Tag: ransomware
-
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims.Swiss cybersecurity company PRODAFT is tracking the centrally administered RaaS operation under the name Funky Mantis.”The portal combined build generation, finance, First seen on thehackernews.com…
-
Hackers Use Stealer Logs to Bypass MFA and Launch Ransomware Attacks
Infostealer malware has now become the invisible thread linking petty credential theft to full-blown ransomware campaigns. Attackers no longer bother forcing their way through firewalls when infostealers have already unlocked the front door for them. Documented by DarkOwl, a stealer log archive generated by infostealer malware that silently harvests browser-saved passwords, session cookies, cryptocurrency wallet data,…
-
Cl0p Targets Internet-Exposed Windchill Servers in Global Engineering Data-Theft Campaign
Cl0p ransomware affiliates are actively exploiting internet-exposed PTC Windchill and FlexPLM deployments in a global data-theft campaign targeting high-value engineering environments. Observed post-exploitation activity includes filesystem enumeration via files such as “flst.txt,” followed by staging and exfiltration of sensitive engineering and product design data. This chaining enables unauthenticated remote code execution, allowing attackers to deploy…
-
Ransomware Attacks Targeting Universities on the Rise
Comparitech’s analysis of incidents in the first half of 2026 finds that the emergence of The Gentlemen ransomware has resulted in surge in attacks against higher education First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/university-ransomware-attacks-rise/
-
Clop ransomware targets Windchill, FlexPLM in data theft attacks
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks/
-
InfoGuard Threat Intelligence Insights 2025 – Bei 68 Prozent der unsicheren VPN-Zugänge dringt Ransomware ein
First seen on security-insider.de Jump to article: www.security-insider.de/ransomware-vpn-zugaenge-cyberangriffe-2025-a-f9aebac63f3383f7d23e8fec9f44326c/
-
KI macht Ransomware-Angriffe gefährlicher
Künstliche Intelligenz verändert die Vorgehensweise von Cyberkriminellen und erhöht die Erfolgsquote von Ransomware-Angriffen deutlich. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/ki-ransomware-angriffe-gefaehrlicher
-
Ransomware gangs go after EMEA healthcare’s supply chain
A ransomware attack against a hospital makes headlines, while attacks on the rest of the ecosystem around it tend to stay quiet despite doing damage that can be just as bad. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/24/emea-healthcare-ransomware-activity/
-
Ransomware in 2026: More groups, more victims, no slowdown
Ransomware activity followed a recognizable pattern during the previous four years. Each year was defined by a dominant actor, its collapse, or a major supply chain incident. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/24/ransomware-attack-trends-2026-report/
-
Chaos ransomware deploys browser-based msaRAT to evade network detection
Cisco Talos uncovered msaRAT, a Chaos ransomware RAT that hides C2 traffic by routing it through Chrome or Edge using the Chrome DevTools Protocol. Cisco Talos disclosed msaRAT, a Rust-based remote access trojan attributed to the Chaos ransomware group that routes its entire command-and-control channel through the victim’s own Chrome or Edge browser. The malware…
-
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
The Chaos ransomware group ran its command-and-control through the victim’s own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor.The implant never opens an outbound connection of its own. Its process talks to 127.0.0.1 and nothing else. It starts Chrome or Edge…
-
Chaos ransomware’s msaRAT: Living off the browser to build a covert C2 channel
The Chaos ransomware group uses new malware “msaRAT” that hijacks browsers. The malware doesn’t communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker’s IP from victims via WebRTC over TURN. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/
-
Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process
Cisco Talos has identified a Rust-based remote access trojan it attributes to the Chaos ransomware group, named msaRAT after four of the binding names left in the binary. The … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/23/cisco-talos-chaos-ransomware-msarat/
-
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
The Chaos ransomware gang is using a new backdoor dubbed msaRAT that hides command-and-control (C2) communication by routing it through the Chrome or Edge browsers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-msarat-malware-uses-chrome-edge-browsers-to-route-c2-traffic/
-
Swiss train maker Stadler refuses Everest $12 million ransomware demand
Stadler Rail said it will not make a $12.3 million ransom payment after cybercriminals stole technical data from a supplier’s file-sharing platform. First seen on therecord.media Jump to article: therecord.media/stadler-refuses-everest-ransom-demand
