Tag LockBit

⚡ THN Weekly Update: Key Cybersecurity Threats, Tools, and Tips

Dec 23, 2024
Cybersecurity / Weekly Update

The digital landscape is relentless, as this week has shown. From the apprehension of ransomware developers to state-sponsored hackers unveiling novel tactics, it’s evident that cybercriminals are continually evolving their methods. They exploit everyday tools for malicious purposes, embed spyware in trusted applications, and uncover new vulnerabilities in outdated security systems. These incidents are not mere coincidences—they highlight the ingenuity and adaptability of cyber threats. In this edition, we’ll explore the most significant cybersecurity events from the past week and provide essential insights to help you stay protected and proactive. Let’s dive in.

⚡ Threat of the Week

Charges Filed Against LockBit Developer Rostislav Panev — Rostislav Panev, a 51-year-old dual Russian and Israeli citizen, has been charged in the U.S. for allegedly serving as a developer for the now-disrupted LockBit ransomware-as-a-service (RaaS) operation, which is believed to have generated approximately $230,000 between June 2022 and February 2024. Panev was…

THN Weekly Cybersecurity Overview: Key Threats, Tools, and Insights December 23, 2024 Cybersecurity / Weekly Overview The digital landscape remains unrelenting, offering criminals continuous opportunities for exploitation. This past week has underscored the ever-evolving nature of cyber threats, highlighting a range of incidents from the capture of ransomware developers to…

Read More

⚡ THN Weekly Update: Key Cybersecurity Threats, Tools, and Tips

Dec 23, 2024
Cybersecurity / Weekly Update

The digital landscape is relentless, as this week has shown. From the apprehension of ransomware developers to state-sponsored hackers unveiling novel tactics, it’s evident that cybercriminals are continually evolving their methods. They exploit everyday tools for malicious purposes, embed spyware in trusted applications, and uncover new vulnerabilities in outdated security systems. These incidents are not mere coincidences—they highlight the ingenuity and adaptability of cyber threats. In this edition, we’ll explore the most significant cybersecurity events from the past week and provide essential insights to help you stay protected and proactive. Let’s dive in.

⚡ Threat of the Week

Charges Filed Against LockBit Developer Rostislav Panev — Rostislav Panev, a 51-year-old dual Russian and Israeli citizen, has been charged in the U.S. for allegedly serving as a developer for the now-disrupted LockBit ransomware-as-a-service (RaaS) operation, which is believed to have generated approximately $230,000 between June 2022 and February 2024. Panev was…

Storm-2603 Exploits SharePoint Vulnerabilities to Deploy Warlock Ransomware on Unpatched Systems

Jul 24, 2025
Vulnerability / Ransomware

Microsoft has disclosed that a threat actor, identified as Storm-2603, is actively exploiting vulnerabilities in SharePoint to deploy Warlock ransomware on targeted systems. In an update released Wednesday, the company noted that these insights stem from ongoing analysis and threat intelligence regarding Storm-2603’s exploitation activities. This financially motivated actor is suspected to be based in China and has previously been linked to the deployment of both Warlock and LockBit ransomware. The attack chain involves exploiting CVE-2025-49706, a spoofing vulnerability, and CVE-2025-49704, a remote code execution vulnerability, targeting unpatched on-premises SharePoint servers to facilitate the deployment of the spinstall0.aspx web shell. “This initial access enables command execution via the w3wp.exe process that supports SharePoint,” Microsoft stated. “Storm-2603 subsequently initiates a series of discovery commands, including…”

Storm-2603 Exploits SharePoint Vulnerabilities to Deploy Warlock Ransomware on Unpatched Systems On July 24, 2025, Microsoft disclosed that the cyber group known as Storm-2603 is actively exploiting vulnerabilities in SharePoint software to deploy Warlock ransomware on targeted systems. This revelation is based on an extensive analysis and threat intelligence from…

Read More

Storm-2603 Exploits SharePoint Vulnerabilities to Deploy Warlock Ransomware on Unpatched Systems

