National Cyber Warfare Foundation (NCWF)

ToyMaker Uses LAGTOY to Sell Access to CACTUS Ransomware Gangs for Double Extortion


0 user ratings
2025-04-26 11:04:23
milo
Blue Team (CND) , Ransomware
Cybersecurity researchers have detailed the activities of an initial access broker (IAB) dubbed ToyMaker that has been observed handing over access to double extortion ransomware gangs like CACTUS.
The IAB has been assessed with medium confidence to be a financially motivated threat actor, scanning for vulnerable systems and deploying a custom malware called LAGTOY (aka HOLERUN).
"LAGTOY can be



Source: TheHackerNews
Source Link: https://thehackernews.com/2025/04/toymaker-uses-lagtoy-to-sell-access-to.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)
Ransomware



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.