<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Raas on CuraSec</title><link>https://curasec.metacog.co.kr/tags/raas/</link><description>Recent content in Raas on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 06 Aug 2026 13:03:19 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/raas/index.xml" rel="self" type="application/rss+xml"/><item><title>Ransom Cartel Creator Sentenced to 16 Years for RaaS Operation</title><link>https://curasec.metacog.co.kr/insights/2026-08-06-ransom-cartel-creator-gets-16-years-in-prison-for-operating/</link><pubDate>Thu, 06 Aug 2026 13:03:19 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-06-ransom-cartel-creator-gets-16-years-in-prison-for-operating/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Background on the Ransom Cartel RaaS model (2021–2023) is useful for understanding affiliate-driven ransomware tradecraft, but the operation is dismantled and no new IOCs or detection angles are provided.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A successful DOJ prosecution of a major RaaS operator is useful context for board or customer conversations about ransomware deterrence, but it changes no current risk posture or vendor exposure.&lt;/li>
&lt;/ul></description></item><item><title>DevMan RaaS Portal Offers Affiliates Centralized Build and Victim Management</title><link>https://curasec.metacog.co.kr/insights/2026-07-25-devman-raas-portal-centralizes-payload-builds-victim-managem/</link><pubDate>Sat, 25 Jul 2026 12:08:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-25-devman-raas-portal-centralizes-payload-builds-victim-managem/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Awareness of a maturing RaaS platform with self-serve affiliate tooling is useful context for defense-in-depth planning, but the summary contains no IOCs, CVEs, or exploited software — no immediate patching or configuration action available.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> PRODAFT&amp;rsquo;s tracking of the Funky Mantis operation is useful actor-profile context, but the summary surfaces no IOCs, ATT&amp;amp;CK-mapped TTPs, or detection hooks — revisit if PRODAFT releases a full technical report with indicators.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Demonstrates continued commoditization of ransomware operations, useful for board-level narrative on ransomware risk trends, but no sector-specific targeting or vendor exposure is identified that would require immediate leadership action.&lt;/li>
&lt;/ul></description></item></channel></rss>