RansomHub Affiliate Leverages Python-based Backdoor to Maintain Access and Deploy Encryptors
In an incident response in Q4 2024, GuidePoint Security identified evidence of a threat actor utilizing a Python-based backdoor to maintain access to compromised endpoints. The threat actor later leveraged this access to deploy RansomHub encryptors.