The actions of ToyMaker, an initial access broker (IAB) that has been seen granting access to double extortion ransomware gangs such as CACTUS, have been described in depth by cybersecurity researchers.
With a medium level of confidence, the IAB has been identified as a financially motivated threat actor that uses a bespoke virus named LAGTOY (also known as HOLERUN) to find weak systems.
According to Cisco Talos researchers Joey Chen, Asheer Malhotra, Ashley Shen, Vitor Ventura, and Brandon White, LAGTOY can be leveraged to build reverse shells and run commands on compromised endpoints.
Google-owned Mandiant initially reported the virus in late March 2023, claiming that a threat actor it watches, UNC961, was responsible for its deployment. Other names for the activity cluster are Prophet Spider and Gold Melody read more about ToyMaker Uses LAGTOY to Sell Access to CACTUS Ransomware Gangs for Double Extortion.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
