Threat Actor Conducts Large-Scale Exploit Testing Before Ransomware Deployment
First seen 9 Jan 2026, 20:34 UTC
•
•37
Export
Article Content
Browse articles
Between December 25–28, 2025, a threat actor executed a scanning campaign targeting internet-facing systems, testing over 240 different exploits. This operation, linked to CTG Server Limited, aimed to identify and collect data on vulnerable targets as a precursor to ransomware attacks.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
MuddyWater's Operation Olalampo Targets MENA Region with New Malware
Iranian APT MuddyWater Uses Chaos Ransomware as a False Flag for Espionage
Iranian APT Groups Target Israeli Organizations with Modular C2 Frameworks
Microsoft Word Vulnerability CVE-2026-21514 Exposes Millions to Malware Attacks
China-Linked Hackers Deploy PlugX Malware in Qatar via Fake War News