The group is abusing trusted remote management and file transfer tools to deliver a Linux encryptor on Windows machines.
IT admins who can't immediately deploy the emergency patches are advised to disable the WSUS Server role on vulnerable systems to remove the attack vector. The day CVE-2025-59287 patches were released ...