Elektrine lite

โ† Feed

amvinfe

amvinfe@infosec.exchange

<p>Cyber security researcher and blogger</p>

Posts

  • Post #4496258

    ๐’๐ข๐ง๐ ๐ข๐ง๐  ๐‘๐ข๐ฏ๐ž๐ซ ๐‡๐ž๐š๐ฅ๐ญ๐ก ๐’๐ฒ๐ฌ๐ญ๐ž๐ฆ: ๐๐ž๐ญ๐ฐ๐ž๐ž๐ง ๐‘๐š๐ง๐ฌ๐จ๐ฆ๐ฐ๐š๐ซ๐ž, ๐‹๐ž๐ ๐š๐ฅ ๐ƒ๐ข๐ฌ๐ฉ๐ฎ๐ญ๐ž๐ฌ, ๐š๐ง๐ ๐‘๐ž๐œ๐ฎ๐ซ๐ซ๐ข๐ง๐  ๐•๐ฎ๐ฅ๐ง๐ž๐ซ๐š๐›๐ข๐ฅ๐ข๐ญ๐ข๐ž๐ฌ Just over two years after the devastating ransomware attack attributed to the Rhysida group, Singing River Health System (SRHS) has once again fallen victim to cybercrime. This time, the Anubis ransomware group has claimed responsibility for compromising the healthcare organizationโ€™s IT systems, stating that it stole sensitive data belonging to patients and employees before encrypting the infrastructu...

  • Post #4496257

    ๐„๐ฏ๐ž๐ซ๐ž๐ฌ๐ญ: ๐’๐ข๐ฑ ๐˜๐ž๐š๐ซ๐ฌ ๐จ๐Ÿ ๐„๐ฏ๐จ๐ฅ๐ฎ๐ญ๐ข๐จ๐ง ๐Ÿ๐ซ๐จ๐ฆ ๐ƒ๐š๐ญ๐š ๐‹๐ž๐š๐ค ๐ญ๐จ ๐ƒ๐จ๐ฎ๐›๐ฅ๐ž ๐„๐ฑ๐ญ๐จ๐ซ๐ญ๐ข๐จ๐ง โ€“ ๐ญ๐ก๐ž ๐ข๐ง๐ญ๐ž๐ซ๐ฏ๐ข๐ž๐ฐ The responses provided to SuspectFile paint a picture of a group that claims to have grown gradually and demonstrated a consistent ability to adapt. One of the most interesting aspects concerns the shift from extortion based solely on stolen data to the adoption of encryption. https://www.suspectfile.com/everest-six-years-of-evolution-from-data-leak-to-double-extortion-the-interview/ #ALPHV #Black_Basta #Doubl...

  • Post #4496256

    @verisizintisi @PogoWasRight @jerry @JayeLTee Hi, I read your article on HCRG and I think you may be mistaken about some of your writing. In one passage, you write, &amp;quot;The entity directly affected by the attack is CRG Medical Services, a subsidiary of HCRG that provides forensic medical services to police forces.&amp;quot; Can I ask where you got this information? Has it been verified by you? If it has been verified, can you provide evidence? I think, I&amp;#39;m sure, you&amp;#39;re mis...

