Red Hot Cyber
Cybersecurity is about sharing. Recognize the risk, combat it, share your experiences, and encourage others to do better than you.
Search
Banner Ransomfeed 320x100 1
2nd Edition GlitchZone RHC 970x120 2

Author: RHC Dark Lab

RHC interviews RADAR and DISPOSSESSOR: “When it comes to security, the best defense is a good offense.”

In our usual underground analysis activities, we came into contact with the cyber gang DISPOSSESSOR, which came to attention in February 2024 in the cyber threat landscape. Accessing their Data Leak Site (DLS) one immediately realizes a strong resemblance to that of the well-known cyber-gang LockBit, and even the number of views of individual posts, taking into account that it is a blog in the onion network, has nothing to envy the elite cyber-gang. This profound similarity suggests a possible reorganization by affiliates of the world’s longest-running cybergang, LockBit, in part because of the two Cronos operations, which saw law enforcement break

RHC interviews Ransomcortex, the gang targeting Hospitals. “pay the ransom, we won’t even spare the CEO’s family.”

Ransomcortex is a new cyber ransomware gang that resonates menacingly in the healthcare sector. This group has quickly attracted attention for its specialization in attacks on healthcare facilities, striking four institutions in a matter of days, including three in Brazil and one in Canada. This group demonstrated extraordinary efficiency and a clear “on target” strategy, highlighting the vulnerability of a sector already under tremendous pressure. Ransomcortex’s targeted focus on healthcare organizations raises crucial questions: why this sector and what are the real targets of these criminals? Extremely sensitive and valuable health information is a tempting target for financial fraud, extortion, and black

Threat Actors IntelBroker Release Alleged Equifax Data on Underground Forum

Recently, a threat actor in an underground forum published an alleged data breach. This incident was revealed by a user named IntelBroker on BreachForums, a notorious online community for cybercriminal activities. According to IntelBroker, the data was obtained from an Equifax Staging Azure storage bucket. Currently, we are unable to accurately confirm the veracity of the breach, as no press release has been issued on the official website regarding the incident. Therefore, this article should be used as an “intelligence source.” Details of the Alleged Violation According to the post by IntelBroker, the breach involved the exfiltration of some files from an

Hospitals tremble! Ransomcortex arrives. ransomware gang targeting healthcare facilities

Recently, the landscape of cyber threats has been enriched by the emergence of a new ransomware group named “Ransomcortex”. This group is distinguished by its specialization in attacking healthcare facilities, having already collected four victims within a few days of its first appearance. Among these, three are Brazilian healthcare facilities and one is Canadian. The preference for attacks on the healthcare sector is not new, but Ransomcortex represents a significant evolution of this trend. Historical Context The interest of cybercriminals in healthcare organizations dates back several years, but recently there has been a significant increase in these attacks. One of the first

RHC interviews Vanir Group. Former affiliates of LockBit, Karakurt and Knight united to extort money: ‘Hire professionals, don’t be cheap’

New threat actors often emerge every day to destabilize the digital foundations of organizations around the world. One of the most recent and disturbing cybergangs uncovered by Darklab of Red Hot Cyber team is the VANIR group, a collective known for its ruthless ransomware operations. This exclusive interview, conducted by Dark Lab group, sheds light on an enemy as mysterious as it is dangerous. “You have to know the demons to learn how to counter them.” This phrase, frequently quoted by Red Hot Cyber in conferences and articles, underscores the importance of understanding the modus operandi of cyber criminals. Knowing the “demons”

Facebook Breach 2024: Sensitive User Data Up for Sale by Hacker on Breach Forums

Recently, a threat actor in an underground forum published an alleged data breach. This incident involves the purported exposure of a substantial Facebook user database. The compromised data includes sensitive user information such as full names, profiles, emails, phone numbers, date of birth, and locations. It is important to note that the information stems from a cybercriminal and should be approached with caution. Al momento, non possiamo confermare la veridicità della notizia, poiché l’organizzazione non ha ancora rilasciato alcun comunicato stampa ufficiale sul proprio sito web riguardo l’incidente. Pertanto, questo articolo deve essere considerato come ‘fonte di intelligence’. The reaction of interest

Threat Actors: Alleged Data Breach of Ukraine Traffic Police

Recently, a threat actor in an underground forum published an alleged data breach. The leak purportedly involves sensitive information from the Ukraine traffic police (GAI). The data, spanning millions of entries, was shared on the forum by a user named “Tanaka.” According to the forum post, the leaked dataset includes a comprehensive range of details about vehicle registrations, owners, and other pertinent information. Al momento, non possiamo confermare la veridicità della notizia, poiché l’organizzazione non ha ancora rilasciato alcun comunicato stampa ufficiale sul proprio sito web riguardo l’incidente. Pertanto, questo articolo deve essere considerato come ‘fonte di intelligence’. Details of the Alleged

Threat Actors Post Tennis Tournament Data Breach in Israel

Recently, a threat actor in an underground forum published an alleged data breach. This breach is claimed to have compromised the personal information of thousands of participants and instructors involved in a tennis tournament in Israel. The data includes sensitive details such as contact information, medical records, and national rankings, potentially putting those affected at risk of identity theft and other malicious activities. Given that this information was posted by a cybercriminal, its authenticity remains uncertain. At the moment, we cannot confirm the veracity of this report, as the organization has not yet issued an official statement regarding the incident on its

Potential Data Breach Hits Traderie: Roblox Trading Platform

In a concerning turn of events for the online trading community, a threat actor under the pseudonym “victim” has claimed responsibility for leaking a substantial database from Traderie, a popular trading platform for Roblox. The announcement was made on the notorious hacking forum BreachForums on June 28, 2024. The leaked database reportedly contains 392,270 records, which were allegedly breached in 2022. Details of the Breach According to the forum post, the breach was initially concealed due to a financial agreement which Traderie failed to honor, leading to the public disclosure of the data. The post features a sample of the compromised data,

Alleged Leak of the 2020 Israeli Voter Database

In a significant and concerning development, an individual using the alias “mrwan” has allegedly leaked the 2020 Israeli voter database. The personal data of all 6.5 million Israeli voters has been exposed, causing serious privacy and security concerns. Details of the Data Leak According to mrwan’s post, the data leak includes the following elements: Implications of the Data Leak The exposure of such a vast amount of personal data has several potential implications: Conclusion The alleged leak of the Israeli voter database is a serious incident with wide-ranging consequences. It underscores the importance of robust data security measures and the need for