ToyMaker Uses LAGTOY to Sell Access to CACTUS Ransomware Gangs for Double Extortion
Cybersecurity researchers have detailed the activities of an
initial access broker (IAB) dubbed ToyMaker that has been observed
handing over access to double extortion ransomware gangs like
CACTUS. The IAB has been assessed with medium confidence to be a
financially motivated threat actor, scanning for vulnerable systems
and deploying a custom malware called LAGTOY (aka HOLERUN). "LAGTOY
can be
Read more https://thehackernews.com/2025/04/toymaker-uses-lagtoy-to-sell-access-to.html