Void Rabisu
0 incidentes
0 paises
0 sectores
apt RU Ultimo: -
Aliases: Tropical Scorpius
Void Rabisu, also known by the alias Tropical Scorpius, is a cyber threat actor that emerged in 2022, initially engaged in financially motivated ransomware operations using Cuba Ransomware. The group underwent a significant transformation around October 2022, shifting its primary objectives to cyber-espionage driven by geopolitical interests, particularly targeting Ukraine and its allies. This evolution blurs the traditional lines between cybercrime and state-sponsored advanced persistent threat activity, as Void Rabisu increasingly employs techniques and targets typically associated with APT groups. The group is assessed with high confidence to operate with motivations aligned with Russian interests, though direct state sponsorship remains unconfirmed. A defining characteristic is their strategic use of the RomCom backdoor for intelligence gathering, alongside exploitation of zero-day vulnerabilities in high-profile software to achieve their espionage goals.