Double Extortion (Data Exfiltration + Encryption)
White-label RaaS/Cartel Model
BYOVD (Bring Your Own Vulnerable Driver) using truesight.sys and rentdrv2.sys to disable EDR
Cloud-native extortion (deletion of Azure backups and data without endpoint encryptors)
Vishing and advanced social engineering (via Muddled Libra partnership)
Entra ID (Azure AD) privilege escalation and persistence via malicious federated domains
C2 concealment using Backdoor.Turn via Microsoft Teams TURN relay infrastructure
Post-compromise discovery using AzureHound