Pay2Key, gruppo legato all'Iran, è riemerso e ha cifrato l'infrastruttura di un provider sanitario statunitense. I ricercatori dicono che gli attori hanno raccolto credenziali e usato tattiche focalizzate su Active Directory per muoversi lateralmente, completando la cifratura in circa tre ore. Separatamente, il gruppo pro‑ucraino Bearlyfy ha condotto oltre 70 attacchi contro aziende russe e ora impiega un ransomware Windows custom chiamato GenieLocker per chiedere riscatti maggiori.
Pro-Ukraine hacker group Bearlyfy targets Russian companies with custom ransomware
A pro-Ukrainian hacker group known as Bearlyfy has carried out more than 70 cyberattacks against Russian companies over the past year and is now escalating its campaign with newly developed ransomware tools, researchers have found.