Archive

Ongoing report: Babuk2 (Babuk-Bjorka)

January 29, 2025 Editor’s note: We will continue to provide updates as further information is forthcoming.

GRIT 2025 Report: Post-Compromise Detection Strategies

January 28, 2025 This blog marks the beginning of a series based on the findings in the GRIT 2025 Ransomware and Cyber Threat Report.

Unveiling the GRIT 2025 Ransomware and Cyber Threat Report

January 16, 2025 The ransomware landscape is shifting, and understanding these changes is critical to staying ahead.

RansomHub Affiliate leverages Python-based backdoor

January 15, 2025 In an incident response in Q4 of 2024, GuidePoint Security identified evidence of a threat actor utilizing a Python-based backdoor to maintain access to compromised endpoints.

To Pay or Not to Pay: The Ransomware Dilemma

November 14, 2024 Disclaimer: In the majority of cases, the determination of whether or not to pay a ransom is a business decision, and this blog is intended solely to help decision-makers navigate th…

Quarterly GRIT Ransomware Report — Q3 2024

October 17, 2024 As we wrap up the third quarter of 2024, it’s time to dive into the key takeaways from GRIT’s latest analysis on ransomware and cyber threat trends from Q3.

Risky Recovery: Ransomware “Decryption” Scams Remain in 2024

September 19, 2024 Note: To protect the identity of the individuals involved in these events, some details of the ransomware attack and recovery company have been altered.

GRIT Ransomware Report: August 2024

September 12, 2024 Additional contributors to this report: Jason Baker, Ryan Silver, JP Mouton, and Grayson North In this month’s report, we highlight the Ransomware group, Black Suit, the only rans…

Hazard Ransomware – A Successful Broken Encryptor Story

September 10, 2024 Ransomware encryption can be one of the most devastating security events for an organization, potentially halting operations and causing significant financial and emotional stress.

So-Phish-ticated Attacks

Update: September 16, 2024 Authors: Rui Ataide, Hermes Bojaxhi GuidePoint Security is continuing to monitor this ongoing campaign.

GRIT Ransomware Report: July 2024

August 15, 2024 Additional contributors to this report: Jason Baker, Justin Timothy, Ryan Silver, and JP Mouton July 2024 yielded some answers to our ongoing questions about the future of ransomware, …

Update from the Ransomware Trenches

August 14, 2024 Authors: Rui Ataide, Hermes Bojaxhi GuidePoint’s DFIR team is frequently called upon to respond to Ransomware incidents.