Jul 24, 2025
Vulnerability / Ransomware

Microsoft has disclosed that a threat actor, identified as Storm-2603, is actively exploiting vulnerabilities in SharePoint to deploy Warlock ransomware on targeted systems. In an update released Wednesday, the company noted that these insights stem from ongoing analysis and threat intelligence regarding Storm-2603’s exploitation activities. This financially motivated actor is suspected to be based in China and has previously been linked to the deployment of both Warlock and LockBit ransomware. The attack chain involves exploiting CVE-2025-49706, a spoofing vulnerability, and CVE-2025-49704, a remote code execution vulnerability, targeting unpatched on-premises SharePoint servers to facilitate the deployment of the spinstall0.aspx web shell. “This initial access enables command execution via the w3wp.exe process that supports SharePoint,” Microsoft stated. “Storm-2603 subsequently initiates a series of discovery commands, including…”

Black Basta Leaks Expose Phishing and Google Account Takeover Vulnerabilities

Fraud Management & Cybercrime, Ransomware Former Ransomware Group’s Fallout Reveals Hackers Targeting Microsoft Teams Mathew J. Schwartz (euroinfosec) • June 12, 2025 Recent data leaks from ransomware organizations underscore the evolving tactics used by attackers to compromise and lure in new victims. Notable disclosures include a substantial cache of internal…

Read MoreBlack Basta Leaks Expose Phishing and Google Account Takeover Vulnerabilities

LockBit’s New Challenge: Unruly Affiliates

Fraud Management & Cybercrime, Ransomware Data Leak Reveals LockBit Ransomware Group Expanding Targeting Strategies Akshaya Asokan ( asokan_akshaya) • June 12, 2025 Image: Shutterstock Recent analysis of data leaked from the LockBit ransomware group’s administrator panel indicates a troubling trend: the group’s affiliates have increasingly targeted organizations in China. This…

Read MoreLockBit’s New Challenge: Unruly Affiliates

NC Pathology Practice Alerts 236,000 Patients About Data Breach

Fraud Management & Cybercrime, Healthcare, Industry Specific Did Marlboro-Chesterfield Pathology Pay Ransom to Cybercriminal Group SafePay? Marianne Kolbasuk McGee (HealthInfoSec) • May 23, 2025 Marlboro-Chesterfield Pathology, a laboratory in North Carolina, is notifying nearly 236,000 patients about a data breach incident reported in January. (Image: MCP) A hacking incident involving…

Read MoreNC Pathology Practice Alerts 236,000 Patients About Data Breach

LockBit Leaks Expose Efforts to Recruit Ransomware Newcomers

Fraud Management & Cybercrime, Ransomware ‘Lite Panel’ Provides Easy Entry for Ransomware Operators at $777, Reports Researcher Mathew J. Schwartz (euroinfosec) • May 16, 2025 Ransomware groups are continually evolving their strategies to extort organizations, both large and small. The introduction of a more accessible “lite” version of LockBit’s ransomware-as-a-service…

Read MoreLockBit Leaks Expose Efforts to Recruit Ransomware Newcomers

Hacker Compromises Developer of Signal Alternative Utilized by US Government.

By the CyberWire staff Cybersecurity Incidents Summary A recent breach has compromised the developer of a Signal clone utilized by the US government, leading to the exposure of customer data. This incident underscores vulnerabilities in systems supporting critical communication. Additionally, the NSO Group has been ordered to pay over $167…

Read MoreHacker Compromises Developer of Signal Alternative Utilized by US Government.

Exposing Ransomware: The LockBit Breach and Its Impact on the Digital Extortion Economy | HaystackID

The cybersecurity landscape has recently undergone a notable shift due to the compromise of LockBit’s operational infrastructure, shedding light on one of the most advanced ransomware-as-a-service (RaaS) operations currently in existence. This breach has unveiled around 60,000 Bitcoin addresses linked to LockBit’s extensive ransomware activities, delivering invaluable insights for cybersecurity…

Read MoreExposing Ransomware: The LockBit Breach and Its Impact on the Digital Extortion Economy | HaystackID