  • Post #4496255

    ๐—ก๐—ผ๐˜ƒ๐—ฎ ๐—–๐—น๐—ฎ๐—ถ๐—บ๐˜€ ๐—”๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€ ๐˜๐—ผ ๐—ก๐—ฆ๐—ช ๐—ฆ๐˜†๐˜€๐˜๐—ฒ๐—บ๐˜€: ๐—•๐—ฒ๐˜๐˜„๐—ฒ๐—ฒ๐—ป ๐Ÿฐ๐Ÿฌ๐Ÿฌ ๐—š๐—• ๐—˜๐˜…๐—ณ๐—ถ๐—น๐˜๐—ฟ๐—ฎ๐˜๐—ฒ๐—ฑ ๐—ฎ๐—ป๐—ฑ ๐——๐—ฎ๐˜๐—ฎ ๐——๐—ถ๐˜€๐—ฝ๐˜‚๐˜๐—ฒ๐—ฑ ๐—ฏ๐˜† ๐—”๐˜‚๐˜๐—ต๐—ผ๐—ฟ๐—ถ๐˜๐—ถ๐—ฒ๐˜€ The story emerged in recent days via the ๐๐จ๐ฏ๐š ๐ ๐ซ๐จ๐ฎ๐ฉโ€™๐ฌ ๐๐š๐ญ๐š ๐ฅ๐ž๐š๐ค ๐ฉ๐จ๐ซ๐ญ๐š๐ฅ, where the ransomware operators ๐—น๐—ถ๐˜€๐˜๐—ฒ๐—ฑ ๐˜๐—ต๐—ฒ ๐—ก๐—ฒ๐˜„ ๐—ฆ๐—ผ๐˜‚๐˜๐—ต ๐—ช๐—ฎ๐—น๐—ฒ๐˜€ ๐—ด๐—ผ๐˜ƒ๐—ฒ๐—ฟ๐—ป๐—บ๐—ฒ๐—ป๐˜ among their alleged victims, claiming to have gained access to a hashtag #Citrix system and exfiltrated a significant amount of data. https://www.suspectfile.com/nova-claims-access-to-nsw-systems-between-400-gb-exfiltrated-and-data-disputed-by-authorities/ #Cit...

  • Post #4496254

    ๐—š๐—น๐—ผ๐—ฏ๐—ฎ๐—น ๐—ฆ๐—ฐ๐—ต๐—ผ๐—ผ๐—น๐˜€ ๐—š๐—ฟ๐—ผ๐˜‚๐—ฝ ๐—ฎ๐—ป๐—ฑ ๐—™๐˜‚๐—น๐—ฐ๐—ฟ๐˜‚๐—บ๐—ฆ๐—ฒ๐—ฐ: ๐—” ๐— ๐—ฎ๐˜€๐˜€๐—ถ๐˜ƒ๐—ฒ ๐——๐—ฎ๐˜๐—ฎ ๐—•๐—ฟ๐—ฒ๐—ฎ๐—ฐ๐—ต ๐—ฎ๐—ป๐—ฑ ๐˜๐—ต๐—ฒ ๐—ช๐—ผ๐—ฟ๐—น๐—ฑ๐˜„๐—ถ๐—ฑ๐—ฒ ๐—ฃ๐˜‚๐˜€๐—ต ๐˜๐—ผ ๐—ฆ๐˜‚๐—ฝ๐—ฝ๐—ฟ๐—ฒ๐˜€๐˜€ ๐—ฅ๐—ฒ๐—ฝ๐—ผ๐—ฟ๐˜๐—ถ๐—ป๐—ด ๐—ผ๐—ป ๐—œ๐˜ Among the statements attributed to FulcrumSec are allegations of particularly poor security practices. The group claims to have identified administrative credentials reused across numerous systems, passwords stored in plaintext, #AWS access keys embedded directly within application code, and databases relying on credentials that had reportedly remained unchanged for years. https://www....

  • Post #4496253

    ๐—–๐˜†๐—ฏ๐—ฒ๐—ฟ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—œ๐—ป๐—ฐ๐—ถ๐—ฑ๐—ฒ๐—ป๐˜๐˜€: ๐—ช๐—ต๐—ฒ๐—ป ๐˜๐—ต๐—ฒ ๐—ฃ๐—ฟ๐—ผ๐—ฏ๐—น๐—ฒ๐—บ ๐—œ๐˜€ ๐—ก๐—ผ๐˜ ๐—ข๐—ป๐—น๐˜† ๐—ช๐—ต๐—ผ ๐—”๐˜๐˜๐—ฎ๐—ฐ๐—ธ๐˜€ In this context, attackersโ€™ ability to exploit existing vulnerabilities is intertwined with a less discussed but equally crucial reality: the accumulation of technical and organizational weaknesses that often remains unresolved until data exfiltration occurs. https://www.suspectfile.com/cybersecurity-incidents-when-the-problem-is-not-only-who-attacks/ #Cybersecurity #Data_Breaches #Data_Protection #Digital_Privacy #Ransomware

