ZeroHour

Search: “pattern”

764 stories

How Ransomware Gangs Use Automation, and How You Can Beat It

Recorded Future outlines ten automation strategies ransomware gangs use, from credential marketplaces to bulletproof hosting, urging intelligence-led defense.

A Recorded Future blog post promoting an Insikt Group report and webinar describes how ransomware gangs leverage automation across their attack cycles. The Insikt Group identified ten key strategies, including selling breached credential databases on underground forums, checkers and brute-forcers for validating stolen credentials, loaders and crypters for evading antivirus, banking injects, exploit kits, spam and phishing services, bulletproof hosting services, sniffers, and automated marketplaces for selling stolen credentials and digital fingerprints. The post argues defenders should adopt intelligence-led automation to counter the speed and scale of automated criminal tooling.

Recorded Future · Aug 18, 2026Ransomware

Locky Ransomware Installed Through Nuclear EK

Unit 42 reports Locky ransomware delivered through the Nuclear exploit kit using Flash exploits, adding a drive-by path to existing malspam distribution.

Unit 42 observed Locky ransomware being delivered by the Nuclear exploit kit in March 2016 via Flash exploits, following February reports of Neutrino EK distributing Locky. Infections follow a drive-by chain through a gate to the Nuclear EK, which either installs Locky directly or drops a downloader that retrieves it from another domain. Locky retains two distribution paths: malspam with malicious Office macros or JavaScript attachments and exploit kit traffic triggered by casual web browsing.

Palo Alto Unit 42 · Aug 17, 2026Ransomware in the wild1