CiberLATAMbywhalemate

CHAOS, DragonForce and STORM add ransomware victims

Security Arsenal linked new victims to CHAOS, DragonForce, KRYBIT, STORM and GLOBAL SECRET GROUP, including cases in the U.S.

Whalemate Labs · AI-assisted researchPublished:3 min read

Security Arsenal reported new victim postings tied to CHAOS, DragonForce, KRYBIT, STORM and GLOBAL SECRET GROUP, including cases in the United States and an Argentine pharmaceutical distributor tied in another recent Aur0ra and Cursor AI report.

Security Arsenal said over the past few days that CHAOS, DragonForce, KRYBIT, STORM and GLOBAL SECRET GROUP had added new victims, with organizations affected in the United States and other countries. The coverage also overlapped with cases in Latin America, including an Argentine pharmaceutical distributor mentioned in reports on Aur0ra and Cursor AI, as well as victims in Brazil, Argentina and the United Arab Emirates in another DragonForce post.

What did Security Arsenal report about CHAOS, DragonForce and KRYBIT?

Security Arsenal said CHAOS posted three new victims in 24 hours, DragonForce added four in the same period and KRYBIT listed 13 organizations in 48 hours. In CHAOS' case, one of the victims was mswalker.com in the United States, and the group of targets included professional services and small businesses.

For DragonForce, the report tied the activity to victims in Argentina, Brazil, the United Arab Emirates and Canada. Security Arsenal also described TTPs linked to that campaign, including exploitation of public applications, use of valid credentials, external remote services, RDP/SMB, WMI, PsExec, exfiltration, recovery inhibition and encryption.

KRYBIT, meanwhile, published 13 organizations in 48 hours. Security Arsenal said the set included a victim in the United States, wmiemporium.com, within sectors such as retail and e-commerce, health care, agriculture and food, and financial services.

What extra information did Breach House and RecentBreaches provide?

Breach House and RecentBreaches added details on mswalker.com and wmiemporium.com, with different nuances on whether the incident was confirmed. In the mswalker.com case, Breach House attributed it to CHAOS, placed it in the United States and added that roughly 620 GB may have been exfiltrated before encryption.

The same case also appears in RecentBreaches as a claim not confirmed by the company. The entry on that site reinforces the CHAOS attribution, but keeps the incident status as claimed and not publicly verified at the time of the report.

For wmiemporium.com, Breach House confirmed the KRYBIT attribution and said the victim is based in the United States and operates in retail and e-commerce. That matches the broader campaign described by Security Arsenal.

What scope did STORM and GLOBAL SECRET GROUP have?

STORM posted seven new victims in 72 hours, six of them in the United States, and GLOBAL SECRET GROUP logged three new victims in 24 hours, all also in the United States. In STORM's case, the sectors mentioned included government, health care, financial services and manufacturing.

IntelFusions widened the picture on STORM by saying that, in a larger set of posted listings, 27 of 35 victims were U.S. organizations. That sector breakdown put the main groups in manufacturing, health care and financial services.

For GLOBAL SECRET GROUP, Security Arsenal described victims in transportation and construction, retail and automotive, and an environment close to government and defense. ransomware.live also identified Lockheed Architectural Solutions, Inc. in Rhode Island, within manufacturing and building materials, and Tiseo Paving in Texas, as a commercial and residential construction company.

What is known about the Aur0ra front with Cursor AI?

Claims Journal and Reuters reported that the Aur0ra operator used Cursor AI to breach seven companies. Among the victims were an Argentine pharmaceutical distributor and Bayou Title, a title insurance company based in Louisiana, along with organizations in Belgium, Germany, Scotland, Italy and the United States.

Reuters identified six of the seven companies by name and confirmed the attack pattern built around SpaceX's programming tool. Follow-up coverage in eSecurityPlanet, La Nación and explainx.ai repeated that information and kept the reference to the Argentine victim and the U.S. insurer.

Sources

View all