Void Rabisu
Void Rabisu is an intrusion set associated with both financially motivated ransomware attacks and targeted campaigns on Ukraine and countries supporting Ukraine.
Void Rabisu is a dual-threat actor known for ransomware and espionage campaigns targeting Ukraine and EU states.
Void Rabisu (also known as Tropical Scorpius) is an intrusion set linked to both financially motivated ransomware attacks and targeted campaigns against Ukraine and countries supporting Ukraine. This actor primarily targets Ukraine and European Union member states. Their TTPs blend ransomware operations with targeted espionage-style intrusions, though specific tools and methods beyond this dual approach are not detailed in the provided data. Defenders should focus on detecting both cybercriminal and targeted intrusion indicators, strengthening monitoring for dual-purpose tactics, and ensuring incident response plans account for both ransomware and espionage scenarios.
Void Rabisu is an intrusion set associated with both financially motivated ransomware attacks and targeted campaigns on Ukraine and countries supporting Ukraine.
Void Rabisu primarily targets Ukraine and European Union member states.
Its campaigns are linked to both financially motivated ransomware attacks and targeted espionage-style intrusions against Ukraine and countries supporting Ukraine.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.