{"id":54900,"date":"2023-12-20T13:20:28","date_gmt":"2023-12-20T13:20:28","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/35324\/Play-Ransomware-Gang-Tied-To-300-Attacks-In-17-Months.html"},"modified":"2023-12-20T13:20:28","modified_gmt":"2023-12-20T13:20:28","slug":"play-ransomware-gang-tied-to-300-attacks-in-17-months","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/play-ransomware-gang-tied-to-300-attacks-in-17-months\/","title":{"rendered":"Play Ransomware Gang Tied To 300 Attacks In 17 Months"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/files.scmagazine.com\/wp-content\/uploads\/2023\/12\/Ransomware-Kid.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>Several disruptive attacks against U.S. municipal services this year were just the tip of the iceberg for the Play ransomware gang which, according to the FBI, hit almost 300 organizations in 17 months.<\/p>\n<p>The threat group made headlines this year for attacks on the cities of <a href=\"https:\/\/www.scmagazine.com\/brief\/oakland-still-grappling-to-recover-from-ransomware-attack\">Oakland, California<\/a> and <a href=\"https:\/\/www.scmagazine.com\/brief\/massachusetts-city-targeted-by-play-ransomware-operation\">Lowell, Massachusetts<\/a>, along with <a href=\"https:\/\/www.scmagazine.com\/brief\/play-ransomware-attack-confirmed-by-dallas-county\">Dallas County, Texas<\/a>. It has also claimed responsibility for a November attack against <a href=\"https:\/\/www.scmagazine.com\/brief\/cyberattack-hits-central-virginia-transit-system\">Virginia\u2019s Greater Richmond Transit Company<\/a>.<\/p>\n<p>But its impact has extended beyond upending the delivery of public services and stealing citizen data.<\/p>\n<p>Between June 2022 and October 2023, the gang exploited approximately 300 entities, according to a Dec. 18 <a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-352a\">joint cybersecurity advisory<\/a> from the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and the Australian Signals Directorate\u2019s Cyber Security Centre.<\/p>\n<p>In the advisory, the agencies said the group (also known as Playcrypt) impacted a wide range of businesses and critical infrastructure in North America, South America, and Europe. In Australia, its first incident was observed in April 2023 and the most recent one was in November.<\/p>\n<p>\u201cThe Play ransomware group is presumed to be a closed group, designed to \u2018guarantee the secrecy of deals,\u2019 according to a statement on the group\u2019s data leak website,\u201d the advisory read.<\/p>\n<p>\u201cPlay ransomware actors employ a double-extortion model, encrypting systems after exfiltrating data. Ransom notes do not include an initial ransom demand or payment instructions, rather, victims are instructed to contact the threat actors via email.\u201d<\/p>\n<p>The gang generally gained initial access to victims\u2019 networks either by abusing stolen account credentials or by exploiting public-facing applications. It was known to take advantage of known vulnerabilities in FortiOS (<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2018-13379\">CVE-2018-13379<\/a> and <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2020-12812\">CVE-2020-12812<\/a>) and <a href=\"https:\/\/www.scmagazine.com\/analysis\/ransomware-groups-use-new-exploit-to-bypass-proxynotshell-mitigations-for-microsoft-exchange\">ProxyNotShell vulnerabilities<\/a> in Microsoft Exchange (<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-41040\">CVE-2022-41040<\/a> and <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2022-41082\">CVE-2022-41082<\/a>).<\/p>\n<p>The group used a mix of repurposed legitimate tools and custom tools in its attacks which were recognizable because of the gang\u2019s practice of adding a \u201c.play\u201d extension to file names during the exfiltration and encryption process.<\/p>\n<p>\u201c[The group uses] tools like GMER, IOBit, and PowerTool to disable anti-virus software and remove log files. In some instances, cybersecurity researchers have observed Play ransomware actors using PowerShell scripts to target Microsoft Defender,\u201d the agencies said.<\/p>\n<p>In a post last month, researchers at Adlumin said they had uncovered evidence the Play gang had recently begun selling the malware on <a href=\"https:\/\/adlumin.com\/post\/playcrypt-ransomware-as-a-service-expands-threat-from-script-kiddies-and-sophisticated-attackers\/\">a ransomware-as-a-service basis<\/a>.<\/p>\n<p>\u201cMaking it available to affiliates that might include sophisticated hackers, less-sophisticated \u2018script kiddies\u2019 and various levels of expertise in between, could dramatically increase the volume of attacks using the highly successful, Russia-linked Play ransomware,\u201d the researchers said.<\/p>\n<p>The agencies who issued the joint advisory recommended a range of steps organizations should take to mitigate against the ransomware gang. These included: prioritizing the remediation of known exploited vulnerabilities, enabling multifactor authentication wherever possible (particularly for webmail, VPNs, and accounts that access critical systems), ensuring software and applications were regularly patched and updated, and conducting regular vulnerability assessments.<\/p>\n<p>READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/35324\/Play-Ransomware-Gang-Tied-To-300-Attacks-In-17-Months.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":54901,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[8372],"class_list":["post-54900","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlinehackermalwarecybercrimefraudcryptography"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Play Ransomware Gang Tied To 300 Attacks In 17 Months 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/play-ransomware-gang-tied-to-300-attacks-in-17-months\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Play Ransomware Gang Tied To 300 Attacks In 17 Months 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/play-ransomware-gang-tied-to-300-attacks-in-17-months\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2023-12-20T13:20:28+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/files.scmagazine.com\/wp-content\/uploads\/2023\/12\/Ransomware-Kid.