24/7 INCIDENT RESPONSE
(877) 259-0509

BLOG TOPIC

Threat Actor Analysis

Research on threat groups, campaigns, tactics, techniques, procedures, malware, infrastructure, and observed adversary behavior.

when Ransomware Makes Mistakes

Threat Actor Analysis · January 22, 2026

When Ransomware Makes a Mistake Inside INC Ransomware’s Backup Infrastructure

This article documents how Cyber Centaurs identified, validated, and safely accessed attacker-controlled data repositories operated by the INC Ransomware Group, resulting in the recovery of stolen data belonging to twelve unrelated U.S. corporations. What made this possible was not a vulnerability or a takedown, but forensic discipline applied to attacker tooling. Specifically, artifacts left behind…

Read Article →
infiltration into the inc ransomware groups infrastructure

Threat Actor Analysis · November 10, 2025

Infiltration into the INC Ransomware Group’s Infrastructure

In a world where technology news are dominated by stories of ransomware attacks and data breaches, Cyber Centaurs is proud to share a rare story of success. While many organizations continue to struggle against a rising tide of cyber extortion, this case demonstrates that determined investigation and skilled response can lead to positive outcomes ,…

Read Article →
RedNovember

Threat Actor Analysis · October 4, 2025

RedNovember’s Tactics and Tradecraft

Over the past year, a Chinese-linked threat actor known as RedNovember has emerged as a significant player in the global cyber-espionage landscape. Their operations have targeted governments, defense contractors, law firms, and critical infrastructure providers across multiple regions. What sets RedNovember apart is its pragmatic playbook: exploiting unpatched internet-facing devices to gain entry, deploying lightweight…

Read Article →
The 2025 Spike in Veeam Exploitation Explained

Threat Actor Analysis · September 11, 2025

Threat Actors’ Obsession with Veeam Backups

Threat actors are now deliberately targeting Veeam backup infrastructure to exfiltrate sensitive data before executing broader attacks. For years, Veeam Backup & Replication has quietly supported business continuity across enterprises…

Read Article →
Guarding Against Midnight Blizzards New RDP Tactics

Threat Actor Analysis · November 26, 2024

Guarding Against Midnight Blizzard’s New RDP Tactics

As cyber threat actors continually refine their techniques, state-sponsored groups are pushing boundaries to infiltrate even the most secure networks. Among these groups, Midnight Blizzard—also known as APT29 or Cozy…

Read Article →
Unmasking North Korean IT Infiltration

Threat Actor Analysis · October 26, 2024

Unmasking North Korean IT Infiltration

The evolution of remote work has created new avenues for business growth but also introduced significant cyber risks. As of 2024, around 22.8% of U.S. employees work remotely at least…

Read Article →
FOG Threat Actor Dossier

Threat Actor Analysis · October 1, 2024

FOG Threat Actor Dossier

The FOG threat actor group, first identified by Arctic Wolf researchers on May 2, 2024, represents a distinctive strain within the larger ecosystem of ransomware operations. While sharing similarities with other ransomware groups, FOG's tactics, techniques, and procedures (TTPs) emphasize speed and efficiency over the more complex, multi-stage attacks observed in other contemporary ransomware operations.…

Read Article →
SpiceRAT Remote Access Trojan

Threat Actor Analysis · June 24, 2024

Insight into China’s Cyber Espionage with SpiceRAT and SugarGh0st

In recent months, the cybersecurity landscape has witnessed a significant escalation in threats as Chinese state-sponsored hacking groups intensify their cyber-espionage efforts. Utilizing advanced cyber tools such as SpiceRAT and…

Read Article →
Freybug APT Threat min

Threat Actor Analysis · April 2, 2024

Shadow Ops – Unveiling the Stealth Tactics of Earth Freybug

Shadow Ops – Unveiling the Stealth Tactics of Earth Freybug The emergence and maturation of Advanced Persistent Threat (APT) groups represent a significant evolution in the methodology and objectives of…

Read Article →
GhostSec and Stormous Launch Joint Ransomware Attacks min

Threat Actor Analysis · March 12, 2024

GhostSec and Stormous – Unveiling the New Era of Cyber Threat Alliances

GhostSec and Stormous – Unveiling the New Era of Cyber Threat Alliances The Blight of Global Ransomware Alliances In today’s interconnected world, cyber resilience is more than a protocol; it’s…

Read Article →
MEDUSA Ransmoware

Threat Actor Analysis · January 8, 2024

Behind the Gaze of MEDUSA – Understanding the Latest Ransomware Phenomenon

Behind the Gaze of MEDUSA MEDUSA Ransomware, drawing its name from the Greek mythological figure known for her lethal gaze, has become a symbol of dread in the cyber world….

Read Article →