Modern Ransomware’s Double Extortion Tactics and How to Protect Enterprises Against Them
ID: a102458e-e681-4a50-89e1-6cd16aa1b462
STIX ID: report--a102458e-e681-4a50-89e1-6cd16aa1b462
Threat Score
75/100
Uploaded: 2026-08-05
Published Date: 2026-08-05
Last Modified Date: 2026-08-05
Created by: gogogo
TLP:CLEAR
...
...
This report analyzes the Nefilim ransomware family and modern double-extortion tactics: initial access via weak RDP credentials, exposed HTTP services, and exploitation of critical vulnerabilities (e.g., Citrix CVE-2019-19781); evolution from Nemty and links to the "Water Roc" intrusion set; adversary behaviors include APT-like lateral movement, data theft prior to encryption, and criminal collaboration. It concludes with recommendations for cross-layered detection and response to prevent and mitigate ransomware impacts across corporate networks.
