Tag: ransomware
-
Key Operators of LockerGoga, MegaCortex, and Nefilim Ransomware Gangs Arrested
The U.S. District Court for the Eastern District of New York has charged Volodymyr Viktorovich Tymoshchuk, a Ukrainian national known as deadforz, Boba, msfv, and farnetwork, for his role in administering LockerGoga, MegaCortex, and Nefilim ransomware operations. The indictment alleges that Tymoshchuk managed attacks against more than 250 companies in the U.S. and hundreds of…
-
Akira ransomware crims abusing trifecta of SonicWall security holes for extortion attacks
Patch, turn on MFA, and restrict access to trusted networks”¦or else First seen on theregister.com Jump to article: www.theregister.com/2025/09/10/akira_ransomware_abusing_sonicwall/
-
Wyden calls on FTC to investigate Microsoft for ‘gross cybersecurity negligence’ in protecting critical infrastructure
The Oregon senator said Microsoft’s default settings for Windows and other products are enabling ransomware attacks, like the one against Ascension hospital system in 2024. First seen on cyberscoop.com Jump to article: cyberscoop.com/ron-wyden-ftc-microsoft-default-security-flaws-rc4-kerberoasting-ascension-ransomware/
-
US charges suspected ransomware kingpin, and offers $10 million bounty for his capture
A US federal court has unssealed charges against a Ukrainian national who authorities allege was a key figure behind several strains of ransomware, including LockerGoga, MegaCortex, and Nefilim. First seen on fortra.com Jump to article: www.fortra.com/blog/us-charges-suspected-ransomware-kingpin-offers-10-million-bounty
-
Ransomware Ein Cyberangriff hat die Systeme kompromittiert Was nun?
Netzpalaver hat seine Community zum Thema Ransomware befragt und die Community-Experten aus dem IT- und Cybersicherheitsbereich antworteten mit einem Video-Statement auf die Frage: ‘Ransomware: Ein erfolgreicher Cyberangriff hat die Systeme kompromittiert Was nun?” Statement von Zac Warren, Tanium Statement von Karl Heuser, NETSCOUT Statement von Martin Gegenleitner, Thales Weitere Video-Statements zu […] First seen on…
-
‘The Gentlemen’ Ransomware Targets Asia Pacific
Trend Micro Researchers Uncover New Ransomware Strain. A newly identified ransomware group is targeting victims across the Asia Pacific region using custom-built evasion capabilities that could pose a significant threat to organizations, warn researchers at security firm Trend Micro. The Gentlemen deploys customized methods tailored to each target. First seen on govinfosecurity.com Jump to article:…
-
Ransomware insurance losses spike despite fewer claims: Resilience
AI-powered phishing, “double extortion” tactics and insurance policy theft are fueling more destructive, costly ransomware attacks, the;cybersecurity firm said. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ransomware-insurance-losses-spike-claims-resilience-ai-phishing/759626/
-
We’ve crossed the security singularity – Impart Security
Tags: access, ai, api, attack, authentication, breach, ciso, compliance, credentials, cyber, cyberattack, cybersecurity, data, data-breach, defense, detection, exploit, framework, group, hacker, incident response, injection, intelligence, Internet, msp, password, penetration-testing, ransomware, risk, risk-assessment, skills, software, sql, strategy, supply-chain, threat, update, vulnerability, zero-day, zero-trustThe Bottom Line: We’ve Crossed the Security Singularity “ The Security Singularity: When AI Democratized Cyberattacks We’ve crossed a threshold that fundamentally changes cybersecurity forever. Not with fanfare or headlines, but quietly, in the background of our AI-powered world. The expertise barrier that once separated script kiddies from sophisticated threat actors has simply… vanished. I…
-
CyberVolk Ransomware Targets Windows Systems in Critical Infrastructure and Research Institutions
CyberVolk ransomware, which first emerged in May 2024, has escalated its operations against government agencies, critical infrastructure, and scientific institutions across Japan, France, and the United Kingdom. Operating with pro-Russian leanings, CyberVolk specifically targets states perceived as hostile to Russian interests, leveraging sophisticated encryption techniques that render decryption impossible. This article delivers a technical analysis…
-
CyberVolk Ransomware Targets Windows Systems in Critical Infrastructure and Research Institutions