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/play-ransomware-gang-tied-to-300-attacks-in-17-months\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/play-ransomware-gang-tied-to-300-attacks-in-17-months\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Play Ransomware Gang Tied To 300 Attacks In 17 Months\",\"datePublished\":\"2023-12-20T13:20:28+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/play-ransomware-gang-tied-to-300-attacks-in-17-months\\\/\"},\"wordCount\":489,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/play-ransomware-gang-tied-to-300-attacks-in-17-months\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/play-ransomware-gang-tied-to-300-attacks-in-17-months.jpg\",\"keywords\":[\"headline,hacker,malware,cybercrime,fraud,cryptography\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/play-ransomware-gang-tied-to-300-attacks-in-17-months\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/play-ransomware-gang-tied-to-300-attacks-in-17-months\\\/\",\"name\":\"Play Ransomware Gang Tied To 300 Attacks In 17 Months 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/play-ransomware-gang-tied-to-300-attacks-in-17-months\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/play-ransomware-gang-tied-to-300-attacks-in-17-months\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/play-ransomware-gang-tied-to-300-attacks-in-17-months.jpg\",\"datePublished\":\"2023-12-20T13:20:28+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/play-ransomware-gang-tied-to-300-attacks-in-17-months\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/play-ransomware-gang-tied-to-300-attacks-in-17-months\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/play-ransomware-gang-tied-to-300-attacks-in-17-months\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/play-ransomware-gang-tied-to-300-attacks-in-17-months.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/play-ransomware-gang-tied-to-300-attacks-in-17-months.jpg\",\"width\":800,\"height\":560},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/play-ransomware-gang-tied-to-300-attacks-in-17-months\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,hacker,malware,cybercrime,fraud,cryptography\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinehackermalwarecybercrimefraudcryptography\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Play Ransomware Gang Tied To 300 Attacks In 17 Months\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Play Ransomware Gang Tied To 300 Attacks In 17 Months 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/play-ransomware-gang-tied-to-300-attacks-in-17-months\/","og_locale":"en_US","og_type":"article","og_title":"Play Ransomware Gang Tied To 300 Attacks In 17 Months 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/play-ransomware-gang-tied-to-300-attacks-in-17-months\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2023-12-20T13:20:28+00:00","og_image":[{"url":"https:\/\/files.scmagazine.com\/wp-content\/uploads\/2023\/12\/Ransomware-Kid.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/play-ransomware-gang-tied-to-300-attacks-in-17-months\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/play-ransomware-gang-tied-to-300-attacks-in-17-months\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Play Ransomware Gang Tied To 300 Attacks In 17 Months","datePublished":"2023-12-20T13:20:28+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/play-ransomware-gang-tied-to-300-attacks-in-17-months\/"},"wordCount":489,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/play-ransomware-gang-tied-to-300-attacks-in-17-months\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/12\/play-ransomware-gang-tied-to-300-attacks-in-17-months.jpg","keywords":["headline,hacker,malware,cybercrime,fraud,cryptography"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/play-ransomware-gang-tied-to-300-attacks-in-17-months\/","url":"https:\/\/www.threatshub.org\/blog\/play-ransomware-gang-tied-to-300-attacks-in-17-months\/","name":"Play Ransomware Gang Tied To 300 Attacks In 17 Months 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/play-ransomware-gang-tied-to-300-attacks-in-17-months\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/play-ransomware-gang-tied-to-300-attacks-in-17-months\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/12\/play-ransomware-gang-tied-to-300-attacks-in-17-months.jpg","datePublished":"2023-12-20T13:20:28+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/play-ransomware-gang-tied-to-300-attacks-in-17-months\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/play-ransomware-gang-tied-to-300-attacks-in-17-months\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/play-ransomware-gang-tied-to-300-attacks-in-17-months\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/12\/play-ransomware-gang-tied-to-300-attacks-in-17-months.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/12\/play-ransomware-gang-tied-to-300-attacks-in-17-months.jpg","width":800,"height":560},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/play-ransomware-gang-tied-to-300-attacks-in-17-months\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,hacker,malware,cybercrime,fraud,cryptography","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinehackermalwarecybercrimefraudcryptography\/"},{"@type":"ListItem","position":3,"name":"Play Ransomware Gang Tied To 300 Attacks In 17 Months"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/54900","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=54900"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/54900\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/54901"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=54900"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=54900"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=54900"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}