Tag: ransomware
-
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor.The use of StormEncryptor marks a shift from the adversary’s previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said.”StormEncryptor is written in C++ and appends the file name extension .encrypted First seen…
-
SonicWall SMA1000 flaws now exploited by ransomware gangs
CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-sonicwall-sma1000-flaws-now-exploited-by-ransomware-gangs/
-
China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns
Tags: china, cybersecurity, exploit, hacker, microsoft, ransomware, software, threat, tool, vulnerabilityA China-linked threat actor is believed to be exploiting a critical vulnerability affecting cybersecurity software from the company N-able. First seen on therecord.media Jump to article: therecord.media/china-hackers-ransomware-microsoft
-
Play Ransomware Masquerades as PsExec to Blend Into Legitimate Windows Administration
Play ransomware is using a familiar Windows-administration disguise to reduce suspicion during intrusions: a custom service binary named PSexesvc.exe. The group’s use of a custom service binary named PSexesvc.exe, mimicking Microsoft Sysinternals PsExec, illustrates how attackers can turn routine Windows administration into cover for lateral movement and payload execution. The binary has been observed alongside…
-
Sophos Warns Unprotected Endpoints Let Interlock Credential Theft Go Undetected
Interlock ransomware incident that shows how unprotected endpoints can give attackers enough time to steal credentials, establish persistence, and reach a domain controller before defenders intervene. During a March 2026 response engagement, Sophos Emergency Incident Response investigators found the group abusing legitimate forensic utilities, including Volatility3 and WinPmem, to acquire memory and extract credential material…
-
Ransomware Attackers Compromise Multiple Employees Inside the Same Company
Ransomware operations are increasingly targeting the people behind critical business processes, not just privileged IT administrators. Over a one-month observation period, ThreatLabz identified 351 victims across 334 organizations connected to a single ransomware campaign. More than a dozen of those organizations had multiple employees compromised, indicating that an initial account takeover may be only the…
-
Ransomware-Attacke in Rhein-Nahe – ‘Als wäre man aus seinem eigenen Haus ausgesperrt”
Tags: ransomwareFirst seen on security-insider.de Jump to article: www.security-insider.de/als-waere-man-aus-seinem-eigenen-haus-ausgesperrt-a-c1663abc76ada6f52fb75dfe33d3bf52/
-
Flock’s Plans for Rideshare Dashcams and Coaching Police, Revealed
Plus: A judge rules cell tower dumps unconstitutional, water utility hacks spread to a dozen states, a phishing email opens a missile-parts supplier’s inbox, and a ransomware boss gets 16 years. First seen on wired.com Jump to article: www.wired.com/story/flocks-plans-for-rideshare-dashcams-and-coaching-police-revealed/
-
Storm-1175 Launches StormEncryptor Ransomware Attacks Using N-able Security Flaw
Microsoft Threat Intelligence has identified a new ransomware campaign attributed to the financially motivated threat actor Storm-1175 that began deploying a previously undocumented ransomware strain, StormEncryptor, on August 2, 2026. The activity represents Storm-1175’s first observed operation since April 2026 and signals a notable shift in its ransomware tooling. The group was previously associated with…
-
Zscaler’s Brett Stone-Gross on which roles are targeted in ransomware attacks
First seen on scworld.com Jump to article: www.scworld.com/resource/zscalers-brett-stone-gross-on-which-roles-are-targeted-in-ransomware-attacks
-
The Cyber Express Weekly Roundup: Ransomware Surge, Government Data Breaches, Logistics Disruptions, and Third-Party Security Risks
This weekly roundup highlights the growing cybersecurity risks affecting businesses, government agencies, and critical service providers. From the continued dominance of ransomware operations to government database breaches and third-party supply chain incidents, recent events demonstrate how attackers are increasingly targeting trusted systems and external service providers to maximize disruption and data exposure. First seen on thecyberexpress.com Jump…
-
Ransomware Surges in July After Q2 Lull
Finance, technology and healthcare sectors were particularly heavily targeted in July, according to Comparitech First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ransomware-surges-july-q2-lull/
-
Ransom Cartel Leader Sentenced to 16 Years in U.S.
