Pay2Key legato all'Iran cifra sistemi di provider sanitario USA
Il gruppo Pay2Key, riconducibile all'Iran, ha cifrato sistemi presso un provider sanitario statunitense. Gli attori hanno usato credenziali rubate, TeamViewer e un installer 7zip SFX per cifrare l'infrastruttura in circa tre ore. Hanno deployato e poi rimosso un toolkit di evasione; le indagini non hanno trovato prove di esfiltrazione dati.
Pro-Ukraine hacker group Bearlyfy targets Russian companies with custom ransomware
A pro-Ukrainian hacker group known as Bearlyfy has carried out more than 70 cyberattacks against Russian companies over the past year and is now escalating its campaign with newly developed ransomware tools, researchers have found.