🚨Actualización:

#Brasil 🇧🇷: El grupo de ransomware RA World vuelca los datos de C&C Casa e Construção, 337GB, cec[.]com[.]br.

#ransomware #ragroup #raworld #Brazil #br

#RAGroup is the highlight of this #readoftheday! Cisco Talos Intelligence Group identified a new ransomware actor who appears to be leveraging leaked #Babuk ransomware source code. Enjoy and Happy Hunting!

Shout out to Chetan Raghuprasad for the article!

Newly identified RA Group compromises companies in U.S. and South Korea with leaked Babuk source code
https://blog.talosintelligence.com/ra-group-ransomware/

Notable MITRE ATT&CK TTPs:
TA0040 - Impact
T1486 - Data Encrypted for Impact
T1490 - Inhibit System Recovery

TA0007 - Discovery
T1135 - Network Share Discovery
T1083 - File and Directory Discovery

#CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting

Newly identified RA Group compromises companies in U.S. and South Korea with leaked Babuk source code

Cisco Talos recently discovered a new ransomware actor called RA Group that has been operating since at least April 22, 2023.

Cisco Talos Blog
Like other ransomware groups, #RAGroup uses double extortion tactics and a leak site. More on this attacker here https://blog.talosintelligence.com/ra-group-ransomware/
Newly identified RA Group compromises companies in U.S. and South Korea with leaked Babuk source code

Cisco Talos recently discovered a new ransomware actor called RA Group that has been operating since at least April 22, 2023.

Cisco Talos Blog
New RA Group ransomware gang is the latest group using leaked Babuk source code

A previously unknown ransomware group known as RA Group is targeting companies in U.S. and South Korea with leaked Babuk source code. Cisco Talos researchers recently discovered a new ransomware operation called RA Group that has been active since at least April 22, 2023. The group has already compromised three organizations in the U.S. and […]

Security Affairs