-
Two-Thirds of Ransomware Victims Say AI Boosted Attack Effectiveness
A new study of organizations which have fallen victim to ransomware suggests the rise of AI-tools being used by hackers is making life harder for defenders First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ai-boosts-ransomware-effectiveness/
-
New ransomware group uses printers to deliver ransom notes
First seen on scworld.com Jump to article: www.scworld.com/brief/new-ransomware-group-uses-printers-to-deliver-ransom-notes
-
Stadler Rail refuses to pay $12.3 million ransom after ransomware attack
First seen on scworld.com Jump to article: www.scworld.com/brief/stadler-rail-refuses-to-pay-12-3-million-ransom-after-ransomware-attack
-
JADEPUFFER agentic ransomware returns, targets AI assets with ENCFORGE payload
First seen on scworld.com Jump to article: www.scworld.com/news/jadepuffer-agentic-ransomware-returns-targets-ai-assets-with-encforge-payload
-
Ransomware Attack Puts a Chill On Japanese Frozen-Food Chain
A cyberattack on a food and logistics firm disrupts the supply of frozen food to thousands of clients, including major franchises like Kentucky Fried Chicken. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/ransomware-attack-japanese-frozen-food-chain
-
Anubis Ransomware Halts Fairlife Milk Production in the US
Gang Claims 1TB of Stolen Data and Sets Deadline for Ransom Talks. Anubis claims it encrypted Fairlife’s production systems and stole 1 terabyte of data, forcing the Coca-Cola-owned dairy brand to suspend U.S. milk production while investigators assess the ransomware incident and work to restore operations. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/anubis-ransomware-halts-fairlife-milk-production-in-us-a-32297
-
How Agentic Ransomware is Changing Enterprise Cybersecurity
Agentic ransomware is reshaping cyberattacks through autonomous AI. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/how-agentic-ransomware-is-changing-enterprise-cybersecurity/
-
Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/swiss-rail-giant-stadler-rejects-123m-ransom-demand-after-cyberattack/
-
Threat group claims credit for ransomware attack on Coca-Cola’s dairy unit
The attackers previously exploited vulnerabilities or used stolen credentials for initial access.; First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/threat-group-ransomware-coca-colas-dairy-Fairlife/825900/
-
How enterprise GenAI can amplify ransomware risk, and how to contain it
Enterprise AI can accelerate ransomware attacks when AI assistants and agents inherit excessive permissions or compromised identities. Acronis explains how identity controls, governance, and least-privilege access help reduce AI-enabled ransomware risk while supporting secure AI adoption. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/how-enterprise-genai-can-amplify-ransomware-risk-and-how-to-contain-it/
-
Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns
Global ransomware attacks climbed 3% in the second quarter of 2026, rising from 2,165 incidents in Q1 to 2,229, according to NCC Group’s latest Quarterly Cyber Threat Intelligence Report. While the increase in volume was modest, the security firm warned that supply chain attacks are growing rapidly in both scale and sophistication, and that the…
-
Ransomware, Spies and Hacktivists Converge on UK and Ireland, New Threat Report Warns
A new threat intelligence report has painted a stark picture of the cyber risks facing the UK and Ireland, describing an environment in which ransomware gangs, nation-state spies and politically motivated hacktivists are increasingly working the same terrain, often against the same victims. The >>Cyber Threat Landscape: UK & Ireland<< report, published by threat intelligence…
-
Ransomware JadePuffer greift KI-Modell-Daten mit EncForge an
Der autonome KI-Agent JadePuffer nutzt die Erpressersoftware EncForge zur Verschlüsselung von Trainingsdaten und Vektordatenbanken. Sysdig schlägt Alarm. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/ransomware-jadepuffer-ki
-
Ransomware trifft die Produktion zunehmend über IT- und OT-nahe Systeme
Wenn von Cyberangriffen auf Industrieunternehmen die Rede ist, denken viele zunächst an manipulierte Maschinen oder kompromittierte Steuerungssysteme. Doch ein aktueller Berichte des OT-Cybersicherheitsanbieters Dragos zeigt ein anderes Bild: Oft müssen Angreifer die Produktionstechnik gar nicht direkt angreifen, um den Betrieb empfindlich zu stören [1]. Die heutige Umgebung von Industrieanlagen hat sich deutlich erweitert Moderne Betriebs- und… First…
-
Ecopetrol confirms ransomware attempt, data stolen from 3,300 accounts
First seen on scworld.com Jump to article: www.scworld.com/brief/ecopetrol-confirms-ransomware-attempt-data-stolen-from-3300-accounts

