📱 Midnight, hĂ©ritier de Babuk : analyse technique et guide de dĂ©chiffrement
📝 Selon un billet de blog technique publiĂ© le 8 novembre 2025, l’article explore en profondeur la souche de rançongiciel « Midnight ».
📖 cyberveille : https://cyberveille.ch/posts/2025-11-08-midnight-heritier-de-babuk-analyse-technique-et-guide-de-dechiffrement/
🌐 source : https://www.gendigital.com/blog/insights/research/midnight-ransomware
#Babuk #IOC #Cyberveille
Midnight, héritier de Babuk : analyse technique et guide de déchiffrement

Selon un billet de blog technique publiĂ© le 8 novembre 2025, l’article explore en profondeur la souche de rançongiciel « Midnight ». L’analyse dĂ©taille la « gĂ©nĂ©alogie » de Midnight Ă  partir de Babuk, en dĂ©crivant son anatomie technique et ses caractĂ©ristiques clĂ©s. Elle met l’accent sur les indicateurs critiques d’infection (IOCs) permettant d’identifier une compromission. L’élĂ©ment central de la publication est un guide pratique de dĂ©chiffrement destinĂ© aux victimes, offrant une opportunitĂ© rare de rĂ©cupĂ©rer les donnĂ©es sans verser de rançon. 🔐

CyberVeille

🚹 Velociraptor DFIR exploited in LockBit ransomware attacks.

Huntress and Cisco Talos link Storm-2603 to a new campaign abusing outdated Velociraptor builds for privilege escalation, lateral movement, and ransomware deployment.

The crew reportedly used SharePoint exploits (ToolShell) and domain admin creation before dropping LockBit, Warlock, and Babuk payloads.

💬 Are open-source DFIR tools the next frontier for living-off-the-land tactics?

Full Details:
https://www.technadu.com/qantas-customer-data-was-published-after-the-july-cyber-breach-impacting-5-million-people/611263/

Follow TechNadu for more cutting-edge cyber threat intelligence.

#CyberSecurity #DFIR #Velociraptor #Ransomware #LockBit #Warlock #Babuk #ThreatIntel #Storm2603 #Infosec #IncidentResponse #ThreatHunting #TechNadu #CyberAwareness

🚹 Velociraptor DFIR exploited in LockBit ransomware attacks.

Huntress and Cisco Talos link Storm-2603 to a new campaign abusing outdated Velociraptor builds for privilege escalation, lateral movement, and ransomware deployment.

The crew reportedly used SharePoint exploits (ToolShell) and domain admin creation before dropping LockBit, Warlock, and Babuk payloads.

💬 Are open-source DFIR tools the next frontier for living-off-the-land tactics?

Follow @technadu for more cutting-edge cyber threat intelligence.

#CyberSecurity #DFIR #Velociraptor #Ransomware #LockBit #Warlock #Babuk #ThreatIntel #Storm2603 #Infosec #IncidentResponse #ThreatHunting #TechNadu #CyberAwareness

They’re turning the tables—hackers are hijacking Velociraptor (a tool meant to catch them) to launch sneaky ransomware and double-extortion attacks. Just when you thought defenders had it all figured out, the game has changed.

https://thedefendopsdiaries.com/attackers-weaponize-velociraptor-dfir-tool-in-ransomware-campaigns/

#velociraptor
#ransomware
#dfir
#cve20256264
#cybersecurity
#threatactors
#doubleextortion
#infosec
#lockbit
#babuk

Attackers Weaponize Velociraptor DFIR Tool in Ransomware Campaigns

Attackers exploit a Velociraptor DFIR vulnerability to deploy ransomware, evade detection, and use double-extortion tactics in recent campaigns.

The DefendOps Diaries

HellCat strongly defended the authorship of the attacks, avoiding any ambiguity in credit distribution among its members.
"Am I supposed to prove my attacks? If so, just wait for the deadline to end and download the data—nothing more. We already have a profile."

https://www.suspectfile.com/hellcat-rey-and-grep-internal-dynamics-and-conflicting-claims-in-the-orange-and-highwire-press-cases/

#HellCat #Rey #Babuk #Orange #Infosec #Data_Breach #Ransomware #Lies

Auf ihrer Darknet-Website gab die Babuk-Ransomware-Gruppe bekannt, dass sie angeblich rund 750 GB Daten sowie E-Mail-Zugangsdaten von #Rheinmetall Defence gestohlen hat. Insgesamt soll es sich dabei um 1400 Dateien handeln. Zu den gestohlenen Daten zÀhlen laut #Babuk MilitÀrvertrÀge, E-Mails, GeschÀftstransaktionen des Unternehmens, Details und Bilder von Produkten sowie viele weitere Informationen.

Weitere Infos und Screenshots gibt es hier:
https://teufelswerk.net/die-babuk-ransomware-gruppe-hat-heute-im-darknet-bekanntgegeben-dass-sie-rheinmetall-defence-gehackt-hat/

Die Babuk Ransomware Gruppe gab heute im Darknet bekannt, dass sie Rheinmetall Defence gehackt hat

Rheinmetall Opfer eines Ransomware-Angriffs? Die Babuk Ransomware Gruppe (babuk-bjorka) hat heute auf ihrer Website im Darknet bekanntgegeben, dass

teufelswerk | IT-Sicherheit & Cybersecurity

Die Babuk Ransomware Gruppe (babuk-bjorka) hat heute auf ihrer Website im Darknet bekanntgegeben, dass sie Rheinmetall Defence (rheinmetall.com) gehackt hat.

#babuk #babukbjorka #ransomware #ransom #rheinmetall #gehackt #hack #hacker #rheinmetalldefence #cybersecurity #itsicherheit #leaksdata #datenschutz #militar

New post from #Babuk-Bjorka : Rheinmetall.Com (Rheinmetall Defence)
More at : https://www.ransomlook.io/group/Babuk-Bjorka #Ransomware
babuk-bjorka details

New post from #Babuk-Bjorka : Secret Plans Of Indian Army
More at : https://www.ransomlook.io/group/Babuk-Bjorka #Ransomware
babuk-bjorka details

New post from #Babuk-Bjorka : Bangladesh Armed Forces (Bangladesh Army)
More at : https://www.ransomlook.io/group/Babuk-Bjorka #Ransomware
babuk-bjorka details