As cited
Copy frozen at (site build).
ransomware
2608-volatility-interlock
Attackers belonging to the GOLD EMBRACE threat group have leveraged legitimate digital forensics and incident response (DFIR) tools to conduct double-extortion ransomware campaigns. The abuse of trusted security utilities allows adversaries to evade detection while conducting reconnaissance and data theft before deploying ransomware.
Why it matters: Defenders must monitor for suspicious behavior from legitimate DFIR tools in their environments, as attackers are weaponizing the same utilities they use for incident response and threat hunting.
- Source published
- First seen by Cybersecurity Tracker