The transcription discusses the sudden disappearance of the ransomware group Ransom Hub, known for its extensive operations and unique features like SFTP data encryption. The origin of Ransom Hub is speculated to be linked to Black Cat, with commonalities in their operations. The group targeted critical infrastructure, especially healthcare organizations, to increase ransom payment likelihood. Affiliates played a crucial role in carrying out attacks on behalf of Ransom Hub. The impact of Ransom Hub on businesses globally was significant, and its sudden disappearance has led to uncertainty in the ransomware marketplace. Recommendations for businesses to avoid ransomware attacks include patching vulnerable devices, avoiding weak passwords, implementing two-factor authentication, and segregating servers and workstations. The landscape of ransomware groups has become more fragmented, with affiliates switching between groups based on recommendations, features, and propaganda. The concerns for businesses remain high, as the affiliates conducting attacks may continue operations with similar tactics and tools even after Ransom Hub's disappearance.
Transcription
5008 Words, 29241 Characters
Imagine you're at work tapping away at an email when suddenly you get a message that
changes everything. It's a note that tells you your company's servers have been breached
and your data stolen and encrypted. The note goes on to deliver the good news that your
data is for now secure and that nobody knows about the breach. It warns against reaching
out to the authorities for help and says that any action will have irreversible negative
consequences for your business, including the publication of the stolen data and details
of the hack. The solution you read is really quite simple. You have to pay up, pay the
ransom and the problem goes away in 24 hours guaranteed. Before April of this year, that
ransom note might be signed by one of the most prolific gangs of online extortionists
around the globe, a group responsible for over 600 attacks and multi-million dollars
of stolen money. But then they vanished, their web pages went dark, their thriving ransomware
operation vanished overnight and their members scattered to rival groups across the dark web.
Now there are two questions on everyone's lips. What does that mean for the ransomware
marketplace and what exactly happened to the cyber criminal group codenamed Ransom Hub?
Alright, let's dive right into this episode. So we have an exciting guest joining us this
week, Cyber Threat Intelligence Analyst and Group I.B.'s Ransom Hub Expert Pietro. Pietro,
now you've been close to the ground on this one. I know it. You're our ransomware expert.
So you're working as part of the Cyber Threat Intelligence Team investigating Ransom Hubs
operations and delivering crucial updates and information to help fight back against this
prominent ransomware as a service group. We're pleased that you've joined us to share your
insights. Let's first get into some of the basics. Can you tell us a little bit about
the origins of Ransom Hub? When did Group I.B. or you become aware of them?
Thanks Nick. Thanks Gary for having me here. I really have to be here. The first time we
heard about the Ransom Hub was in February of the last year, when they first published
the partnership program on Ramp Forum. But one of the accounts used by Ransom Hub admin
called Coley was created in this forum, I mean a Ramp Forum on May 2023. The group Ransom
Hub may have started even before the first victim was published in the idea of us. The
origin of Ransom Hub is quite confusing. A lot of people think that Ransom Hub is a
rebrand of Black Cat and there are some reasons for that. The first one is because the partnership
program of Ransom Hub was published right after Black Cat exited SCAM. The second reason
is because one of the victims, a big company that was published in the Ransom Hub DLS was
previously published in the Black Cat DLS. In addition to that, we also have some common
features in the Ransom Hub, like a feature that modifies synlinks in the Ransom Hub that
is also available in the Black Cat Ransom Hub. And also some instructions that we found
in the Affiliate Panel of Ransom Hub are present in the Black Cat Affiliate Panel.
Ransom Hub may have been created by Nochi, which was a former Black Cat Affiliate. But
of course, it's too confusing, but I think that's the best theory. I do not think that
Ransom Hub was a rebrand of Black Cat, but a group created by former Black Cat Affiliate
and night Ransom Hub developers.
And Ransom Hub is a service provider, right? If I was to try and join this thing, what
would that look like? What sort of things would they give me to then enable me to go and carry
out attacks?
Yeah, that's important to distinguish affiliates from Ransom as a service groups. Ransom as
a service groups, those who provide resources to criminals to encrypt data, to extort companies
and to negotiate with the companies. But because there are a lot of Ransom groups, Ransom as
a service operations, they may eventually provide additional resources like killers,
which is a kind of tool that they use to bypass detection and some security solutions. Some
of them may provide the DOS or you can even call a victim right from the affiliate panel.