  • Post #4496252

    ๐—š๐—น๐—ผ๐—ฏ๐—ฎ๐—น ๐—ฆ๐—ฐ๐—ต๐—ผ๐—ผ๐—น๐˜€ ๐—š๐—ฟ๐—ผ๐˜‚๐—ฝ, ๐—ฟ๐—ฒ๐—ป๐—ฒ๐˜„๐—ฒ๐—ฑ ๐—ฝ๐—ฟ๐—ฒ๐˜€๐˜€๐˜‚๐—ฟ๐—ฒ ๐—ผ๐—ป ๐——๐—ฎ๐˜๐—ฎ๐—•๐—ฟ๐—ฒ๐—ฎ๐—ฐ๐—ต๐—ฒ๐˜€: ๐˜๐—ต๐—ฒ ๐—จ๐—ฆ ๐˜€๐—ถ๐˜๐—ฒ ๐—ฟ๐—ฒ๐—ท๐—ฒ๐—ฐ๐˜๐˜€ ๐—ฎ๐˜๐˜๐—ฒ๐—บ๐—ฝ๐˜๐˜€ ๐˜๐—ผ ๐—ฐ๐—ฒ๐—ป๐˜€๐—ผ๐—ฟ ๐—ฑ๐—ฎ๐˜๐—ฎ ๐—ฏ๐—ฟ๐—ฒ๐—ฎ๐—ฐ๐—ต ๐—ฐ๐—ผ๐˜ƒ๐—ฒ๐—ฟ๐—ฎ๐—ด๐—ฒ The U.S. site emphasizes that it was not named in either ordinance and has no presence or activity in India or Singapore. For this reason, he had already responded to the law firm on June 23, stating that he did not consider himself subject to the jurisdiction of the courts of the two countries and that she did not intend to take any action as a result of the injunctions. https:/...

  • Post #4496251

    ๐—ฅ๐—ฎ๐—ป๐˜€๐—ผ๐—บ๐˜„๐—ฎ๐—ฟ๐—ฒ ๐—ถ๐—ป ๐—œ๐˜๐—ฎ๐—น๐˜†: ๐—ฅ๐—ฒ๐—ฑ๐—”๐—–๐—ง ๐—ฟ๐—ฒ๐—ฝ๐—ผ๐—ฟ๐˜ ๐˜€๐—ต๐—ฒ๐—ฑ๐˜€ ๐—น๐—ถ๐—ด๐—ต๐˜ ๐—ผ๐—ป ๐—ฎ๐—ป ๐—ฒ๐˜ƒ๐—ผ๐—น๐˜ƒ๐—ถ๐—ป๐—ด ๐˜๐—ต๐—ฟ๐—ฒ๐—ฎ๐˜ ๐—ฒ๐—ป๐˜ƒ๐—ถ๐—ฟ๐—ผ๐—ป๐—บ๐—ฒ๐—ป๐˜ The report highlights how Italy continues to represent a frequent target for numerous ransomware groups. Organizations affected belong to very different sectors, including manufacturing, services, healthcare, technology, and industrial companies. https://www.suspectfile.com/ransomware-in-italy-redact-report-sheds-light-on-an-evolving-threat-environment/ #Cyber_Threat_Intelligence #Cybercrime #OSINT #ransomNews_on...

