INTEL_REPORT
Mandiant / Google Threat Intelligence Blog · published 3/16/2026, 2:00:00 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Ransomware Under Pressure: Tactics, Techniques, and Procedures in a Shifting Threat Landscape Written by: Bavi Sadayappan, Zach Riddle, Ioana Teaca, Kimberly Goody, Genevieve Stark Introduction Since 2018, when many financially motivated threat actors began shifting their monetization strategy to post-compromise ransomware deployments, ransomware has become one of the most pervasive threats to organizations across almost every industry vertical and region. In recent years ra…
https://cloud.google.com/blog/topics/threat-intelligence/ransomware-ttps-shifting-threat-landscape
sha256:de836dbce404b6e33129c88d55a1cd440d3708b21a8db5c5cdf606ee5b31cd0f
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| msedge.dll |
| Open → |
| domain | rundll32.exe | Open → |
| domain | red.dll | Open → |
| domain | users.csv | Open → |
| domain | allwindows.csv | Open → |
| domain | impacket.smbexec | Open → |
| domain | net.exe | Open → |
| domain | systembc.linux | Open → |
| domain | foulfog.linux | Open → |
| domain | lockbit.black | Open → |
| domain | agenda.esxi | Open → |
| domain | agenda.rust | Open → |
| domain | babuk.mario | Open → |
| domain | inc.linux | Open → |
| domain | lockbit.unix | Open → |
| domain | www.torproject.org | Open → |
| domain | redbike.linux | Open → |
| domain | akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad.onion | Open → |
| domain | clop.linux | Open → |
| domain | playcrypt.linux | Open → |
| domain | pe.imphash | Open → |
| md5 | ff67c703589f775db9aed5a03e4489b0 | Open → |
| cve | CVE-2024-55591 | Open → |
| cve | CVE-2024-21762 | Open → |
| cve | CVE-2019-6693 | Open → |
| cve | CVE-2024-40766 | Open → |
| cve | CVE-2024-3400 | Open → |
| cve | CVE-2023-4966 | Open → |
| cve | CVE-2025-53770 | Open → |
| cve | CVE-2025-53771 | Open → |
| cve | CVE-2025-8088 | Open → |
| cve | CVE-2025-61882 | Open → |
| cve | CVE-2021-27877 | Open → |
| cve | CVE-2021-27878 | Open → |
| cve | CVE-2021-40539 | Open → |
| cve | CVE-2025-31324 | Open → |
| cve | CVE-2025-31161 | Open → |
| cve | CVE-2024-37085 | Open → |