Kaspersky reveals link between ransomware groups Play, RansomHub, and DragonForce

View profile for Luis Oria Seidel

| IT Manager & Cybersecurity Architect | Automation with N8N and Make | Artificial Intelligence | Fortinet® NSE 3 & FCAC® | ISO/IEC 27001 ™ | CAPC™ | Cloud | CSFPC™ | SODFC™ | FBE™ | RWVCPC™ | NIST | ITIL | FCP | CobiT |

🔍 New connection between ransomware groups: Play, RansomHub, and DragonForce linked to the same threat actor A recent report by Kaspersky reveals that a threat actor, known as "Knight," is linked to the operations of the ransomware groups Play, RansomHub, and DragonForce. This finding suggests possible collaboration or reuse of tools among these criminal gangs. 🕵️ Investigation details Kaspersky's analysis identified similarities in the techniques, tools, and procedures (TTPs) used by these three groups. In particular, the use of similar data exfiltration tools, as well as shared communication patterns and command structures, was observed. The "Knight" actor has been active since at least 2022 and has participated in multiple high-profile ransomware campaigns. Their connection to these three groups suggests a level of organization and cooperation that could increase the effectiveness of their attacks. ⚠️ Implications for cybersecurity This connection highlights the growing sophistication and collaboration among ransomware groups. Organizations must be vigilant of these shared tactics and reinforce their security measures, especially in protecting sensitive data and preventing exfiltration. 🛡️ Key recommendations - Implement network segmentation to limit lateral movement - Constantly monitor outgoing traffic to detect data exfiltration - Keep systems updated and apply security patches - Perform regular backups and verify their integrity - Train staff in phishing recognition and social engineering techniques For more information visit: https://enigmasecurity.cl #Ransomware #Cybersecurity #ThreatIntelligence #Kaspersky #PlayRansomware #RansomHub #DragonForce #CyberThreats #InfoSec Let's connect to continue discussing cybersecurity trends: https://lnkd.in/eGvmV6Xf 📅 Tue, 09 Sep 2025 10:36:21 +0000 🔗Subscribe to the Membership: https://lnkd.in/eh_rNRyt

  • No alternative text description for this image

To view or add a comment, sign in

Explore content categories