  • Post #4427861

    ๐—ข๐—ฉ๐—ฃ ๐—›๐—ฒ๐—ฎ๐—น๐˜๐—ต ๐˜๐—ฎ๐—ฟ๐—ด๐—ฒ๐˜๐—ฒ๐—ฑ ๐—ฏ๐˜† ๐—ฆ๐˜๐—ผ๐—ฟ๐—บ: ๐—ฟ๐—ฎ๐—ป๐˜€๐—ผ๐—บ๐˜„๐—ฎ๐—ฟ๐—ฒ ๐—ด๐—ฟ๐—ผ๐˜‚๐—ฝ ๐—ฐ๐—น๐—ฎ๐—ถ๐—บ๐˜€ ๐˜๐—ต๐—ฒ๐—ณ๐˜ ๐—ผ๐—ณ ๐Ÿญ๐Ÿฏ๐Ÿฌ ๐—š๐—• ๐—ผ๐—ณ ๐—ต๐—ฒ๐—ฎ๐—น๐˜๐—ต๐—ฐ๐—ฎ๐—ฟ๐—ฒ ๐—ฑ๐—ฎ๐˜๐—ฎ One characteristic Storm claims to have adopted concerns the negotiation process. The operators stated that there is no human negotiator involved within the service and that all negotiation stages are automated. Human assistance would reportedly be limited exclusively to technical issues and decryption-related requests. https://www.suspectfile.com/ovp-health-targeted-by-storm-ransomware-group-claims-theft-...

  • Post #4174239

    ๐—˜๐˜…๐—ฐ๐—น๐˜‚๐˜€๐—ถ๐˜ƒ๐—ฒ: ๐—•๐—ฎ๐˜๐—ต ๐—™๐—ถ๐˜๐˜๐—ฒ๐—ฟ ๐—–๐—น๐—ฎ๐—ถ๐—บ๐—ฒ๐—ฑ ๐—ฏ๐˜† ๐—”๐—ป๐˜‚๐—ฏ๐—ถ๐˜€ ๐—ฅ๐—ฎ๐—ป๐˜€๐—ผ๐—บ๐˜„๐—ฎ๐—ฟ๐—ฒ, ๐—”๐—น๐—น๐—ฒ๐—ด๐—ฒ๐—ฑ ๐Ÿฒ๐Ÿฌ๐Ÿฌ ๐—š๐—• ๐——๐—ฎ๐˜๐—ฎ ๐—ง๐—ต๐—ฒ๐—ณ๐˜ ๐—™๐—ผ๐—น๐—น๐—ผ๐˜„๐—ฒ๐—ฑ ๐—ฏ๐˜† ๐—ฎ $๐Ÿฎ.๐Ÿฏ๐Ÿฑ ๐— ๐—ถ๐—น๐—น๐—ถ๐—ผ๐—ป ๐—˜๐˜…๐˜๐—ผ๐—ฟ๐˜๐—ถ๐—ผ๐—ป ๐—ก๐—ฒ๐—ด๐—ผ๐˜๐—ถ๐—ฎ๐˜๐—ถ๐—ผ๐—ป The negotiations, a copy of which was provided by Anubis to SuspectFile, document a familiar pattern increasingly observed in modern double-extortion ransomware operations: technical proof of compromise, demonstrations of data possession, decryptor testing, financial negotiations, and the eventual threat of public disclosure. https://www.suspectfile.com/exclusive-bat...

  • Post #3886266

    ๐—ก๐—ฎ๐˜ƒ๐—ถ๐—ด๐—ฎ๐˜๐—ฒ๐Ÿฏ๐Ÿฒ๐Ÿฌ ๐—ฎ๐—ป๐—ฑ ๐—ฃ๐Ÿฏ ๐—š๐—น๐—ผ๐—ฏ๐—ฎ๐—น ๐—œ๐—ป๐˜๐—ฒ๐—น: ๐—™๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ฒ ๐—ฝ๐—ฟ๐—ผ๐—บ๐—ถ๐˜€๐—ฒ ๐—ผ๐—ณ โ€œ๐Ÿฎ๐Ÿฌ+ ๐˜†๐—ฒ๐—ฎ๐—ฟ๐˜€ ๐—ฎ๐—ป๐—ฑ ๐˜‡๐—ฒ๐—ฟ๐—ผ ๐˜ƒ๐—ถ๐—ผ๐—น๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐˜€โ€ ๐˜๐—ผ ๐˜๐—ต๐—ฟ๐—ฒ๐—ฒ ๐—บ๐—ผ๐—ป๐˜๐—ต๐˜€ ๐—ผ๐—ณ ๐˜€๐—ถ๐—น๐—ฒ๐—ป๐—ฐ๐—ฒ The P3 Global Intel platform was designed to collect reports regarding potentially critical situations within school communities. This means that the information involved could pertain to incidents, behaviors, or circumstances that fall within an extremely private aspect of the lives of students and their families. https://www.suspectfile.com/navigate360-and-p3-global-intel-from-the...

