BLOG TOPIC
Threat Actor Analysis
Research on threat groups, campaigns, tactics, techniques, procedures, malware, infrastructure, and observed adversary behavior.

When Ransomware Makes a Mistake Inside INC Ransomware’s Backup Infrastructure
This article documents how Cyber Centaurs identified, validated, and safely accessed attacker-controlled data repositories operated by the INC Ransomware Group, resulting in the recovery of stolen data belonging to twelve unrelated U.S. corporations. What made this possible was not a vulnerability or a takedown, but forensic discipline applied to attacker tooling. Specifically, artifacts left behind…
Read Article →
Infiltration into the INC Ransomware Group’s Infrastructure
In a world where technology news are dominated by stories of ransomware attacks and data breaches, Cyber Centaurs is proud to share a rare story of success. While many organizations continue to struggle against a rising tide of cyber extortion, this case demonstrates that determined investigation and skilled response can lead to positive outcomes ,…
Read Article →
RedNovember’s Tactics and Tradecraft
Over the past year, a Chinese-linked threat actor known as RedNovember has emerged as a significant player in the global cyber-espionage landscape. Their operations have targeted governments, defense contractors, law firms, and critical infrastructure providers across multiple regions. What sets RedNovember apart is its pragmatic playbook: exploiting unpatched internet-facing devices to gain entry, deploying lightweight…
Read Article →
Threat Actors’ Obsession with Veeam Backups
Threat actors are now deliberately targeting Veeam backup infrastructure to exfiltrate sensitive data before executing broader attacks. For years, Veeam Backup & Replication has quietly supported business continuity across enterprises…
Read Article →
Guarding Against Midnight Blizzard’s New RDP Tactics
As cyber threat actors continually refine their techniques, state-sponsored groups are pushing boundaries to infiltrate even the most secure networks. Among these groups, Midnight Blizzard—also known as APT29 or Cozy…
Read Article →
Unmasking North Korean IT Infiltration
The evolution of remote work has created new avenues for business growth but also introduced significant cyber risks. As of 2024, around 22.8% of U.S. employees work remotely at least…
Read Article →
FOG Threat Actor Dossier
The FOG threat actor group, first identified by Arctic Wolf researchers on May 2, 2024, represents a distinctive strain within the larger ecosystem of ransomware operations. While sharing similarities with other ransomware groups, FOG's tactics, techniques, and procedures (TTPs) emphasize speed and efficiency over the more complex, multi-stage attacks observed in other contemporary ransomware operations.…
Read Article →
Insight into China’s Cyber Espionage with SpiceRAT and SugarGh0st
In recent months, the cybersecurity landscape has witnessed a significant escalation in threats as Chinese state-sponsored hacking groups intensify their cyber-espionage efforts. Utilizing advanced cyber tools such as SpiceRAT and…
Read Article →
Shadow Ops – Unveiling the Stealth Tactics of Earth Freybug
Shadow Ops – Unveiling the Stealth Tactics of Earth Freybug The emergence and maturation of Advanced Persistent Threat (APT) groups represent a significant evolution in the methodology and objectives of…
Read Article →
GhostSec and Stormous – Unveiling the New Era of Cyber Threat Alliances
GhostSec and Stormous – Unveiling the New Era of Cyber Threat Alliances The Blight of Global Ransomware Alliances In today’s interconnected world, cyber resilience is more than a protocol; it’s…
Read Article →
Behind the Gaze of MEDUSA – Understanding the Latest Ransomware Phenomenon
Behind the Gaze of MEDUSA MEDUSA Ransomware, drawing its name from the Greek mythological figure known for her lethal gaze, has become a symbol of dread in the cyber world….
Read Article →