---
title: "Threat Intel Content Update: 12/10/24"
description: Tidal Cyber's threat intelligence content updates for the week of 12/10/24 “Trending & Emerging Threats” Threat Profile, Akira Ransomware, BlueAlpha/Gamaredon Group, Termite Ransomware
---

[Threat Intelligence Content Updates ](https://www.tidalcyber.com/threat-updates)

# [Threat Intel Content Update: 12/10/24](https://www.tidalcyber.com/threat-updates/threat-intel-content-updated-12/10/24)

 Written by [Tidal Cyber](https://www.tidalcyber.com/threat-updates/author/tidal-cyber) | Dec 11, 2024 1:00:00 PM

#### “Trending & Emerging Threats” Threat Profile, Akira Ransomware, BlueAlpha/Gamaredon Group, Termite Ransomware

****Threat Content Highlights****

Threat Profile

- We released the first edition of a new, regularly updated, Tidal-curated “Trending & Emerging Threats” Threat Profile available in all client tenants. The profile highlights a key new or re-surfacing threat we expect to be relevant & significant to most organizations, **based on our continual landscape monitoring and analysis** 
    - - The profile also** showcases Tidal-recommended profiling & weighting best practices** – most updates will feature a primary subject threat (usually a Group or Campaign), as well as associated Software (Tools/Malware), all curated & weighted by Tidal according to assessed relative relevance.

- - - Our first spotlight is on [Akira Ransomware](https://app.tidalcyber.com/groups/923f478c-7ad1-516f-986d-61f96b9c553e?tab=2). While Akira has consistently claimed a considerable number of victims across a wide range of sectors & geographies since early 2023, last month saw the group claim an unusually large number of victims (135). Cisco Talos researchers recently [highlighted](https://blog.talosintelligence.com/akira-ransomware-continues-to-evolve/) how the group's attack methods are believed to be shifting back towards Windows- and Linux-focused encryptors, and so the curated profile emphasizes two relevant ransomware objects (including a [newly added Software object](https://app.tidalcyber.com/software/48f864a6-724e-4dbc-8428-981670bcd07a) for the Linux/ESXi version of the Akira encryptor).

Threat Objects

- [New Campaign](https://app.tidalcyber.com/campaigns/0c1ce25b-661d-4134-879a-c2a229a62a86) covering recently reported activity where Russia-state-sponsored espionage actors [BlueAlpha/Gamaredon Group](https://app.tidalcyber.com/groups/41e8b4a4-2d31-46ee-bc56-12375084d067?tab=2) used the freely available “TryCloudflare” service to conceal malicious traffic by proxying it via the Cloudflare network.
- Added [Termite Ransomware](https://app.tidalcyber.com/software/51a9d952-4cc3-4c4c-8f43-f4c25f44d830), a threat [newly linked](https://www.techradar.com/pro/security/termite-ransomware-gang-claims-it-carried-out-blue-yonder-attack) to a notable supply chain attack that disrupted multiple prominent retail brands (Termite actors also recently claimed several other victims).

[View full post](https://www.tidalcyber.com/threat-updates/threat-intel-content-updated-12/10/24)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Tidal Cyber"
  },
  "dateModified" : "2024-12-11T13:00:02.867Z",
  "datePublished" : "2024-12-11T13:00:00Z",
  "headline" : "Threat Intel Content Update: 12/10/24",
  "image" : {
    "@type" : "ImageObject",
    "height" : 500,
    "url" : "https://21164103.fs1.hubspotusercontent-na1.net/hubfs/21164103/Threat%20Intelligence%20Content%20Update%20Social.jpg",
    "width" : 900
  },
  "mainEntityOfPage" : "https://www.tidalcyber.com/threat-updates/threat-intel-content-updated-12/10/24",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "Threat Intelligence Content Updates"
  }
}
```