  • Post #3836561

    ๐—›๐˜†๐—ณ๐—น๐—ผ๐—ฐ๐—ธ ๐—ฎ๐—ป๐—ฑ ๐—ก๐—ผ๐˜ƒ๐—ฎ: ๐—” ๐—ฃ๐—ฟ๐—ถ๐˜ƒ๐—ฎ๐˜๐—ฒ ๐—–๐—ผ๐—ป๐˜ƒ๐—ฒ๐—ฟ๐˜€๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ฃ๐—ฟ๐—ผ๐˜ƒ๐—ถ๐—ฑ๐—ฒ๐˜€ ๐—ฎ ๐—š๐—น๐—ถ๐—บ๐—ฝ๐˜€๐—ฒ ๐—ถ๐—ป๐˜๐—ผ ๐—ฅ๐—ฎ๐—ป๐˜€๐—ผ๐—บ๐˜„๐—ฎ๐—ฟ๐—ฒ ๐—š๐—ฟ๐—ผ๐˜‚๐—ฝ ๐——๐˜†๐—ป๐—ฎ๐—บ๐—ถ๐—ฐ๐˜€ The chat, which took place between July 1 and July 6, 2026, concerns a request to join Novaโ€™s affiliate program and contains a series of statements regarding the Hyflock group, the interlocutorโ€™s role, and his alleged technical expertise. https://www.suspectfile.com/hyflock-and-nova-a-private-conversation-provides-a-glimpse-into-ransomware-group-dynamics/ #Hyflock #LockBit #Nova #Qilin #RaaS #Ransomware

  • Post #3770691

    ๐—ก๐—ผ๐—ฟ๐˜๐—ต๐—ฒ๐—ฎ๐˜€๐˜ ๐—ฃ๐—ฒ๐—ฑ๐—ถ๐—ฎ๐˜๐—ฟ๐—ถ๐—ฐ๐˜€ ๐—ฒ๐—ป๐˜๐—ฒ๐—ฟ๐˜€ ๐—ป๐—ฒ๐—ด๐—ผ๐˜๐—ถ๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐˜€ ๐˜„๐—ถ๐˜๐—ต ๐—”๐—ป๐˜‚๐—ฏ๐—ถ๐˜€, ๐˜๐—ต๐—ฒ๐—ป ๐˜€๐—ถ๐—น๐—ฒ๐—ป๐—ฐ๐—ฒ. ๐—ฆ๐˜‚๐˜€๐—ฝ๐—ฒ๐—ฐ๐˜๐—™๐—ถ๐—น๐—ฒ ๐—ฟ๐—ฒ๐—ฐ๐—ผ๐—ป๐˜€๐˜๐—ฟ๐˜‚๐—ฐ๐˜๐˜€ ๐˜๐—ต๐—ฒ ๐—ป๐—ฒ๐—ด๐—ผ๐˜๐—ถ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐˜๐—ต๐—ฎ๐˜ ๐—ฝ๐—ฟ๐—ฒ๐—ฐ๐—ฒ๐—ฑ๐—ฒ๐—ฑ ๐˜๐—ต๐—ฒ ๐—ฑ๐—ฎ๐˜๐—ฎ ๐—ฝ๐˜‚๐—ฏ๐—น๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป For ethical and privacy reasons, SuspectFile has chosen not to analyze or describe documentation relating to minor patients, as Northeast Pediatrics is a healthcare facility specialized in pediatric care. https://www.suspectfile.com/northeast-pediatrics-enters-negotiations-with-anubis-then-silence-suspectfile-reconstructs-the-negotiation-that-preceded-...