A major international law enforcement effort has disrupted the infrastructure supporting three prominent malware families used in ransomware attacks and data theft. Coordinated by Europol and Eurojust, Operation Endgame involved agencies from Australia, Belgium, Canada, Denmark, France, Germany, the Netherlands, the United Kingdom and the United States, together with private sector partners. The operation focused on SocGholish, Amadey and StealC. SocGholish acts as a dropper delivered via fake
amadey (2)
Cybercriminals are increasingly outsourcing the task of deploying ransomware to affiliates using commodity malware and attack tools, according to new research. Affiliates are typically threat actors responsible for gaining an initial foothold in a target network. In a recent analysis published by Sophos. The report states that the new deployments of Ryuk and Egregor ransomware have involved the use of SystemBC backdoor to laterally move across the network and fetch additional payloads for fu