Multistage RA World Ransomware Uses Anti-AV Tactics Exploits GPO

The Trend Micro threat hunting team discovered a multistage RA World ransomware attack targeting healthcare organizations in Latin America. The attack involved components designed to maximize impact by compromising systems across the network via compromised domain controllers and Group Policy exploitation.