mindly.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mindly.Social is an English speaking, friendly Mastodon instance created for people who want to use their brains and their hearts to make social networking more social. 🧠💖

Administered by:

Server stats:

1.3K
active users

#ransomware

36 posts32 participants1 post today

#NSA warns “fast flux” threatens national #security. What is fast flux anyway?

A technique that hostile nation-states & financially motivated #ransomware groups are using to hide their operations poses a threat to critical #infrastructure & national security, the NSA has warned.

The technique is known as #FastFlux. It allows decentralized networks operated by threat actors to hide their infrastructure and survive takedown attempts that would otherwise succeed
#privacy

arstechnica.com/security/2025/

Ars Technica · NSA warns “fast flux” threatens national security. What is fast flux anyway?By Dan Goodin

Daixin published some leak files titled "A little gift of exclusive data for everyone." They claim 17k PII PHI records. It looks like 17 sections of a database download. The attribute names look like it might be a pediatric hospital or something since most of them revolve around birth, peds, parents, etc. Also, at least the first several records appear to be UK based. If that sounds like it might be in your AO, you might want to look into it since the post wasn't titled anything obvious.

Rapid7 posted a good write-up on Babuk 2, which has been used against some interesting targets lately.

A sample named babuk.exe SHA-256 3facc153ed82a72695ee2718084db91f85e2560407899e1c7f6938fd4ea011e9 was initially shared on the Telegram channel “Babuk 2.0 Ransomware Affiliates”, before being forwarded to another operational account. Upon analysis, it turned out not to be Babuk Locker at all, but rather LockBit 3.0 also known as LockBit Black. This case is yet another example of the well-established trend: threat actors rebranding ransomware strains, whether to confuse researchers, lure affiliates, or just keep the marketing fresh. Either way, babuk.exe is just LockBit 3.0/Black wearing a fake name.

Babuk Locker 2.0 is not a true revival of the original Babuk group—it’s just LockBit 3.0 with a new label. Our analysis strongly suggests that Skywave and Bjorka are behind this operation, either as collaborators or opportunistic actors riding the same wave.

rapid7.com/blog/post/2025/04/0

Rapid7 · A Rebirth of a Cursed Existence? - The Babuk Locker 2.0 | Rapid7 BlogIn early 2025, we came across a channel promoting itself as Babuk Locker. Since the original group had shut down in 2021, we decided to investigate whether this was a rebrand or a new threat.