Is Vendetta

Threat Actor updated 4 months ago (2024-05-04T20:42:11.513Z)
Download STIX
Preview STIX
V is Vendetta is a recently discovered vulnerability that appears to be associated with the notorious ransomware group known as Cuba (also referred to as COLDDRAW and Tropical Scorpius). The link between the two entities became apparent when it was found that V is Vendetta's website is hosted on the same domain used by the Cuba gang. This connection, along with the deviation from the usual Cuban theme in naming conventions, suggests that V is Vendetta might be a moniker used by a subgroup or affiliate of the main hacker group. The V is Vendetta vulnerability came into prominence in February this year, when it published information about three victims on its leak site. This site uses imagery derived from a mid-2000s dystopian action film, a practice that is not uncommon among such entities. Despite the newness of the group, their tactics appear to be well-established and potentially damaging to those who fall victim to their attacks. In light of these findings, cybersecurity firm Kaspersky has detailed the tactics, techniques, and procedures of the Cuba ransomware group, including the newly identified V is Vendetta moniker. As of the time of writing, the V is Vendetta website remains active, and reports of new extortion victims continue to surface. This ongoing activity underscores the importance of understanding and mitigating this threat to cybersecurity.
Description last updated: 2023-10-11T00:59:14.697Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Is Vendetta Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CERT-EU
a year ago
Microsoft Warns of New Phishing Campaign Targeting Corporations via Teams Messages | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware | National Cyber Security Consulting
CERT-EU
a year ago
From Caribbean shores to your devices: analyzing Cuba ransomware – GIXtools
Securelist
a year ago
Analysis of Cuba ransomware gang activity and tooling
Malwarebytes
a year ago
Ransomware review: March 2023