LV Ransomware Exploited ProxyShell to target Jordan

Threat Advisories

LV Ransomware Exploited ProxyShell to target Jordan

Threat Level
Attack Report

For a detailed threat advisory, download the pdf file here

Summary

LV ransomware as a service has been active since late 2020 The most recent infiltration entailed the compromise of the corporate environment of a Jordan based entity, leveraging the double extortion technique and exploiting ProxyShell flaws to extort potential targets