Tag: ransomware
-
Ransomware-Tool <> bereitet laterale Bewegung im kompromittierten Netzwerk vor
Zscaler ThreatLabz hat eine neue Malware-Familie mit der Bezeichnung <> analysiert, die die laterale Bewegung innerhalb kompromittierter Umgebungen vorbereitet. Als Grundlage für Ransomware-Angriffe wird SloppyRAT über eine mehrstufige Clickfix-Infektionskette verbreitet. Die Malware unterstützt eine Vielzahl von Funktionen, darunter eine große Anzahl integrierter Powershell-ähnlicher Befehle, verschlüsselte Codeblöcke, ‘EtherHiding” für die Command-and-Control-Auflösung (C2) über das Polygon-JSON-RPC-Protokoll sowie…
-
Backup überlebt doch die Recovery scheitert
Backups allein schaffen noch keine Cyberresilienz. Entscheidend ist, ob sich Systeme nach Ransomware oder Totalausfall schnell, vollständig und unabhängig vom bisherigen Anbieter wiederherstellen lassen. Die französische Plattform Cybee setzt dafür auf Restic, offene Formate, S3-kompatiblen Objektspeicher und eine konsequent getrennte Daten- und Steuerungsebene muss Leistungsfähigkeit und Skalierbarkeit aber noch breiter belegen. Management Summary Recovery… First…
-
3 Cyber Threats That Defined the Summer of 2026
This installment of the Reporters’ Notebook video series discusses the impact of AI agents breaching Hugging Face, Fairlife’s ransomware attack, and Iranian-linked threat actors compromising a dozen US water systems. It was a busy summer. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/3-cyber-threats-defined-summer-2026
-
Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims
Ransom notes by n0n ransomware claim to take double extortion to a new level of danger for victims First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ransomware-gang-uses-backup/
-
Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims
Ransom notes by n0n ransomware claim to take double extortion to a new level of danger for victims First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ransomware-gang-uses-backup/
-
Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims
Ransom notes by n0n ransomware claim to take double extortion to a new level of danger for victims First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ransomware-gang-uses-backup/
-
Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims
Ransom notes by n0n ransomware claim to take double extortion to a new level of danger for victims First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ransomware-gang-uses-backup/
-
Ukrainian ransomware developer jailed for nearly 13 years
A court in Zurich has sentenced a Ukrainian man to 12 years and nine months in prison, and banned him from Switzerland for ten years, for developing ransomware that blackmailed companies around the world. First seen on bitdefender.com Jump to article: www.bitdefender.com/en-us/blog/hotforsecurity/ukrainian-ransomware-developer-jailed-for-nearly-13-years
-
Ransomware gangs now exploiting critical TeamCity flaw
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw/
-
New Galago Ransomware Operation Emerges With Links to Panzer Extortion Group
A newly identified ransomware operation tracked as Galago has emerged with apparent operational links to the Panzer ransomware group, raising concerns of an expanding double-extortion ecosystem targeting organizations worldwide. Researchers began directly monitoring Galago’s dark leak site (DLS) on 15 September 2026. At the time of observation, the group’s Tor-based leak portal was inactive and…
-
Warum das Berlin-Problem eben gerade kein Berlin-, sondern ein Deutschland-Problem ist
Rund 5,8 Terabyte Daten hat die Cybergruppe Rhysida bei ihrem Ransomware-Angriff auf das Netz der Berliner Landesverwaltung genauer, die Bereiche der Senatsverwaltung für Stadtentwicklung, Bauen und Wohnen und der Senatsverwaltung für Mobilität, Verkehr, Klimaschutz und Umwelt erbeutet. Knapp 1,2 Millionen unverschlüsselte Dateien, die unter anderem auch Informationen zu Beamten und Angestellten wahrscheinlich auch zu Antragstellern enthalten, hat sie mittlerweile […] First…
-
Clop Ransomware Responds to ShinyHunters Amid Eight-Figure Demands
Clop responds to ShinyHunters after its leak site takeover as the group demands an eight-figure payment, interest and a public apology in their escalating feud. First seen on hackread.com Jump to article: hackread.com/clop-ransomware-responds-shinyhunters-demands/
-
ShinyHunters Hacks and Defaces Clop Ransomware Leak Site
ShinyHunters hacked and defaced Clop’s ransomware leak site, replacing its content with ShinyHunters branding as its own onion site goes offline. First seen on hackread.com Jump to article: hackread.com/shinyhunters-hacks-defaces-clop-ransomware-leak-site/
-
ShinyHunters cybercrime gang takes over Cl0p ransomware site, demands extortion payment
The ShinyHunters extortion group hijacked the dark web leak site of the prolific Cl0p ransomware gang, according to material posted on the site over the weekend. First seen on therecord.media Jump to article: therecord.media/shinyhunters-clop-cyberattack-website
-
ShinyHunters Claim Hack of Rival Ransomware Gang Clop
ShinyHunters has claimed responsibility for hacking the Clop ransomware group, defacing its leak site and alleging theft of key operational data First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/shinyhunters-claim-hack-of-clop/
