SpearTip | April 1st, 2022


Ransomware is no joke, as it continues to devastate businesses, communities, and critical infrastructure all over the world. This chapter of ‘Weekly Ransomware Wrap-Up’ demonstrates that the threat landscape continues to expand.

The Hive ransomware group has changed its Linux encryptors to the Rust programming language, borrowing features from BlackCat‘s malware. These developments are intended to make it more difficult for researchers to observe the ransom negotiation process.

An Irish charity supporting adults and children with disabilities, Rehab Group, was targeted in a recent cyberattack. While no services were impacted, sensitive client records were externally accessed.

Argentina-based software development company, Globant, suffered a major network breach following an attack by the Lapsus$ threat group. 70GB of data has already been leaked in the threat group’s latest extortion attempt.

SunCrypt ransomware claims responsibility for knocking the Oklahoma Indian Clinic systems offline and potentially stealing 350GB of sensitive data. The clinic serves 20,000 patients from over 200 Native American tribes.

In addition to its programming changes, the Hive ransomware group has taken credit for an attack compromising records from Partnership HealthPlan of California. Among the stolen data are approximately 850,000 documents containing patient PII.

SpearTip Defends You from ransomware.