SentinelOne Demo: SentinelOne VS RA Group Ransomware – Protection
In this video demo, we showcase how SentinelOne’s XDR technology detects and remediates RA Group ransomware. RA Group emerged in April 2023. The RA Group ransomware payloads are derived/based on Babuk, and appear to be generated by the leaked Babuk builder toolset. The generated malware payloads are functionally similar to Babuk and contain commodity features such as VSS deletion.
The RA Group is a multi-extortion group. They threaten victims with publicly leaking data if victims fail to pay the demanded ransom. The group has also been known to include strings in their malware which taunt or shame well-known security researchers. The RA Group has a TOR (.onion) based website where they list victims and host exfiltrated data (should they fail to comply with the ransom demands). RA Group victims are instructed to communicate with their attackers via qTox messenger. RA Group does not exclude specific industries or locations from their targeting.
Experience the power of SentinelOne’s XDR solution and witness first-hand its effectiveness in combating the RA Group ransomware. Subscribe to our channels for more in-depth analysis and real-life examples from the forefront of cybersecurity.