The group is abusing trusted remote management and file transfer tools to deliver a Linux encryptor on Windows machines.
In March 2024, Exodus Intelligence discovered a vulnerability in Microsoft Windows Cloud Files Minifilter driver.