Researchers at Palo Alto have outlined the details of a new attack campaign by the Mespinoza ransomware group, also known as PYSA. The group has been around since April 2020 and is known to target victims all over the world, though they mainly focus on companies in the US. Their victims have been in multiple industries including manufacturing, education, retail, engineering, and government. In their most recent attack, the group will use compromised credentials, which they likely stole through phishing, to access a company’s network through Remote Desktop Protocol (RDP) and gain a foothold that is undetected. The group will then search for any documents, email or other material containing compromising information that could be used for blackmail and a double extortion, in addition to the ransomware extortion. The group takes the attack a step further by installing an additional backdoor on the victim’s networks allowing them to gain persistence in the network.
12 Essentials for a Successful SOC Partnership
As cyber threats continue to impact businesses of all sizes, the need for round-the-clock security