Feral Wolf is using exposed business software and weak server settings to reach corporate networks, then locking files with ransomware. The campaign shows how one overlooked internet-facing system can become the starting point for a much larger incident. The group targeted Russian organizations in retail, construction, manufacturing, and information technology from May through August 2026. Its operators combined exploitation, stolen or weak credentials, remote access, and custom backdoors before deploying GenieLocker to encrypt data. Analysts at BI.ZONE identified the activity while investigating the intrusions, documenting paths through vulnerable Atlassian Confluence installations, contractor environments, and poorly protected...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!