CyberVolk ransomware, which first emerged in May 2024, has escalated its operations against government agencies, critical infrastructure, and scientific institutions across Japan, France, and the United Kingdom. Operating with pro-Russian leanings, CyberVolk specifically targets states perceived as hostile to Russian interests, leveraging sophisticated encryption techniques that render decryption impossible. This article delivers a technical analysis…
-
KillSec Ransomware Hits Brazilian Healthcare IT Vendor
A ransomware attack by KillSec on Brazil software provider MedicSolution threatens healthcare, impacting providers and patients First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/killsec-ransomware-hits-brazilian/
-
Ransomware Payments Plummet in Education Amid Enhanced Resiliency
Sophos found that average ransom demands and payments fell substantially in the education sector in 2025, as recovery time and costs fell First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ransomware-payments-plummet/
-
Ransomware Payments Plummet in Education Amid Enhanced Resiliency
Sophos found that average ransom demands and payments fell substantially in the education sector in 2025, as recovery time and costs fell First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ransomware-payments-plummet/
-
Ransomware im Bildungssektor – Sophos veröffentlicht State of Ransomware-Report
Die Ergebnisse basieren auf einer unabhängigen Befragung von 441 IT- und Security-Verantwortlichen, die 2024 Opfer eines Ransomware-Angriffs wurden 243 aus Grund- und weiterführenden Schulen, 198 aus Hochschulen. Alle Einrichtungen beschäftigen zwischen 100 und 5.000 Mitarbeiter und stammen aus 17 Ländern. Die Befragung lief von Januar bis März 2025. First seen on infopoint-security.de Jump to article:…
-
Ransomware upstart ‘The Gentlemen’ raises the stakes for OT”‘heavy sectors
Tags: access, attack, breach, ceo, ciso, credentials, cybersecurity, data, defense, endpoint, group, healthcare, insurance, intelligence, least-privilege, monitoring, network, ransomware, resilience, risk, supply-chain, threat, tool, update, vulnerability, zero-trustHigh-stakes industries make prime targets: The attacks have been spread across 17 countries, with Thailand and the US being the top targets, followed by Venezuela and India. The Gentlemen ransomware group already has a victim count of 27, with manufacturing and construction industries being the key targets, followed by healthcare, insurance, and others.”These sectors are…
-
KillSec Ransomware is Attacking Healthcare Institutions in Brazil
First seen on resecurity.com Jump to article: www.resecurity.com/blog/article/killsec-ransomware-is-attacking-healthcare-institutions-in-brazil
-
Bildungssektor gut gewappnet gegenüber Ransomware auf Kosten seines IT-Personals
Der Sophos-State-of-Ransomware-Report belegt, dass der Bildungssektor sich gut gegenüber Ransomware-Angriffen aufgestellt hat: 97 Prozent der von Datenverschlüsselung betroffenen Einrichtungen konnten ihre Daten wiederherstellen und Lösegeldzahlungen sanken rapide. Doch der Erfolg hat auch eine Kehrseite: das Personal ist am Limit. Die Ergebnisse des jährlichen ‘Sophos State of Ransomware in Education” liegen vor und belegen, dass der…
-
Uncle Sam indicts alleged ransomware kingpin tied to $18B in damages
Prosecutors claim Ukrainian ran LockerGoga, MegaCortex, and Nefilim ops $11M bounty on his head First seen on theregister.com Jump to article: www.theregister.com/2025/09/10/us_nefilim_ransomware_indictment/
-
KillSec Ransomware is Attacking Healthcare Institutions in Brazil
KillSec Ransomware claimed responsibility for a cyberattack on MedicSolution, a software solutions provider for the healthcare industry in Brazil. The KillSec Ransomware group has threatened to leak sensitive data unless negotiations are initiated promptly. According to threat intelligence reporting by Resecurity, the root cause of the incident data exfiltration from insecure AWS S3 bucket. […]…
-
U.S. indicts Ukrainian national for hundreds of ransomware attacks using multiple variants
The Department of Justice unsealed an indictment against a Ukrainian national alleged to be central to a ransomware campaign affecting hundreds of companies worldwide. Volodymyr Viktorovych Tymoshchuk, known online as “deadforz,” “Boba,” “msfv,” and “farnetwork,” is accused of developing and deploying ransomware variants Nefilim, LockerGoga, and MegaCortex, all of which have been used in attacks…
-
US Feds Indict Lockergoga and Megacortex Ransomware Hacker
