Ransomware attacks follow a set pattern, leaving a trail and providing insights into the economic activity connected with such attacks. Payment is usually demanded in cryptocurrencies, avoiding cross-border complications. Since 2019, attackers have threatened to leak unencrypted files, putting employee, client, and vendor data at risk. The FBI used blockchain analytics to recover payments to Darkside in 2021, and the tool Elliptic has revealed the activity of ransomware group REvil/Sodinokibi since 2019.
Salt Typhoon targets telcos again with backdoor GhostSpider malware
Salt Typhoon, a Chinese state-sponsored threat actor, is using a new malware backdoor called GhostSpider to target telecommunications service providers. Cybersecurity company Trend Micro said