The resources that Ransom Hub provided through their affiliates was the Ransomware, the DLS,
the Affiliate Panel, where they could configure and build the Ransomware and also some killers
that were able to bypass some security solutions and also some post-exploitation tools. The
Ransomware developed by Ransom Hub is very similar to most of the Ransomware we see nowadays.
I mean, you see features like killing processes, stopping services. They're able to use techniques
like the hash, pass the ticket and stuff like that. But there was one special feature in
the Ransom Hub, which was the feature that allowed criminals to encrypt data via SFTP protocol.
So that was a feature that I've never, ever seen before. There are some other groups like
killing that also provide some features in the Ransomware, which allow remote data encryption,
but they do not use SFTP. So that was the first time I see that.
And it's reported that Ransom Hub is the biggest Ransomware as a service operator, bigger than
LockBit. How did they pull that off in such a short time?
In 2024, because of the amount of the companies that were disclosed in the Ransom Hub TLS,
we can say that it was much bigger than the amount of companies published on LockBit TLS.
But I do not think that Ransom Hub was a special and great Ransomware as a service operation.
The thing is that when they emerged, LockBit was impacted by a law enforcement operation
called Operation Chronos. So that's one of the reasons why they became such a big Ransomware
as a service operation with a lot of affiliates. But there are some additional reasons I would
like to mention here. One of them is because the Black Hat and LockBit Ransomware operations
were impacted by law enforcement operations and exited skin. So they emerged in the right
moment in the middle of the chaos when LockBit and Black Hat was facing this kind of problem.
The second reason is, as I mentioned before, right after the Ransom Hub emerged, they leaked
data of a big company that was previously published in the Black Hat TLS. So they gained
a lot of attention. A lot of people started talking about Ransom Hub. So for obvious reasons,
those affiliates that previously worked with Black Hat and LockBit thought that Ransom
Hub could be a good group for them to move and start working with. Some additional reasons
is because of the exit scams from Black Hat and also from Nosecape, Ransom Hub allow affiliates
to use their own crypto wallets. So affiliates somehow felt like they could trust Ransom
Hub because probably they would not steal their money since the payment, the Ransom payment
was received right in the affiliates' crypto wallets. Also because the affiliates had to
pay only 10% of fee for the Ransom Hub group. As you know, every time you join a Ransom
Hub as a service operation, all the money that you get from the victims, you need to
give like 10%, 20% of that payment to the Ransom Hub as a service group that provide
the resources to the affiliates. And in case of Ransom Hub, affiliates had to pay only
10% as a fee. So it was at that time, their lowest fee I've ever seen from a Ransom group.
And for obvious reasons, a lot of affiliates moved to Ransom Hub because they wanted to
gain a lot of money and pay as less as they could. And I think there is something else
like I've heard from a lot of Ransom Hub affiliates that the ransomware was good. The
ransomware was fast. It had some cool features like that one I mentioned. They were able
to encrypt data via SFTP and so on and so on. And the last thing I would like to say,
why Ransom Hub became such a big Ransom as a service operation and could recruit a lot
of criminals is because they created a narrative based on what the Ransom Hub admin called
Lockbeat and Black Hat mistakes. So all that stuff about exit scam, the problems that Lockbeat
faced because of the law enforcement operation and so on and so on. So the Ransom Hub admin
posted a lot of stuff in the ramp forum talking about their mistakes and said like, look, you
will not face this kind of problem with us. We are a great group and we will not make such
mistakes like those that Lockbeat and Black Hat did. So I think that's one of the reasons
why they became such a big group.
One of many reasons it seems that this franchise model is really working out for Ransom Hub.
So Pietro, can you tell us a little bit about who were the Ransom Hub targets?
Ransom Hub as their affiliates financially motivated threat actors. So they do not focus
on a specific country or region or industry. But because of the law enforcement operations
that happened in the last year and late in 2023 that affected Black Hat, I've noticed
that a lot of Ransom and affiliates started attacking critical infrastructure like the
healthcare hospitals and these kind of organizations. So the same happened with the Ransom Hub.
The amount of organization, healthcare organization that they attacked was really impressive because
they believed, the affiliates believed that by attacking critical infrastructure the likelihood
for the victims to pay the ransom was much higher. So that's why nowadays we see a lot
of attacks against the healthcare organization and this kind of company.
