Two new Fully Undetected ESXi samples uploaded to Virustotal:
virustotal.com/gui/file/f3e906
virustotal.com/gui/file/80adf4

Some very nasty string obfuscation.
Procedure is a little different for each string, complicating static signature writing.

#hiveransomware

Last updated 2 years ago