Ransomware briefings
Ransomware and extortion operations: new crews and rebrands, encryptor and leak-site activity, negotiation tactics, and the victims they claim.
- Akira reboots PCs into Safe Mode to blind security tools 2026-08-19
- A ransomware crew left its victim screenshots wide open 2026-08-18
- New Rust backdoor takes its orders from GitHub 2026-08-17
- Cl0p names 45 victims in a day, including GE and Shell 2026-08-14
- Ransomware's top crews lose ground as 93 groups pile in 2026-08-13
- Weaxor ransomware turns SQL Server into its launchpad 2026-08-13
- DeadLock ransomware wipes logs and throttles to stay hidden 2026-08-10
- FBI and CISA warn of Gunra ransomware hitting hospitals 2026-08-10
- Ransomware crew mined crypto in Colombia before encrypting 2026-08-10
- Ransomware crews can hide their tracks in ESX logs 2026-08-07
- Extortion crew hides behind five brands, Google says 2026-08-06
- Ransomware crews are going after managers, not just admins 2026-08-06
- Interlock ransomware turns forensics tools against victims 2026-08-05
- Gentlemen ransomware ends Qilin's 13-month reign on top 2026-08-02
- Qilin claims one of America's oldest magazines 2026-08-02
- Extortion crew names Europe's standards bodies as victims 2026-08-01
- Ransomware crew claims quantum computing firm Quantinuum 2026-08-01
- Ransomware crew Kyber claims US defense giant L3Harris 2026-08-01
- New extortion crew claims Turkey's banks and flag carrier 2026-08-01
- Low-profile crew CMD keeps adding schools to its leak site 2026-08-01
- Russian factories hit by new ransomware built for Windows and ESXi 2026-07-30
- NightSpire posts 12 victims in nine countries after a quiet July 2026-07-30
- Extortion crew claims data theft at Coca-Cola's Fairlife dairy arm 2026-07-29
- Extortion crew claims Ernst and Young, RingCentral and Brinks Home 2026-07-29
- Fake IT support calls on Microsoft Teams are ending in ransomware 2026-07-29
- Extortion crew that hit dental offices now claims US IT providers 2026-07-27
- New extortion crew claims a Spanish cloud host among 28 victims 2026-07-26
- New extortion crew claims Microsoft, Allstate and two US cities 2026-07-26
- Colombia warns on Gentlemen ransomware as 30 victims land in a day 2026-07-26
- Deadlock ransomware resurfaces with Kenya's roads agency and EU factories 2026-07-26
- Qilin lists Stryker four months after the medtech giant ruled out ransomware 2026-07-26
- Qilin ransomware lists Argentina's army on its leak site 2026-07-25
- Chaos ransomware's new trojan hides its traffic inside your browser 2026-07-25
- Nova ransomware outpaces rivals with a global wave of leak claims 2026-07-22
- Extortionists lock Latin American firms with BitLocker and office printers 2026-07-21
- Coinbase Cartel ransomware claims Caterpillar and Colliers as victims 2026-07-21
- Smaller ransomware brands crowd the leak sites as Blackout debuts 2026-07-20
- Krybit ransomware claims Bulgaria's Eurohold and its Euroins insurer 2026-07-19
- The Gentlemen ransomware lists Colombia's Ecopetrol and a US Navy command 2026-07-19
- Qilin ransomware sweeps up US churches, schools and small businesses 2026-07-19
- INC Ransom floods its leak site with Asia-Pacific victims 2026-07-18
- Interlock ransomware claims a DC housing agency and a refugee charity 2026-07-17
- DragonForce ransomware posts more than 20 victims in three days 2026-07-17
- The Gentlemen ransomware dumps nearly 20 victims in a single day 2026-07-17
- Rogue ransomware negotiator helped BlackCat extort his own clients 2026-07-14
- Ransomware crew D1R claims Synopsys breach reaching ARM and Bosch 2026-07-14
- Ransomware hits Latvia's state forestry firm through a two year old flaw 2026-07-14
- LockBit lists nine fresh victims across Europe despite takedown 2026-07-11
- Qilin ransomware claims 31 victims in a week across 15 countries 2026-07-11
- Deadlock ransomware floods its leak site with 65 victims in a day 2026-07-11
- The Gentlemen ransomware lures affiliates with rare 90 percent payouts 2026-07-11
- New ransomware crew Crpx O debuts by hitting US dental practices 2026-07-10
- Access broker exploits Citrix bug to plant DragonForce ransomware 2026-07-10
- New WhiteLock ransomware kills remote tools to block recovery 2026-07-08
- Scattered Spider is not one gang but a sprawling cybercrime movement 2026-07-07
- New ransomware crew Booba Project debuts by naming five victims 2026-07-07
- SafePay ransomware names a German airport and charity in leak site surge 2026-07-06
- New ransomware crew Doommageddon debuts with a Mercedes-Benz Turk claim 2026-07-06
- Overlooked ransomware crew Genesis piles up US clinics and small businesses 2026-07-05
- New ransomware crew Wallstreet claims a US police department and rural hospital 2026-07-05
- Ransomware crews pile onto US healthcare providers over the July 4 weekend 2026-07-04
- Gentlemen ransomware crew names 41 victims in a single day 2026-07-04
