AhnLab ASEC published a weekly summary covering three incidents: DragonForce ransomware attacking a South Korean online education company, Qilin ransomware attacking a South Korean motor and robotics manufacturer, and ShinyHunters claiming a data leak from a U.S. digital healthcare company. No technical IOCs, attack chain details, or detection rules are provided in the public blog post; detailed analysis is available only to AhnLab TIP subscribers.
DragonForce
2 posts
Ransom & Dark Web Issues Week 2, August 2026 An analysis of incidents at Brazilian educational institutions Brazilian educational institutions face ransomware attacks primarily from DragonForce and LockBit 3 variants, with initial access gained through valid accounts, exposed applications, and insider threats. Attackers leverage Potato variants for privilege escalation, AnyDesk and PsExec for remote access and lateral movement, and batch scripts to disable Windows Defender and enable RDP. The use of outdated Windows 10 and unpatched Windows Server 2016 systems increases the attack surface, while shared accounts on multi-user machines enable insider keylogging attacks.