FulcrumSec is a data extortion group active since approximately September 2025, specializing in high-speed exfiltration of cloud-hosted databases by exploiting unrotated API keys and misconfigured cloud permissions rather than deploying encryption, with known victims including Australian fintech youX and LexisNexis.
Genera un perfil del actor con IA (defensivo) cuando lo pidas.
Este grupo no tiene TTPs curadas. Puedes generar un mapeo MITRE ESTIMADO por IA (no confirmado) a partir de su descripción/notas, solo cuando lo pidas.
Firma de detección defensiva para este grupo (úsala en tu EDR/SIEM). Fuente: ransomware.live.
/*
fulcrumsec ransomware
*/
rule fulcrumsec_Ransomnote
{
meta:
author = "ransomware.live"
family = "ransomware.fulcrumsec"
description = "Detects fulcrumsec ransomware ransom note or artifact"
date = "2026-05-04"
severity = 7
score = 70
strings:
$name1 = "fulcrumsec" ascii nocase
$name2 = "FULCRUMSEC" ascii
$onion = "fulcrumsec.onion" ascii nocase
condition:
any of them
}
[AI generated] Global Schools Foundation is a Singapore-based non-profit organization operating in the international education sector. It manages a network of private schools across Asia and the Middle East under brands such as Global Indian International School. The foundation focuses on providing quality education with an Indian curriculum framework to students from diverse nationalities, emphasizing holistic development and academic excellence across multiple campuses worldwide.
[AI generated] N/A
| Organización | País | Sector | Grupo | Descubierta |
|---|---|---|---|---|
| Global Schools Foundation | Education | — | 10 jun 2026 | |
| Nordstern Technologies | MX | Technology | — | 1 may 2026 |
| IMEVI | CO | Not Found | — | 1 may 2026 |
Las direcciones de los sitios de filtración (.onion) se conocen pero no se publican ni se enlazan. Solo se muestran metadatos públicos. ética
[AI generated] N/A