Back to Resources

SentinelOne Demo: SentinelOne VS RA Group Ransomware – Detection and Response

In this video demo, we showcase how SentinelOne’s XDR technology detects and responds to RA Group ransomware. RA Group emerged in April 2023. The RA Group ransomware payloads are derived/based on Babuk, and appear to be generated by the leaked Babuk builder toolset. The generated malware payloads are functionally similar to Babuk and contain commodity features such as VSS deletion.

The RA Group is a multi-extortion group. They threaten victims with publicly leaking data if victims fail to pay the demanded ransom. The group has also been known to include strings in their malware which taunt or shame well-known security researchers. The RA Group has a TOR (.onion) based website where they list victims and host exfiltrated data (should they fail to comply with the ransom demands). RA Group victims are instructed to communicate with their attackers via qTox messenger. RA Group does not exclude specific industries or locations from their targeting.

Experience the power of SentinelOne’s XDR solution and witness first-hand its effectiveness in combating the RA Group ransomware. Subscribe to our channels for more in-depth analysis and real-life examples from the forefront of cybersecurity.

Experience the power of SentinelOne’s XDR solution and witness first-hand its effectiveness in combating the RA Group ransomware. Subscribe to our channels for more in-depth analysis and real-life examples from the forefront of cybersecurity.

지금 읽기

세계에서 가장 앞선 사이버 보안 플랫폼 경험하기

지능적인 자율형 사이버 보안 플랫폼이 현재와 미래의 조직을 어떻게 보호할 수 있는지 알아보세요.