-
PAYLOAD Ransomware Abuses Active Directory Group Policy to Disrupt Entire Windows Domain
A ransomware incident in which attackers used Active Directory Group Policy to disrupt operations without deploying a Windows encryptor or leaving malware running on endpoints. In April 2026, the attackers accessed a FortiGate SSL VPN using compromised domain credentials, then gained domain-admin-equivalent rights. PAYLOAD Ransomware On April 13, Kaspersky’s Global Emergency Response Team (GERT) created…
-
UAE Cyber Chief Says Country Faced 640,000 Cyberattacks in One Day
The UAE faced 640,000 cyberattacks in one day, its cyber chief says, highlighting risks from unpatched software, ransomware, and deepfakes. The post UAE Cyber Chief Says Country Faced 640,000 Cyberattacks in One Day appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-uae-640000-cyberattacks-deepfakes-ransomware-emea/
-
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation’s data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang/
-
Settra ransomware variant deployed in recent attacks
Security researchers warned that hackers are using VPN credentials for initial access and deploying RMM tools. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/settra-ransomware-variant-recent-attacks/830787/
-
New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing
Huntress researchers highlighted a new ransomware variant, named Settra, and the post-compromise techniques used in two recent attacks First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/settra-ransomware-retail/
-
Feral Wolf Hackers Exploit Confluence and 1C to Deploy GenieLocker Ransomware
Feral Wolf has expanded its ransomware tradecraft by abusing exposed Atlassian Confluence servers and insecure 1C:Enterprise deployments to gain access to Russian corporate networks before deploying GenieLocker ransomware. The campaign, tracked from May through August 2026, targeted organizations in the retail, construction, manufacturing, and IT sectors. BI.ZONE DFIR investigators found that the threat actor combined…
-
New SETTRA Ransomware Uses MeshAgent RMM and BYOVD to Encrypt Windows Systems
A newly observed ransomware operation dubbed SETTRA is abusing the legitimate MeshAgent remote monitoring and management platform for persistence while using recovery-inhibition and defense-evasion techniques to maximize the impact of Windows encryption attacks. Huntress investigated two SETTRA incidents in July and September 2026, uncovering a repeatable operational pattern involving victim-specific ransomware binaries, Windows log clearing,…
-
JADEPUFFER Evolves Agentic Ransomware to Target AI Models and Training Data
Tags: ai, attack, cyber, data, data-breach, extortion, group, infrastructure, intelligence, ransomware, threat, trainingJADEPUFFER, the agentic threat actor first linked to an autonomous ransomware operation against exposed Langflow infrastructure, has evolved its tooling to target artificial intelligence models, training datasets, and vector data. Its latest payload, ENCFORGE, marks a shift from conventional database extortion toward destruction-focused attacks on high-value AI and machine-learning assets. The group’s ENCFORGE locker targets…
-
Manufacturing Accounts for 22% of all Ransomware Victims
Black Kite has found that manufacturing remained the most targeted sector for ransomware attacks, and saw a big jump in incidents in H1 2026 First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/manufacturing-22-ransomware-victims/
-
New Settra Ransomware Strain Deploys MeshAgent RMM for Persistence
Researchers at Huntress have detailed two ransomware incidents involving Settra, a relatively new strain first observed in June, and revealed a consistent set of post-compromise tactics defenders can use to spot the threat before encryption takes hold. In a blog post published this week, Huntress researchers Harlan Carvey and Lindsey O’Donnell-Welch said the company had…
-
Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin’s AI use
Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/ransomware-incidents-in-japan-in-the-first-half-of-2026/
-
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky.The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for…
-
The true cost of a ransomware attack, with and without BCDR
The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to recovery. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/the-true-cost-of-a-ransomware-attack-with-and-without-bcdr/
-
CISOs to Watch in Atlanta: From City Hall to the Credit Bureau
Atlanta has more reason than most cities to take security leadership seriously. The 2018 ransomware attack on city systems and the 2017 Equifax breach both happened here, and both organisations appear on this list under new security leadership. The other… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/cisos-to-watch-in-atlanta-from-city-hall-to-the-credit-bureau/
-
Cisco FMC Flaws Give Ransomware and APTs a Path Into Internal Networks
Cisco Talos says attackers are exploiting FMC flaws to steal credentials, tunnel into internal networks, and deploy Qilin ransomware. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-cisco-fmc-vulnerabilities/