As most of the Ransom Hub as a service groups, they did not allow affiliates to attack countries
like Russia, Ukraine and all of those countries that were part of Soviet Union. And also they
didn't allow affiliates to attack North Korea, Cuba and some other countries. That's really
hard to explain why they do not attack these countries but maybe there are some political
reasons why they do not do it. But Ransom and groups admins do not have any control of what
affiliates we attack. So they can have these rules but an affiliates can eventually attack
a Russian company or attack a company in Brazil if they do not allow it to attack Brazil for
example. Killing for example has the same very similar rule. So killing does not allow their
affiliates to attack Briggs country but they may eventually attack a company in Briggs country.
So they do not have any control of it and the Ransom can be run in any computer so they do not
check languages, the country of that IP address of the victim. So yeah even though they have rules
they do not have any control of the affiliates. Yeah I suppose there are more guidelines at this
point than rules and really interesting to see them targeting critical infrastructure and healthcare.
So talk to us a little bit about the impact from Ransom Hub. A lot of people may know
some threat actors like those involved with the scattered spider and some other big groups joined
Ransom Hub. In addition to the amount of companies that they published in the DLS they
attacked really big companies. So I think that the impact that Ransom Hub made in the companies
all over the world was really big. And where are Ransom Hub today? That's a hard question to answer.
There are some theories that Ransom Hub may have joined Dragon Force. A lot of people know that
Dragon Force advertised something that they called Ransom Hub Cartel. Even though that's not the
first time that we see this kind of stuff, sometime ago in 2021 they also tried to do the same like
to create a Ransom Hub Cartel and work together. But even though there is such a theory that
Ransom Hub may have joined Dragon Force or even that Dragon Force attacked Ransom Hub I do not
think that none of them is true. The truth is that there is no evidence of what happened to
Ransom Hub. Some criminals think that Dragon Force may be a rebrand of Ransom Hub. And even
though Ransom Hub admin said a lot of bad things about Dragon Force on Ramp Forum, maybe it's
just to create confusion so that people will not think that Dragon Force is not a rebrand of
Ransom Hub. There is no evidence of what happened to Ransom Hub. If someone did take them down,
who do you think that would have been? As I mentioned, some people think that Dragon Force
attacked Ransom Hub because there are some evidence that Dragon Force already attacked some other
Ransom Groups. But there are some interesting information that we found in the Ransom Hub
Affiliate Panel. The admin of Ransom Hub reported at least three of what they call
technical issues, incidents in the infrastructure. The admin didn't mention about any attack,
any fantastic exploitation of vulnerability or something like that. But that's very strange,
even though we do not know who did that, either it was Glow Enforcement or maybe Dragon Force or
the Ransom Group. But in one of the technical issues that the admin mentioned in the Affiliate
Panel, he said that those who were trying to exploit their system, their Affiliate Panel,
gained access to some decryptors. So he said that they were working on an update of their
Affiliate Panel and the developer did some things wrong and it allowed those who were
trying to exploit the Affiliate Panel to gain access to some decryptors. The admin said that
it didn't impact all the affiliates. I mean, those who gained access to the decryptors didn't get
all the decryptors, but only part of it. But that was something that was reported in the
Affiliate Panel that was very strange. So maybe Dragon Force, who knows.
So what does this mean for the businesses that were waiting on a decryptor? They paid their
money, they're waiting for the decryptor, what do they do now?
