Tag: ransomware
-
‘MessiahGPT’ AI Service Promises Ransomware, Phishing Kits, and Malware
Trellix says MessiahGPT is marketed to cybercriminals as an uncensored AI service for ransomware, phishing kits, malware, and breach exploitation. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/artificial-intelligence/news-messiahgpt-malware-phishing-ai/
-
Philips and GE Investigate Clop Ransomware Data Theft Claims
Philips and GE are investigating Clop data theft claims potentially linked to a PTC vulnerability. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/philips-and-ge-investigate-clop-ransomware-data-theft-claims/
-
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
IntroductionIn July 2026, Zscaler ThreatLabz identified a new Rust-based malware family that we track as C2Looper, which is likely leveraged by a ransomware-related threat actor. Furthermore, ThreatLabz assesses with low to medium confidence that C2Looper has been delivered to victims through a multi-stage ClickFix infection chain. C2Looper supports backdoor commands including executing arbitrary commands, performing reconnaissance,…
-
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
Tags: blockchain, communications, data, extortion, group, infrastructure, leak, microsoft, network, ransomware, service, threatThe ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience.”Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process,” the Microsoft Threat First seen on thehackernews.com Jump…
-
ExfilSquad Targets New Victims, Shares Data via Torrents
ExfilSquad targets 13 organizations, exploiting cloud portals for data theft and using torrents to spread stolen information and amplify damage. Resecurity is tracking the activity of ExfilSquad the group announced new victims this week. ExfilSquad is a new cybercrime group that emerged in mid-2026. Instead of using ransomware, it steals data and threatens to […]…
-
Alert: Unpatched Fortinet Devices Fall to Gunra Ransomware
Tags: access, cybersecurity, firewall, fortinet, government, group, infrastructure, korea, north-korea, ransomware, vpnUS and South Korea Tie Initial Access to Unpatched Firewalls and VPN Gateways. Critical infrastructure organizations running unpatched firewalls and VPN gateways – including Fortinet gear not updated since early 2025 – and getting hit hard by a ransomware group with possible ties to the North Korean government, warns a joint U.S.-South Korean cybersecurity alert.…
-
QA: Ransomware is now a ‘fully fledged industry’, says cybercrime journalist Geoff White
Cybercrime no longer divides neatly between lone hackers, organised gangs and state-backed operations. These groups exchange tactics and tools, while stolen data gives them an asset that can be sold, used for fraud, held to ransom or weaponised for political damage. Geoff White is an award-winning investigative journalist whose reporting has taken him inside global…
-
Ransomware Attacks Are Targeting Managers and other Business Leaders
Zscaler findings show ransomware attackers increasingly target managers and business leaders. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/ransomware-attacks-are-targeting-managers-and-other-business-leaders/
-
Ransomware-Attacken in Deutschland, Österreich und der Schweiz
Ransomware-Angriffe sind laut Schlagzeilen gefühlt allgegenwärtig. Die Gefahr ist enorm jeder Fall für das Unternehmen eine eventuell existenzbedrohende Katastrophe. Wie groß ist aber die tatsächliche Dimension des Problems und die für die Opfer negative Erfolgsrate der Hacker? Die Sicherheitsexperten von Bitdefender haben anhand verschiedener Quellen ausgewertet, welche erfolgreichen Angriffe und Opfer Cyberkriminelle weltweit und […]…
-
Microsoft SharePoint flaw now exploited in ransomware attacks
CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-flaw-now-exploited-in-ransomware-attacks/
-
China-Linked Hackers Use N-able Flaw in Ransomware Attacks
Microsoft Says Storm-1175 Exploited CVE-2026-18577 After Its Disclosure. Microsoft says China-linked Storm-1175 is exploiting N-able N-central authentication bypass CVE-2026-18577 to gain administrative RMM access, pivot into managed endpoints and rapidly deploy its new StormEncryptor ransomware. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/china-linked-hackers-use-n-able-flaw-in-ransomware-attacks-a-32506
-
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
