Since late February 2025, Microsoft has observed Moonstone Sleet, a North Korean state actor, deploying Qilin ransomware at a limited number of orgs. Qilin is a ransomware as a service (RaaS) payload used by multiple threat actors, both state-sponsored and cybercriminal groups.
Sad day! Oppression, bullying, and taking advantage of the less fortunate. ;(
This should not be a transaction for $$. They r looking to us for help because their Sons, Daughters, Husband r dying.
Bad signal to our adversaries that are experts at creating this confusion.
🚨 8Base Ransomware Takedown – Site Seized by Law Enforcement 🚨
The notorious 8Base ransomware group has been shut down, with their darknet leak site now displaying a "THIS HIDDEN SITE HAS BEEN SEIZED" message.
🔴 8Base was one of the most active ransomware gangs, responsible for numerous corporate breaches and data leaks.
🔴 The law enforcement operation signals a major strike against cybercriminal networks.
🔴 The impact? Will affiliates regroup or move to other ransomware operations?
💻 The fight against ransomware continues. Who will be next?
🔗 Read more: https://t.co/k9v07XnnwG
#CyberSecurity #Ransomware #8Base #CyberCrime #ThreatIntel
@Arete_Advisors's Threat Research Team (TRT) analysis of Fog ransomware TA group and malware (background on TA, data from our DFIR engagements like ransom demands, analysis of the malware, indicators, and detection rules): https://t.co/hNiDifBjUt
Exciting news! We are thrilled to announce that Arete has been awarded AT&T Cybersecurity's New Partner of the Year for 2023! We are honored to be recognized for our commitment to growth, innovation, and customer solutions. Read more on the winners here: https://t.co/NYmvZuwimx
@Arete_Advisors Report on the active Trigona ransomware threat and observed links to ALPHV\BlackCat: https://t.co/HQdU6D1UCI (PDF download link on the top right)
In February 2022, Arete investigated a #Surtr ransomware incident where the #ransomware author paid tribute to the now defunct #REvil (aka Sodinokibi) group by making a registry key change to the infected host.
Learn more in Arete’s latest insight: https://t.co/zSN1YW8EyA
Interesting work into physically tracking down #EvilCorp members located in Russia from BBC News. They even showed up at Maksim Yakubets family home and talk to his dad. It’s not so funny when people show up at your house… just sayin. https://t.co/JJfj10XKLh
@Jon__DiMaggio@DanPatterson To my understanding, EvilCorp is Indrik Spider that is associated with Dridex and BitPaymer.
Then, a fork from EvilCorp is known as Doppel Spider that is associated with Doppel Dridex/Dridex 2.0 and DoppelPaymer. Then, Grief having code similarities with Doppel Paymer != EC.
@Jon__DiMaggio@DanPatterson I am curious about where is the hard evidence that associates him with Grief which is said to have some code similarities with Doppel Paymer.
Are there messages known to be from him saying he created or is updating the Grief code?
I am genuinely interested about the attrib..
Arete’s new #insight, “Egregor: The Ghost of Soviet Bears Past Haunts On” breaks down the evolution of Egregor and provides Arete’s assessment and security recommendations based on breach response engagements.
Click here to read: https://t.co/EGYBiCq2VP
#Egregor#Ransomware
@Arete_Advisors article update on #Sodinokibi \ #REvil ransowmare: Sodinokibi Joins The Black Lives Matter Movement. It includes an artifact of interest found in various Sodin cases and additional artifacts from one of our engagements. https://t.co/Myzsij5eUn