TropChaud · @IntelScott
82 followers · 13 posts · Server infosec.exchange

Analyzing overlap for nine top

This originates from analysis of ransomware targeting schools, but most of these families have threatened a range of critical infrastructure & other industries too

Each ransomware covered here has published extortion threats involving a school or university during the past year, and this trend is increasing. I tallied 66 ransomware extortion threats against these entities since last October. A few groups dominate (see pie chart), and victim count jumped especially high in recent months for schools (K-12) (see bar chart).

The covered here (and count of associated extortion threats against education entities) are: (25), (8), 3.0 (7), / (6), LockBit 2.0 (5), (4), (3), , Snatch (2), & , , Sabbath, and Stormous (1 each). Also / , which is used by Vice Society, but no relevant posts were observed.

Visual summary of my analysis: app.tidalcyber.com/share/8d9f2

Overall the nine ransomware map to 131 unique techniques total, sourced from 30 recent public reports, mainly malware analysis & government advisories ("Show only labelled techniques" gives the best view). The underlines & numbers in the cells indicate number of malware mapped to that technique. Background color gradient represents number of sources referencing it. This tool helps with pivoting to defenses and analytics (think Sigma rules), offensive tests (Atomic Red Team), and data sources (make sure you have proper logging enabled) mapped to the same techniques.

#ttp #ransomware #education #malware #vicesociety #pysa #lockbit #ALPHV #blackcat #hive #bianlian #quantum #Conti #revil #hellokitty #FiveHands #threatintel #sharedwithtidal

Last updated 2 years ago

The infosec team at are tracking a targeting ®. Dubbed ChaChi; the RAT has been used by ransomware gang as part of their toolset to attack victims globally, but most recently targeting education organizations.

blogs.blackberry.com/en/2021/0

#pysa #window #rat #Blackberry

Last updated 4 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online

Data stolen from Hackney Council posted on dark web by ransomware gang - The cybercrime gang behind the PYSA ransomware has released files which they claim to have stolen ... grahamcluley.com/data-stolen-f

#pysa #hackney #malware #dataloss #mespinoza #databreach #ransomware

Last updated 4 years ago