CYBERSECURITYTRACKER
TRACKING7,159 stories in this site build1,507 vulnerability news stories in this site build
Permanent story citation

2608-volatility-interlock

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3864

As cited

Copy frozen at (site build).

ransomware

2608-volatility-interlock

Attackers belonging to the GOLD EMBRACE threat group have leveraged legitimate digital forensics and incident response (DFIR) tools to conduct double-extortion ransomware campaigns. The abuse of trusted security utilities allows adversaries to evade detection while conducting reconnaissance and data theft before deploying ransomware.

Why it matters: Defenders must monitor for suspicious behavior from legitimate DFIR tools in their environments, as attackers are weaponizing the same utilities they use for incident response and threat hunting.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary