May 15, 2023, 12:35 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news


  • Cisco Talos recently discovered a new ransomware actor called RA Group that has been operating since at least April 22, 2023.

  • The actor is swiftly expanding its operations. To date, the group has compromised three organizations in the U.S. and one in South Korea across several business verticals, including manufacturing, wealth management, insurance providers and pharmaceuticals.

  • Talos assesses with high confidence that RA Group is leveraging leaked Babuk ransomware source code.

Who is the RA Group?

Talos recently discovered a …

actor april babuk called cisco cisco talos code companies compromised korea leaked operations organizations ra group ransomware source code south south korea talos

Principal Security Engineer

@ Elsevier | Home based-Georgia

Infrastructure Compliance Engineer

@ NVIDIA | US, CA, Santa Clara

Information Systems Security Engineer (ISSE) / Cybersecurity SME

@ Green Cell Consulting | Twentynine Palms, CA, United States

Sales Security Analyst

@ Everbridge | Bengaluru

Alternance – Analyste Threat Intelligence – Cybersécurité - Île-de-France

@ Sopra Steria | Courbevoie, France

Third Party Cyber Risk Analyst

@ Chubb | Philippines