Yeah, as long as I know that there's no decryptor, you know that there is a project called no more
ransom, no law enforcement and security companies upload some decryptors. But as long as I know
there is no decryptor for the ransom hub, they just disappeared. Recently, countries
international said that they're going to close the project. And they told their victims that,
look, you can message us and we will give you, we will provide you with the decryptors. But it
didn't happen with the ransom hub. So if there is no decryptor and those companies who were attacked
do not have any backup, that's really hard to recover the data. Yeah, maybe there's nothing to
do unless you have backup. The ransomware marketplace as a whole, you know, how are these
groups orchestrating hostile takeovers? You can say even more fragmented because of a lot of
stuff that happened that I mentioned here really, law enforcement operations, exit scams and so
on and so on. So now we see a very fragmented that it was a really very fragmented wrestling
landscape. But now it's even more fragmented wrestling landscape. So affiliates are living big
groups like Keylin and Dragonforce. Some of them do not trust what they call big groups because
they believe that in the future, they may exit scam like Black Hat did, like Nosecape did. So
they are living these big groups and they are creating their own wrestling operation. Some of
them are like wrestling as a service. Some of them are like private groups, so very close. So
they allow only those that they know to join their operation. So I think that's the kind of
thing we deal with right now, very fragmented but a lot of groups, a lot of uncertainty and this
kind of thing. How do people move from one group to the other? Is there like, you know, a jobs
board or is it people what's up in each other? It depends. I do not think that they move to the
group that offer the best resources, like the best wrestler, the group that has the best
features. Sometimes they move to a group because their friends work with some specific groups,
or because they got some good recommendations. Even though the wrestler is not good, they have
some problems, but they get some recommendations of some other threat actors. In addition to that,
I think it also depends on the, let's say, propaganda that wrestling groups make on open
sources like Twitter or on underground forums like RIMP. For example, now if you go and access
the RIMP forum, you will see some advertisements of NOVA, which is somehow a new wrestling group,
and also some advertisements of Killing. They try to make this propaganda. In addition to
advertisement, they make some comments on some partnership problems to say, "Look,
we have this group. We have these resources. Join us. We are ready to help you."
Yeah, a little bit of some recommendations from criminals, a little bit of some propaganda that
they see on underground forums. Yeah, that's how they move.
Thanks, Pietro. They really sound like businesses trying to scale themselves. Employees going where
their friends are working. Now that Ransom Hub has disappeared, did businesses still be concerned?
Yeah, sure. Ransom Hub is just Ransom as a service provider. Those involved with Ransom Hub
do not conduct any intrusion. Those who conduct intrusion, the affiliates. It doesn't matter
if it's Ransom Hub, Killing, NOVA, Lockpit, it really doesn't matter. That's why companies should
care about identifying, attributing the intrusion to the affiliates, understanding their techniques.
Those who worked with Ransom Hub, some of them, and I know that they moved to Killing, for example.
So they're still there using the same techniques, very similar modus operandi, the same tools.
That's why they should be aware and be concerned.
And I think that's a really key point that you brought up about the affiliates conducting the
attacks, the overlaps in the tactics, techniques, and procedures. So when you look at it from a
business perspective, impacted by Ransom Hub or similar groups, what are the common weaknesses
that you see that could be avoided? You should patch everything which is vulnerable, of course.
But especially devices that provide SSL, VPN, and web-based applications like
RD-Web, C-Tricks, and stuff like that. Because usually they gain initial access by exploiting
generabilities in such devices, especially SSL VPNs. But in addition to that,
things that the first time we heard about Ransom as a service and partnership programs and affiliates,
they use very similar techniques. So you should avoid public-facing RDPs and remote services.
So what should be available on the internet is only the VPN. So you should connect to the VPN
and also you connect to the VPN, you gain access to the resources of your company.
RDP windows should not, in my humble opinion, be available on the internet. Otherwise, they view
brute force, they will try to exploit generabilities in this kind of service. Also, the lack of
two-factor authentication. So they perform a lot of brute force based on very weak passwords.
So if you do not have two-factor authentication, that's a problem. And in addition to that, we see
very bad password policies. So they have some word lists that they use to conduct brute force
with passwords like admin, admin, admin, one, two, three. So you should not allow such a password.
So the weak password and bad password policies, very serious problem. They also, I think that there's
one thing that should be avoided, which is having a workstation and all of the servers in the same
network. If you do it, if you do not use VLAN, for example, when criminals gain access to your
network, you see everything that will be really easy to do some lateral movement. Use a VPN,
please do it and do not put all the servers and workstation together. What else I think should
be avoided? Unpatched, really old vulnerabilities. So I've heard a lot about some hackers that
they could do some privilege escalation because they could exploit some old vulnerabilities on
Windows. So that's the kind of stuff you should avoid. The lack of offline backup. You may have
backup, but if it's connected to your network, the contractors may eventually gain access to your
backup and also encrypt your backup. So that's why when they are talking about a successful attack,
what they mean by that is that backup should be either encrypted or deleted. You should have
offline backup. Yeah, I think that's all. So from a defender perspective,
is there an overlap in the TTPs that they use from different RAS operators?
