Description Summary
Scaled to ~300 victims across 66 countries since mid-2025; RaaS from Sept 2025.
Threat Actor
RaaS (affiliate cut up to 90%), operator alias 'Hastalamuerte'; initial access via FortiOS/FortiProxy CVE-2024-55591; BYOVD (ThrottleStop → ThrottleBlood.sys), EDR-specific killers (Allpatch2.exe).
Technical Indicators
Encryption Extension
Not publicly reported
Encryption Algorithm
Go-based locker (Windows/Linux/NAS) + dedicated C-based ESXi locker
Ransom Note Name
Not publicly reported
Targeted Industries
Cross-sector (per leak-site victim telemetry)
First Seen
Mid-2025 (RaaS September 2025)
Last Seen
Active (~300 victims)
Geographical Location
Global (66 countries)
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Impact x 2 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| Exfiltration x 1 | T1567 | Exfiltration Over Web Service (leak site) |
| Initial Access x 2 | T1190 | Exploit Public-Facing Application |
| T1078 | Valid Accounts |