The Angry Likho APT, via the Lumma Stealer malware, has launched attacks on high-profile organisations in Russia, Belarus and other countries, targeting system data, personal details, and cryptocurrency wallets. Kaspersky’s analysis revealed the use of spear-phishing emails with malicious attachments and a novel method of deployment for the malware. This comes as Angry Likho evolves towards more covert operations.

96% of ransomware incidents involve data exfiltration
Ransomware incidents now mainly involve data exfiltration, with only 4% not doing so. This indicates a shift in priorities among malicious actors.