Ransomware Tool Matrix Project Updates: Three Groups To Track
Introduction This blog is a focused update on the latest updates to the Ransomware Tool Matrix (RTM) and the Ransomware Vulnerability Matrix (RVM) covering three groups that I have published profiles for to help defenders home in on the threats most relevant to them: TheGentlemen, DragonForce, and WarLock. Rather than write another broad ecosystem summary, the goal of this post is to introduce these profiles, briefly explain why each group matters right now, and give readers direct links to them so defenders can pivot straight into hunting, detection engineering, and patch prioritisation. For anyone new to the projects, please read the descriptions on GitHub or feel free to watch my talk explaining the project at BSides London . Why these three groups? Each of the three groups added in this update represents a different slice of the current ransomware ecosystem: TheGentlemen TheGentlemen is a newer operation that has matured quickly, with a large and...