ToyMaker Partners with LAGTOY to Facilitate Access to CACTUS Ransomware Gangs for Double Extortion Schemes
Cybersecurity experts have identified an initial access broker called ToyMaker, which is linked to double extortion ransomware groups, including CACTUS. ToyMaker uses custom malware known as LAGTOY to gain access to vulnerable systems, allowing it to create reverse shells and execute commands remotely. Initially documented by Mandiant in early 2023, ToyMaker targets high-value organizations by ...