Tags: attack, breach, cybersecurity, exploit, finance, flaw, fortinet, government, healthcare, infrastructure, intelligence, korea, network, ransomware, serviceCybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world.Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services.”Gunra is another variant in the ongoing trend of First seen on thehackernews.com…
-
US and South Korea warn of Gunra ransomware targeting govt agencies
U.S. federal agencies and South Korea’s National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/us-warns-of-gunra-ransomware-attacks-against-government-critical-infrastructure/
-
CISA Warns SonicWall SMA1000 Flaws Are Exploited in Ransomware Attacks
Tags: attack, cisa, cve, cyber, cybersecurity, exploit, flaw, infrastructure, kev, ransomware, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in SonicWall SMA1000 to its Known Exploited Vulnerabilities catalog, noting that the flaw has been used in ransomware campaigns. This vulnerability, tracked as CVE-2026-15409, is a server-side request forgery (SSRF) issue found in the Workplace interface of SonicWall SMA1000 appliances. It has…
-
Ransomware gangs don’t need control system access to disrupt industrial production
Disrupting IT systems that support industrial environments can be enough to interrupt production, even when ransomware operators do not gain direct access to industrial … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/11/industrial-ransomware-attacks-q2-2026/
-
DeadLock Ransomware Disables Windows Defender, Backups and Event Logs Before Encrypting Files
DeadLock, an emerging financially motivated ransomware operation that couples conventional intrusion tradecraft with decentralized infrastructure engineered to survive disruption. First observed in July 2025, the operation uses double extortion: encrypting enterprise data while threatening publication of stolen material. The encryptor’s pre-encryption routine is built to degrade both prevention and recovery. After XOR-decoding an embedded configuration,…
-
CISA Urges Organizations to Patch Exposed VPNs and Segment Networks Against Gunra Ransomware
Tags: advisory, breach, cisa, credentials, cyber, data, data-breach, encryption, exploit, firewall, infrastructure, international, law, network, organized, ransomware, service, theft, update, vpnCISA and international law-enforcement partners have issued a joint #StopRansomware advisory warning that Gunra ransomware affiliates are exploiting exposed edge infrastructure, including VPN gateways, firewall appliances and RDP-accessible systems, to breach enterprise networks. The advisory positions Gunra as an increasingly organized ransomware-as-a-service operation whose affiliates combine data theft, credential compromise and rapid encryption to pressure…
-
Führungskräfte ins Visier: Ransomware-Akteure zielen auf Inhaber privilegierter Rechte
Tags: ransomwareFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/fuehrungskraefte-visier-ransomware-akteure-inhaber-privileg-rechte
-
The Art of Detonating Malware: Lessons from a Research Lab
Modern ransomware operators are no longer content to simply encrypt data and hope for a payout. They are actively working to evade every layer of enterprise defense, from sandboxes and EDR to backup infrastructure itself, using techniques observed in Cohesity’s in-house REDLab malware research environment. For security leaders, backup and recovery systems can no longer..…
-
China-Linked Hackers Exploit N-able Flaw in Ransomware Attacks
Microsoft Says Storm-1175 Exploited CVE-2026-18577 After Its Disclosure. Microsoft says China-linked Storm-1175 is exploiting N-able N-central authentication bypass CVE-2026-18577 to gain administrative RMM access, pivot into managed endpoints and rapidly deploy its new StormEncryptor ransomware. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/china-linked-hackers-exploit-n-able-flaw-in-ransomware-attacks-a-32506
-
FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure
The Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned. First seen on therecord.media Jump to article: therecord.media/ransomware-south-korea-fbi-gunra
-
U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang
The ransomware-as-a-service outfit has gone after a range of critical infrastructure sectors across the globe. First seen on cyberscoop.com Jump to article: cyberscoop.com/us-south-korea-gunra-ransomware-warning/
-
New StormEncryptor ransomware used by former Medusa affiliate
A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-stormencryptor-ransomware-used-by-former-medusa-affiliate/

