Latest Posts
03 Mar 2025
Identity Reveal: The Threat Actor Behind ZATCA SAUDI ARABIA Leaks
On May 11, 2024, we observed numerous security reports about ZATCA Saudi Arabia access being offered for sale on one of the most well-known dark web forums (BreachForums) by a threat actor known as “gettexik” So, our DarkAtlas Squad initiated an investigation into this threat actor.We began tracking him and successfully discovered his BreachForums account […]
25 Nov 2024
Helldown Ransomware Analysis
Introduction Helldown ransomware, first identified in August 2024, is a recent addition to the ransomware landscape, known for its aggressive tactics and sophisticated encryption methods. This malware encrypts a wide range of file types, appending a unique extension to each, and leaves a ransom note instructing victims on payment procedures, typically demanding cryptocurrency. Notably, Helldown […]
13 Oct 2024
Fog Ransomware – Technical Analysis
what is Fog ? In June [Arctic Wolf Labs] reported a deployment of a new ransomware named Fog Ransomware, according to their report the ransomware was seen in several incident Response cases, affecting education and recreation center in the United States, the investigation revealed that the attackers gain access to victims through compromised VPNs credentials, […]
03 Mar 2025
5 min read
Identity Reveal: The Threat Actor Behind ZATCA SAUDI ARABIA Leaks
On May 11, 2024, we observed numerous security reports about ZATCA Saudi Arabia access being offered for sale on one of the most well-known dark web forums (BreachForums) by a threat actor known as “gettexik” So, our DarkAtlas Squad initiated an investigation into this threat actor.We began tracking him and successfully discovered his BreachForums account […]
25 Nov 2024
5 min read
Helldown Ransomware Analysis
Introduction Helldown ransomware, first identified in August 2024, is a recent addition to the ransomware landscape, known for its aggressive tactics and sophisticated encryption methods. This malware encrypts a wide range of file types, appending a unique extension to each, and leaves a ransom note instructing victims on payment procedures, typically demanding cryptocurrency. Notably, Helldown […]
13 Oct 2024
5 min read
Fog Ransomware – Technical Analysis
what is Fog ? In June [Arctic Wolf Labs] reported a deployment of a new ransomware named Fog Ransomware, according to their report the ransomware was seen in several incident Response cases, affecting education and recreation center in the United States, the investigation revealed that the attackers gain access to victims through compromised VPNs credentials, […]