Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Are open-ear headphones viable in 2025? Listen for the first time, this pair gave a bold statement

    November 10, 2025

    I saw the future of TV in Samsung’s South Korea lab — and I’m excited for these 3 things

    November 9, 2025

    Very few people are talking about this budget laptop from Lenovo that over-delivers

    November 9, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Open-source DFIR VelociRaptor misused in expanding ransomware attempts
    Security

    Open-source DFIR VelociRaptor misused in expanding ransomware attempts

    PineapplesUpdateBy PineapplesUpdateOctober 11, 2025No Comments1 Min Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Open-source DFIR VelociRaptor misused in expanding ransomware attempts
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Open-source DFIR VelociRaptor misused in expanding ransomware attempts

    “VelociRaptor played a critical role in this campaign, ensuring that actors secretly maintained continuous access while deploying the Lockbit and Babuk ransomware,” Talos researchers said. “The inclusion of this tool in the ransomware playbook is consistent with Talos’ findings.”2024 year in review,’ which highlights that threat actors are using an increasing variety of commercial and open-source products.’

    Attribution and ransomware cocktail

    Talos linked the campaign to Storm-2603, a suspected China-based threat actor, citing matching TTPs such as use of ‘cmd.exe’, disabling Defender protection, creating scheduled tasks, and manipulating Group Policy objects. The use of multiple ransomware strains – Warlock, Lockbit, and Babuk – in the same operation also adds credence to this attribution.

    “Talos observed ransomware executables on Windows machines that were identified as Lockbit by EDR solutions, and were files encrypted with the Warlock extension ‘xlockxlock,'” the researchers said. “There was also a Linux binary on the ESXi server marked as Babyk Encryptor, which achieved only partial encryption and appended files with ‘.babyk’.”

    attempts DFIR expanding misused opensource Ransomware VelociRaptor
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleGet T-Mobile 5G Home Internet for $30/mo when you bundle it with a phone line – here’s how
    Next Article Hackers are exploiting a zero-day in Gladinet file sharing software
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    No one pays ransomware demands anymore – so attackers have a new target

    October 28, 2025
    Security

    Your Uber driver has a new endeavor: training an AI for cash

    October 18, 2025
    Security

    American Airlines subsidiary Envoy confirms Oracle data breach attack

    October 18, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    Are open-ear headphones viable in 2025? Listen for the first time, this pair gave a bold statement

    November 10, 2025

    I saw the future of TV in Samsung’s South Korea lab — and I’m excited for these 3 things

    November 9, 2025

    Very few people are talking about this budget laptop from Lenovo that over-delivers

    November 9, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.