RA World
Threat Actor
RA World, active since at least April 2023, primarily targets organizations in the United States and South Korea. The group utilizes a modified variant of the Babuk ransomware, which includes a built-in messaging application for victim communication. They reportedly exploit poorly secured internet-facing systems to gain initial access, followed by credential theft and lateral movement within the network. Security researchers have also suggested a possible link between RA World and a Chinese hacking group known as Bronze Starlight.
Incidents Associated with this Threat
- December 13, 2024: Ransomware Attack at NZ Compass Communications
Malware Used by this Threat Actor
No malware identified for this threat actor.