Since the first time we see this kind of ransomware server stuff, they keep using the same
techniques. I'm not saying that nothing changed. Of course, things change, but they're doing the
same like brute forcing RDP servers, SSL VPNs. They will always try to exploit vulnerabilities,
especially SSL VPNs. They will try to gain access, to gain initial access to the companies as
fast as they can and as easy as they can because they want to do everything fast, to get money fast.
If you see a vulnerability in the SSL VPN device, for example, and they can exploit
by exploiting some path traversal or any vulnerability that can lead to remote code
execution or they can upload web shell, they will do it. Because that's easy to hack,
and as it's easy to hack, that should be better. And in addition to that, we see a lot of intrusions
where affiliates gain access via valid accounts. So it doesn't matter the source. Sometimes the
valid accounts is available on telegram or underground forums because someone decided
to share the stereo logs. So you will see initial access brokers getting those data and selling on
underground forums. You will see that they may eventually buy some credentials, some valid accounts
or marketplaces. So valid accounts is a very serious problem that they keep using this technique.
Talking a lot about threat actors, not only a scattered spider, but encrypt hub, for example,
and some affiliates of Inc. that have been conducting intrusions and gain initial access
through social engineering, like vision, email vision, and events mission. So that's a very common
technique that they use. In addition to that, we see, like in the post-exploitations, they dump the
hashes, they dump Kerberos tickets. They will try to use techniques like pass the hash, pass the
ticket. They will use vulnerable drivers to try to queue some EDR solutions and some other
antiviruses. So that's the kind of technique that we see in intrusions from affiliates of
ransomware as a service groups. Excellent. Thanks a lot, Pedro. When I look at the
ransomware landscape, we have the ransomware as a service operators providing the tools,
providing the scalability, and we have the affiliates that are actually conducting
these attacks against organization. What do you think should or could be done speaking specifically
about the affiliates? I think one of the most important things is to understand the mindset
of criminals, and also to understand the TTPs. As you said, there are some overlaps, so we should
understand what the common techniques that they use, what kind of tools that they usually use,
like we see a lot of PSSAC, we see a lot of Mimicats, we see a lot of Bloodhound, Trexploits,
Windows Domain. So that's really important to understand the common techniques that we see
in intrusions from the affiliates and create detection rules based on the behavior of the
tools and the techniques that they use. From the Trex Intelligence perspective, I believe that's
really important to conduct a human intelligence. What I mean by that? We should get information
from the affiliates. We should infiltrate the groups because we should know about the vulnerabilities,
about the resources that they use, their capabilities before they attack a company.
We should understand how they think, how they choose a victim, why they exploit a specific
vulnerability and stuff like that. That's really important to be a lot of steps ahead of the criminals,
and we should not be afraid of them. They should be afraid of us.
Speaking about the future, you talked about gaining access, gaining knowledge, understanding
your adversary. Given the disappearance and the shifts in the ransomware marketplace,
what signs are you watching for? In the last blog we published in the GroupABE blog,
we noticed that the amount of companies that were published in the Killing DLS increased
in the last three months. It happened right after the Brassel Hub disappeared. Maybe we have
information that some affiliates that previously worked with Brassel Hub moved to Killing. Of
course, we do not have full visibility about all their affiliates because Brassel Hub is not working
anymore, or at least not under this brand. I think that affiliates will join Killing,
will join Dragonforce because they are big and known ransomware as a service groups,
or they may eventually create their own ransomware as a service group. I can give you an example.
The Van Helsing ransomware as a service group was a group created by two affiliates that worked
with the Brassel Hub. They do not trust, because a lot of things that happened, they do not trust
big groups. They may eventually join big groups like Dragonforce and Killing, but they may create
their own ransomware as a service and private ransomware groups. That's why I'm saying that
the Brasselware landscape, we have an even more fragmented scenario. That's really hard to make
attribution during incident response, collecting evidence in incident response and making attribution
because of all of this stuff. We leave them with a fragmented scenario.
Nick, you work with a lot of customers that get impacted in ransomware attacks. What sorts of things
should they be doing to protect themselves? Listening to Pietro, he had a lot of great
insights. I think it's not a matter of if, but when we will be attacked as a business from
ransomware operators, from other APT groups, whoever it might be. It all comes down,
in my opinion, to a few different categories. One is about understanding your adversaries,
so collecting information either from OSIN sources or from private companies like Group IB to really
understand who are the adversaries that can attack me, what are the overlapping tactics,
techniques and procedures that they may use, and then making sure that we have the right tools
in place to defend against it. Pietro spoke a lot about the overlapping vulnerabilities that
ransomware groups will employ to try and target different organizations. Having an attack surface
management capability that ingests the vulnerability intelligence to passively scan the external
infrastructure or actively scan the infrastructure on the external makes sense to make sure those
gaps are plugged before a ransomware group or affiliate will try to actually attack the organization.
