Ransomware gang Everest has taken down its dark web leak site following its defacement in a cyberattack over the weekend by still-unknown threat actors, BleepingComputer reports.
Additional details regarding the compromise remain lacking but Everest's data leak site may have been compromised through the exploitation of a WordPress vulnerability, according to Flare Senior Threat Intelligence Researcher Tammy Harper, who noted the usage of a WordPress template for the website. More than 230 organizations have already been breached by Everest, also a known initial access broker, since its emergence five years ago, with major California marijuana dispensary STIIIZY among its latest victims. Everest which initially focused on data theft alone before eventually integrating ransomware for systems encryption as part of double-extortion attacks was also reported by the U.S. Department of Health and Human Services to have escalated intrusions aimed at U.S. healthcare providers.
An In-Depth Guide to Ransomware
Get essential knowledge and practical strategies to protect your organization from ransomware attacks.
In a report by Bleeping Computer, threat actors are exploiting Steam discussion forums to distribute cryptominers through a social engineering tactic known as ClickFix.
Phishing campaigns targeting financial institutions are evolving from credential harvesting for later use to real-time account hijacking, based on information published by The Hacker News.
Botnets powered by residential proxy networks are proliferating, enabling cybercriminals to evade detection by blending in with legitimate traffic, Lumen Technology’s Black Lotus Labs said in a report.