State Department Offers Up to $10M for Tips on Volodymyr Tymoshchuk. A hacker who federal prosecutors say was behind the LockerGoga and MegaCortex ransomware strains faces a seven count criminal indictment in U.S. federal court, prosecutors said Tuesday. Ukrainian national Volodymyr Tymoshchuk, 28, was administrator of the two ransomware operations, prosecutors say. First seen on…
-
Major blood center says thousands had data leaked in January ransomware attack
New York Blood Center submitted documents to regulators in Maine, Texas, New Hampshire and California that confirmed the cyberattack, which they said was first discovered on January 26. First seen on therecord.media Jump to article: therecord.media/blood-center-discloses-details-on–january-ransomware-attack
-
Ukrainian national charged with helping run LockerGoga, MegaCortex and Nefilim ransomware
Volodymyr Tymoshchuk, currently a fugitive, was an administrator for multiple ransomware strains, including LockerGoga, said U.S. prosecutors in unsealing an indictment against the Ukrainian national. First seen on therecord.media Jump to article: therecord.media/lockergoga-megacortex-nefilim-ransomware-ukrainian-indictment-unsealed
-
Ransomware bei Easy Credit und Plan-B Rechtsanwälte
Gerade sind mir zwei Ransomware-Vorfälle in Deutschland bekannt geworden. Die Easy Credit (Tochter der DZ Bank) ist angeblich Opfer der Everest-Gruppe geworden. Und “Plan-B Die Fachanwaltskanzlei” hat es mit der Qilin-Ransomware-Gruppe zu tun. In beiden Fällen sollten Benutzerdaten abgeflossen sein. … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/09/09/ransomware-bei-easy-credit-und-plan-b-rechtsanwaelte/
-
US charges admin of LockerGoga, MegaCortex, Nefilim ransomware
The U.S. Department of Justice has charged Ukrainian national Volodymyr Viktorovich Tymoshchuk for his role as the administrator of the LockerGoga, MegaCortex, and Nefilim ransomware operations. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/us-charges-admin-of-lockergoga-megacortex-nefilim-ransomware/
-
New Cyber Attack Exploits DeskSoft to Spread Malware via RDP Command Execution
An emerging threat campaign has been identified that weaponizes a trojanized version of DeskSoft’s EarthTime application to deploy sophisticated malware, leveraging Remote Desktop Protocol (RDP) access for command execution and network reconnaissance. Security analysts attribute the intrusion to an affiliate operating across multiple ransomware-as-a-service groups and noted that the incident underscores the growing trend of…
-
New Cyber Attack Exploits DeskSoft to Spread Malware via RDP Command Execution
An emerging threat campaign has been identified that weaponizes a trojanized version of DeskSoft’s EarthTime application to deploy sophisticated malware, leveraging Remote Desktop Protocol (RDP) access for command execution and network reconnaissance. Security analysts attribute the intrusion to an affiliate operating across multiple ransomware-as-a-service groups and noted that the incident underscores the growing trend of…
-
New Cyber Attack Exploits DeskSoft to Spread Malware via RDP Command Execution
An emerging threat campaign has been identified that weaponizes a trojanized version of DeskSoft’s EarthTime application to deploy sophisticated malware, leveraging Remote Desktop Protocol (RDP) access for command execution and network reconnaissance. Security analysts attribute the intrusion to an affiliate operating across multiple ransomware-as-a-service groups and noted that the incident underscores the growing trend of…
-
New Cyber Attack Exploits DeskSoft to Spread Malware via RDP Command Execution
An emerging threat campaign has been identified that weaponizes a trojanized version of DeskSoft’s EarthTime application to deploy sophisticated malware, leveraging Remote Desktop Protocol (RDP) access for command execution and network reconnaissance. Security analysts attribute the intrusion to an affiliate operating across multiple ransomware-as-a-service groups and noted that the incident underscores the growing trend of…
-
LunaLock Ransomware threatens victims by feeding stolen data to AI models
LunaLock, a new ransomware gang, introduced a unique cyber extortion technique, threatening to turn stolen art into AI training data. A new ransomware group, named LunaLock, appeared in the threat landscape with a unique cyber extortion technique, threatening to turn stolen art into AI training data. Recently, the LunaLock group targeted the website Artists&Clients and…

