Skip this post if you don't feel like getting irritated and/or frustrated and/or angry.
July 18th, 2024 Columbus, Ohio was a victim of Rhysida ransomware group — a group believed to be related to the now 'forked' and defunct Conti ransomware group.
August 8th, 2024 Rhysida ransomware group began slowly releasing the 6TB of exfiltrated Columbus, Ohio government data onto their Tor domain. As time progressed, it was evident the city of Columbus, Ohio were unlikely to pay the $1,600,000 Rhysida ransomware group wanted.
Columbus Mayor Andrew Ginther stated to local media outlets that Rhysida has unsuccessfully exfiltrated data and they successfully stopped the attack. Subsequently, a cybersecurity researcher operating under the moniker 'Connor Goodwolf', refuted the mayors statements — essentially acting as a whistleblower.
Connor Goodwolf spoke with Columbus, Ohio media outlets regarding the Rhysida ransomware group attack, proving Rhysida has not only successfully compromised the local government, but also exfiltrated sensitive information on residents of Columbus, Ohio. This information included social security numbers of police officers, people who are victims of domestic violence, etc.
Mayor Andrew Ginther decided to have the City of Columbus, Ohio sue Connor Goodwolf. Additionally, the city is seeking a restraining order against Goodwolf, making it a crime to disclose more information on the Rhysida breach, and requesting a permanent injunction against Connor Goodwolf. The lawsuit against Connor Goodwolf states Mr. Goodwolf places the community in danger stating he is spreading stolen data which is illegal. The lawsuit continues to say 'nobody' had access to the exfiltrated Rhysida ransomware group data because it was published in a manner where access was difficult to achieve.
@malwrhunterteam@SynerComm This was my payload. Can confirm payload was being used in an engagement. Cool to see it was not detected. The payload is actually a simple shellcode loader written in Lua and embedded into Rust. It’s highly effective.
Iffff this CrowdStrike incident were to have been a malicious actor and not a software bug, I think it goes to show how dangerous a supply chain attack could be.
.@MLS the referee announcing the calls on the field is so cringy. We all know what the hand signals mean. Please stop trying to make football into American football. And also #wolffout
We are hiring and growing a ton of folks over @Binary_Defense.
Looking for immediate person skilled in Exabeam if anyone is looking!
Open positions:
Senior Software Engineer, Account Executives, Lead/Sr Software Engineer, RFP + Proposal Managers, Senior Software Engineer, SOC Analysts, Software Architects, Sr. Threat Intelligence Analyst and more!!
#BinaryDefense
After almost 2 years of working on NimPlant as a personal side project, I’m proud to release it to the public! NimPlant is a light-weight, first-stage C2 implant written in Nim, with a supporting Python server and Next.JS web GUI.
Available here now! 👇
https://t.co/KekG9GLGYQ