Pietro mentioned also that external remote services for employees is one of the primary
entry points. Having different OTP enforced for MFA, for remote services, and having really strong
identity access management solutions to make sure only your employees are accessing different
services rather than external affiliates, for example. I think definitely having the right
tools in place. Pietro had a lot of great points about the overlapping tactics, techniques and
procedures. Knowing what those are and making sure you have the right tools in place. More
importantly, I think it's to be prepared and not just from a technical perspective, but from a
business perspective. What are we going to do as a business when and if this happens? How is our
PR team going to react? How is our board of directors going to react? Really running those
simulations, understanding how different important critical pieces of the business
may react during the scenario is critically important. So, yeah, definitely having those
yearly preparations for this type of incident would be critical. Awesome. Thanks, Nick. Well,
that's just about all we have time for this week, Pietro. Thanks very much for joining us. It's been
a pleasure having you on as a guest. Thanks, Gary and Nick for having me here. Cheers, Pietro. Thanks,
man. We'll see you again next time. Your data is valuable and it's under attack. Cyber espionage
groups, financially motivated threat actors, ransomware attackers and other criminal enterprises
are on the rise. Working in secrecy to dismantle security perimeters, they spread like a virus
through the web, stoking geopolitical tensions, holding businesses to ransom and flooding criminal
marketplaces with sensitive information. These groups thrive in secrecy now more than ever.
Knowing who your adversaries are is critical. So, join us as we ask who's behind the world's most
prolific cyber criminal groups? What are their tactics, their motivations and their impact?
Who are the world's masked actors? Masked actors is an independent podcast from GroupIB,
a leading voice in the fight against cybercrime. The threat landscape evolves quickly, but all
information was correct at the time of recording and based on GroupIB's high-tech crime trends report
2025. Join in the conversation online using the hashtag masked actors and don't forget to subscribe
so you don't miss an episode. Thanks for listening. See you next time as we uncover more of the world's
top masked actors.
Podcast Summary
Key Points:
Ransom Hub, a major ransomware group, mysteriously disappeared overnight, leaving questions about the ransomware marketplace.
Ransom Hub's origins are linked to Black Cat, offering ransomware-as-a-service with unique features like SFTP data encryption.
Ransom Hub targeted various sectors, especially critical infrastructure like healthcare organizations, relying on affiliates for attacks.
Summary:
The transcription discusses the sudden disappearance of the ransomware group Ransom Hub, known for its extensive operations and unique features like SFTP data encryption. The origin of Ransom Hub is speculated to be linked to Black Cat, with commonalities in their operations. The group targeted critical infrastructure, especially healthcare organizations, to increase ransom payment likelihood.
Affiliates played a crucial role in carrying out attacks on behalf of Ransom Hub. The impact of Ransom Hub on businesses globally was significant, and its sudden disappearance has led to uncertainty in the ransomware marketplace. Recommendations for businesses to avoid ransomware attacks include patching vulnerable devices, avoiding weak passwords, implementing two-factor authentication, and segregating servers and workstations.
The landscape of ransomware groups has become more fragmented, with affiliates switching between groups based on recommendations, features, and propaganda. The concerns for businesses remain high, as the affiliates conducting attacks may continue operations with similar tactics and tools even after Ransom Hub's disappearance.
FAQs
The emergence of Ransom Hub raised questions about the ransomware marketplace and the fate of the cyber criminal group.
Ransom Hub attracted affiliates with lower fees, unique ransomware features, and a narrative emphasizing trust and reliability.
Ransom Hub targeted financially motivated threat actors, including healthcare organizations and critical infrastructure.
Ransom Hub made a significant impact by targeting big companies and joining hostile groups, leaving victims without decryptors.
Threat actors often move based on recommendations from peers, propaganda on underground forums, and perceived trustworthiness of the groups.
Businesses should remain vigilant as affiliates of Ransom Hub may continue attacks using similar tactics and tools.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.