cognitive cybersecurity intelligence

News and Analysis

Search

Financially motivated hackers are helping their espionage counterparts and vice versa

The RA World ransomware group has been discovered using tools traditionally associated with a Chinese-linked espionage group. The toolset variation, first seen in July, was a variant of PlugX malware. Security company Symantec suggests the attacker may have been a longtime ransomware operator, linked to other China-based ransomware payloads. There are theories this could have been to obscure intrusion evidence, though the ransomware didn’t effectively hide intrusion tools; that one actor was trying to make additional money, or for both financial and espionage reasons.

Source: arstechnica.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts