Latrodectus is a ransomware family observed in recent campaigns associated with the Rhysida threat group.
Latrodectus is a ransomware family observed in recent campaigns associated with the Rhysida threat group. The operation uses malvertising to deliver payloads to users on Teams, Zoom, and PuTTY, and abuses a Microsoft code-signing certificate to bypass defenses, enabling stealthy execution and encryption. This combination of delivery and evasion highlights the evolving capabilities of contemporary ransomware campaigns.
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
Recent reports detail the tactics employed by various cyber adversaries to enumerate files and directories on compromised systems. Adversaries utilize command shell utilities and custom tools to gather sensitive…
Ransomware actors are increasingly focusing on cloud-based assets, particularly in AWS environments. This shift involves utilizing various tactics to compromise critical business data, moving away from traditional…
The Rhysida ransomware group is exploiting fake advertisements for Microsoft Teams to distribute malware, specifically targeting users searching for the software. This campaign employs malvertising techniques,…