From December 2023 to the present, QiAnXin Threat Intelligence Center observed that a ransomware written in rust language is very active on the Chinese Internet, and a large number of machines in China have been ransomed, with up to more than 20 victimized units only in the terminals of government and enterprises, which the researchers call Rast ransomware.
After a long time of tracking, QiAnXin Threat Intelligence Center have captured three versions of Rast ransomware, and the versions are still iterating. rast ransomware has a very special logic: after the ransomware is completed, it will upload the machine name and unique identifier of the local machine to the remote mysql database. Through reverse analysis the research team got the mysql database account password and statistics of victims in the database, and found that in just ten months more than 6,800 terminals were controlled.
Read more…
Source: QiAnXin Threat Intelligence Center
Related:
- Inside an Exposed WebDAV Malware Delivery Lab
July 20, 2026
An MDR alert recently led our team to an exposed server that was doing more than hosting payloads. It was functioning as a fully operational malware delivery lab. Containing over 1,000 artifacts, the infrastructure served as a QA hub where attackers systematically tested delivery paths, social engineering lures, and WebDAV execution methods. Our analysis reveals an ...
- FBI Warns of Scammers Impersonating the IC3
July 20, 2026
This Public Service Announcement contains updated information about an ongoing fraud scheme where criminal scammers are impersonating FBI personnel facilitating Internet Crime Complaint Center (IC3) complaints to deceive and revictimize individuals. This scheme combines several exploitation tactics to include the targeting of previous victims, the use of artificial intelligence (AI)-generated videos to create fictitious or misleading promotional ...
- Hugging Face confirms breach affected internal datasets and credentials
July 20, 2026
Hugging Face, a platform that hosts AI models and datasets, said its internal datasets and service credentials were compromised in a hack last week. The company disclosed the breach on Friday, but said it was still investigating whether any customer or partner data was stolen during the incident. In a blog post, the company said a dataset uploaded ...
- Ernst & Young reveals data breach following hack on support system
July 20, 2026
Ernst & Young (EY) has confirmed suffering a cyberattack in which it lost sensitive customer information, including tax data. In a data breach notification letter sent to affected individuals, the firm said that on April 23, 2026, it spotted “anomalous activity” within a third-party platform its IT team uses. This is an IT service management platform ...
- HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels
July 20, 2026
The Group-IB Threat Intelligence team has identified HOLLOWGRAPH, a new malware sample that we attribute, with high confidence, to the Cavern backdoor framework. This malware is one component of a larger toolkit, and it uses the Microsoft Graph API through a compromised Microsoft 365 account observed in Israel to communicate with its operators — a technique ...
- Healthcare giant Abbott probes two cyber incidents amid extortion claims
July 20, 2026
Abbott Laboratories, one of the world’s largest healthcare and medical device companies, is investigating two apparently unrelated cyber incidents after confirming unauthorized access to internal systems. While Abbott says there has been no impact on manufacturing, laboratory operations, or patient care, cybercriminal groups ShinyHunters and ShadowByt3$ claim the breaches were far more extensive. Those claims ...