A U.S. court sentenced Ransom Cartel founder Maksim Silnikau to 16 years for running a ransomware-as-a-service operation. Maksim Silnikau (aka >>J.P. Morgan,<>lansky,<>xxx,<<) built a ransomware business the way a franchise owner builds a chain: he never had to touch most of the crime scenes himself. This week, a federal judge in Virginia […] First seen…
-
Belarusian cybercriminal behind Ransom Cartel gets 16-year prison sentence
A Belarusian national active in the cybercriminal world for decades was sentenced to 16 years in U.S. prison for running the Ransom Cartel ransomware operation. First seen on therecord.media Jump to article: therecord.media/belarus-hacker-ransomware-sentenced
-
Defending Water OT with AZT PROTECT – ARIA Cybersecurity
<div cla The threat landscape for municipal water systems has never been more perilous, and the regulatory spotlight has never been brighter. A flurry of attacks has taken over the news: in some cases, ransomware-based attacks cripple water production and in other cases controls on individual unprotected PLCs are being suddenly accessed by bad actors…
-
Kill switch fears now rival ransomware as a top security risk for European businesses, Proton study finds
For years, the security team’s job has been to defend against cyberattacks. New research from Proton suggests that job now needs to extend to a very different kind of threat: the risk that a foreign government orders a US technology provider to cut a business off entirely. A study of 1,500 business decision-makers across the…
-
South Korea’s government overtakes telcos as top cyber attack target
Kaspersky researcher Sojun Ryu says ransomware crews have joined nation-state groups in going after South Korean organisations, as traces of LLM output start turning up inside malware First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366647735/South-Koreas-government-overtakes-telcos-as-top-cyber-attack-target
-
Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service
A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel, the ransomware-as-a-service operation he stood up in 2021.Between 2021 and 2023, Ransom Cartel conspirators attacked at least 18 companies, including firms in California, New York and Nebraska, and others abroad, according to…
-
Ransom Cartel ransomware creator sentenced to 16 years in prison
Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ransom-cartel-ransomware-creator-sentenced-to-16-years-in-prison/
-
Ransomware Hackers Are Hiding Malware Command Servers Inside Ethereum Smart Contracts
Ransomware operators are now abusing Ethereum smart contracts as stealthy command”‘and”‘control resolvers, with a Gentlemen ransomware affiliate using the EtherRAT backdoor to pull rotating C2 domains directly from the blockchain instead of hardcoding them in the malware. The toolkit shows a clear progression: scheduled tasks that bootstrap PowerShell, privileged account creation (“support2” with Supp0rt2@2026!). LSASS…
-
Prolific ransomware group behind SonicWall zero-day attacks
INC ransomware wasn’t the first group to exploit the zero-days, but it’s been the most assertive and effective in chaining both vulnerabilities to steal and encrypt data for extortion. First seen on cyberscoop.com Jump to article: cyberscoop.com/inc-ransomware-sonicwall-zero-day-attacks/
-
INC Ransomware is Calling Victims Pressure Tactics Post SonicWall Zero-Day Exploit
INC Ransomware exploits SonicWall SMA 1000 flaws, using calls and emails to pressure victims during extortion campaigns targeting global organizations. Resecurity disclosed that INC Ransomware has emerged as the dominant threat actor exploiting the recently disclosed SonicWall Secure Mobile Access (SMA) 1000 vulnerabilities. According to the company’s research, the group has accelerated its operations since…
-
Russian Access Broker Sells Network Access to Ransomware Gangs While Spying on Ukraine
Tags: access, cyber, data-breach, defense, exploit, intelligence, network, ransomware, russia, ukraineAn exposed server linked to a Russian”‘speaking initial access broker (IAB) has revealed a sprawling operation that simultaneously fuels ransomware intrusions worldwide and supports Russian state-aligned intelligence collection against Ukrainian defense and aerospace targets. The artefacts show a mature, high”‘volume access brokerage pipeline that industrialises exploitation of internet”‘facing appliances, pivots to full Active Directory compromise,…
-
Ransomware nutzt VPNs in Fabriken aus – Fernzugriff in der Fertigung: Secomea mahnt strengere Kontrolle an
First seen on security-insider.de Jump to article: www.security-insider.de/fernzugriff-in-der-fertigung-secomea-mahnt-strengere-kontrolle-an-a-5bd17237b3ff4e1a4a88131854d39c30/
-
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
The INC Ransomware operation has emerged as the “dominant threat actor” exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances.In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its data…
-
River Bank obtained assurances from the attackers that the stolen data in the June attack was deleted
River Bank says hackers deleted data stolen in its June ransomware attack, though the investigation into the incident is still ongoing. River Financial Corporation, the parent company of River Bank & Trust, says hackers deleted data stolen during a ransomware attack that hit parts of its server environment in June. The breach began on June…
-
How the World’s Most Active Ransomware Operation Expanded in H1 2026
The first half of 2026 reinforced a familiar reality in ransomware: a small number of highly capable operators continue to drive a disproportionate share of global attacks. Among them, Qilin ransomware emerged as the most active threat group tracked by Cyble Research and Intelligence Labs (CRIL), demonstrating the scale and reach of today’s ransomware-as-a-service (RaaS) ecosystem. First seen on thecyberexpress.com Jump to article:…
-
From WSProxy to Root: INC ransomware and SonicWall SMA Exploit Chain
First seen on resecurity.com Jump to article: www.resecurity.com/blog/article/from-wsproxy-to-root-inc-ransomware-and-sonicwall-sma-exploit-chain
-
CRPx0 Ransomware Claims Hyundai Turkey Breach, Steals 1.5GB of Assessment Data
The double-extortion ransomware group CRPx0 has listed Hyundai’s Turkish operations on its dark web leak site, claiming to have exfiltrated 1.5 GB of sensitive personnel and recruitment data from the automaker’s assessment systems. According to CyberWatch, first flagged on its data-leak portal, the target is described as a >>Korean automotive manufacturer (Turkish operations)<< with the…