- INC Ransom adds US city governments and eye clinics to leak site 2026-07-04
- Ransomware crew Vect teams up with supply chain hackers TeamPCP 2026-07-03
- Little-known ransomware crew Krybit names nine victims in one day 2026-07-02
- ShinyHunters claims to hit test gear maker Fluke and distributor Ingram Content 2026-07-02
- New ransomware crew CMD hits a Norwegian municipality and healthcare firms 2026-06-30
- Gentlemen ransomware gang builds custom backdoor and stealthy network spying 2026-06-29
- Hackers poison Bing search results to drop Akira ransomware on companies 2026-06-29
- Qilin ransomware adds dentist referral and tolling firms to leak site 2026-06-29
- Settra ransomware crew names a dozen victims in a single day 2026-06-29
- Ransomware gang claims to hit German submarine builder Thyssenkrupp 2026-06-28
- Newer ransomware crews claim diagnostics maker Hologic and an Australian fire service 2026-06-28
- Ransomware affiliate hides a malicious Edge extension to hijack victim PCs 2026-06-23
- Ransomware crew Gentlemen arms affiliates with custom EDR killers 2026-06-19
- New ransomware crew The Gentlemen claims 20 victims in one week 2026-06-12
- LockBit floods its leak site with 26 victims in two days 2026-06-12
- New MLTBackdoor malware plants a stealthy foothold for ransomware 2026-06-12
- New Babuk Based Ransomware Hits Windows, VMware, and NAS Systems 2026-06-05
- 166 Victims in 33 Countries: NightSpire's Global Expansion in Numbers 2026-03-15
- Spectral Flux (NightSpire): Threat Actor Profile and Technical Analysis 2026-03-07
- NightSpire: The Rbfs Rebrand That Went From Data Theft to Double Extortion in Weeks 2026-02-16
- Two U.S. Cybersecurity Professionals Plead Guilty to ALPHV BlackCat Ransomware Attacks 2026-02-16
- LockBit 5.0 Cross-Platform Analysis: ChaCha20 Encryption, ESXi VM Shutdown Automation, and Near-Zero VirusTotal Detection 2026-02-16
- LockBit 5.0 Technical Deep Dive: ETW Patching, DLL Reflection Loading, and Cross-Platform ESXi Targeting Confirm Evolutionary Codebase 2026-02-16
- Akira Topped Sophos Ransomware Cases in 2024, Peaked at 17% of August Detections Amid Veeam Exploits 2026-02-16
- RansomHub (Knight/Cyclops Rebranded): CVE-2024-3400 and ZeroLogon in Sub-14-Hour Attack, PCHunter EDR Termination, FileZilla Exfiltration, and Multi-Platform Ransomware Variants 2026-02-16
- Inside BlackCat's Kill Chain: Picus Dissects ALPHV Ransomware TTPs After Change Healthcare Mega-Breach 2026-02-16
- North Korean Andariel Group Linked to Play Ransomware in Unprecedented Nation-State Collaboration 2026-02-16
- BlackByte Ransomware Evolves: Four Vulnerable Drivers, ESXi Zero-Day Exploitation, and Victim Credentials Baked Into the Payload 2026-02-16
- U.S. Indicts Dmitry Khoroshev as LockBit's Developer and Administrator: $500M Extorted, 2,500 Victims in 120 Countries 2026-02-16
- Operation Cronos Fallout: LockBit Admin Panel Exposed, 193 Affiliates Identified, and Post-Disruption Activity Reveals Inflated Victim Counts 2026-02-16
- From Conti Code to ESXi Servers: SentinelOne Decodes Akira's Cross-Platform Ransomware Evolution 2026-02-16
- CISA and FBI Issue Joint Advisory on ALPHV BlackCat Ransomware Targeting Critical Infrastructure 2026-02-16
- Akira Ransomware Targets Cisco VPNs Without MFA: Sophos Documents Over a Dozen Incidents 2026-02-16
- Play Ransomware (Playcrypt): FBI/CISA/ASD Joint Advisory on Closed-Group Double Extortion Operation Impacting 900+ Entities Across North America, South America, Europe, and Australia 2026-02-16
- LockBit Green: New Variant Incorporates Leaked Conti Source Code, Revealing Transitivity Links to BazaLoader and TrickBot Families 2026-02-16
- Cl0p Goes Linux — and Gets It Wrong: SentinelLabs Publishes Free Decryptor for Flawed ELF Ransomware Variant 2026-02-16
- CISA #StopRansomware: Hive Ransomware Claims 1,300+ Victims and $100M in Payments Targeting Healthcare and Critical Infrastructure 2026-02-16
- REvil Resurfaces: New Samples Confirm GOLD SOUTHFIELD Access to Source Code and Active Development 2026-02-16
- LockBit Affiliate Side-Loads Cobalt Strike via VMwareXferlogs.exe: Malicious glib-2.0.dll Bypasses EDR Hooks, ETW, and AMSI 2026-02-16
- CISA, FBI, and NSA Joint Advisory: Conti Ransomware Surpasses 1,000 Attacks with TrickBot, Cobalt Strike, and Double Extortion 2026-02-16
- TA505 Pivots from Phishing to CVE-2021-35211 SolarWinds Serv-U Exploitation: Cobalt Strike Delivery and RegIdleBackup COM Handler Hijacking for FlawedGrace RAT Persistence 2026-02-16
- Wizard Spider's Sidoh (Ryuk Stealer): Keyword-Based FTP Exfiltration Tool Targeting Government, Military, and Financial Files with Ryuk Source Code DNA 2026-02-16
- Hades Ransomware: How INDRIK SPIDER Reinvented Its Toolchain to Evade OFAC Sanctions 2026-02-16
- Reynolds Ransomware Bundles BYOVD Defense Evasion Directly Into Payload — A Rare and Dangerous Evolution 2026-02-05
- NightSpire Kill Chain: How a FortiOS Zero-Day Became Ransomware's Favorite Front Door 2026-02-01