Threat actors
As you will have understood already, this book is devoted to human-operated ransomware attacks. So, the threat actors we are dealing with are humans, and humans tend to communicate and share. One of the most common media used for such sharing is underground forums.
In this section, we'll look at some forum posts, collected by the Group-IB Threat Intelligence and Attribution platform.
The first post we'll look at is created by a threat actor with the nickname FishEye, who is known to be affiliated with REvil, LockBit, and some other ransomware strains. You can see it here:
In this post, the threat actor shows their interest in obtaining a working exploit for a vulnerability in the SonicWall VPN. The threat actor points out the fact that Conti ransomware affiliates already have it and use it in their campaigns.
Most likely, the threat actor is writing about a vulnerability in SonicWall Secure...