Mespinoza Ransomware Gang Calls Victims “Partners,” Attacks with Gasket, "MagicSocks" ToolsPalo Alto Unit 42·Jun 6, 12:21 UTC · Jun 6, 2024Ransomware57
Cyber Criminals Exploit Open-Source Tools to Compromise Financial Institutions Across AfricaThe Hacker News·Jun 26, 08:08 UTC · Jun 26, 2025Ransomware57
Lorenz Ransomware Exploit Mitel VoIP Systems to Breach Business NetworksThe Hacker News·Sep 15, 00:00 UTC · Sep 15, 2022RansomwareCVE-2022-2949960
Spirals ransomware locks down victim systems in under 24 hoursHelp Net Security·Jul 17, 00:00 UTC · Jul 17, 2026Ransomware57
STAC6565 Targets Canada in 80% of Attacks as Gold Blade Deploys QWCrypt RansomwareThe Hacker News·Dec 9, 11:03 UTC · Dec 9, 2025Ransomware57
Russian Hackers Target Ukrainian Organizations Using Stealthy Living-Off-theThe Hacker News·Oct 30, 09:41 UTC · Oct 30, 2025RansomwareCVE-2025-808860
Anthropic Disrupts AI-Powered Cyberattacks Automating Theft and Extortion Across Critical SectorsThe Hacker News·Aug 27, 16:41 UTC · Aug 27, 2025Ransomware60
Law enforcement operations seized BlackSuit ransomware gang’s darknet sitesSecurity Affairs·Jul 26, 13:48 UTC · Jul 26, 2025Ransomware60
Hacktivist Group Twelve Targets Russian Entities with Destructive Cyber AttacksThe Hacker News·Oct 19, 07:30 UTC · Oct 19, 2024RansomwareCVE-2021-21972CVE-2021-2200560
Andariel Hacking Group Shifts Focus to Financial Attacks on U.S. OrganizationsThe Hacker News·Oct 2, 10:30 UTC · Oct 2, 2024Ransomware57
Analysis of the BlackJack group: techniques, tools, and similarities with TwelveKaspersky Securelist·Sep 25, 10:00 UTC · Sep 25, 2024Ransomware57
Hacktivist group Twelve is back and targets Russian entitiesSecurity Affairs·Sep 23, 05:18 UTC · Sep 23, 2024RansomwareCVE-2021-21972CVE-2021-2200560
Twelve: from initial compromise to ransomware and wipersKaspersky Securelist·Sep 20, 13:33 UTC · Sep 20, 2024RansomwareCVE-2021-21972CVE-2021-2200560
FBI and CISA update a joint advisory on the BlackSuit Ransomware groupSecurity Affairs·Aug 8, 08:39 UTC · Aug 8, 2024Ransomware60
OmniVision disclosed a data breach after the 2023 Cactus ransomware attackSecurity Affairs·May 22, 07:40 UTC · May 22, 2024Ransomware57
Why Apple added protection against quantum computing when quantum computing doesn’t even exist yetCisco Talos·Feb 29, 19:00 UTC · Feb 29, 2024Ransomware57
Cactus ransomware gang claims the theft of 1.5TB of data from Energy management and industrial automation firm Schneider ElectricSecurity Affairs·Feb 20, 07:01 UTC · Feb 20, 2024Ransomware57
Cactus ransomware gang claims the Schneider Electric hackSecurity Affairs·Jan 30, 08:00 UTC · Jan 30, 2024Ransomware57
Cactus RANSOMWARE gang hit the Swedish retail and grocery provider CoopSecurity Affairs·Jan 1, 12:35 UTC · Jan 1, 2024Ransomware57
Royal Ransomware Gang Demands $275m in a YearInfosecurity Magazine·Nov 14, 10:10 UTC · Nov 14, 2023Ransomware57
CISA, FBI warn that Royal ransomware gang may rebrand as ‘BlackSuit’The Record·Nov 14, 01:26 UTC · Nov 14, 2023Ransomware57
FBI, CISA Warn of Rising AvosLocker Ransomware Attacks Against Critical InfrastructureThe Hacker News·Oct 22, 03:10 UTC · Oct 22, 2023Ransomware60
FBI and CISA published a new advisory on AvosLocker ransomwareSecurity Affairs·Oct 13, 10:55 UTC · Oct 13, 2023Ransomware57
How Cyberattacks Are Transforming WarfareThe Hacker News·Sep 15, 00:00 UTC · Sep 15, 2023Ransomware60
New Ransomware Strain 'CACTUS' Exploits VPN Flaws to Infiltrate NetworksThe Hacker News·May 9, 14:05 UTC · May 9, 2023Ransomware57
New CACTUS ransomware appeared in the threat landscapeSecurity Affairs·May 9, 09:44 UTC · May 9, 2023Ransomware57
The U.S. CISA and FBI warn of Royal ransomware operationSecurity Affairs·Mar 3, 10:13 UTC · Mar 3, 2023Ransomware60
Ransomware Gang Hacks VoIP for Initial AccessInfosecurity Magazine·Sep 13, 10:55 UTC · Sep 13, 2022RansomwareCVE-2022-2949960
Hackers Exploit Mitel VoIP ZeroThe Hacker News·Jun 27, 05:55 UTC · Jun 27, 2022RansomwareCVE-2022-29499CVE-2022-29854CVE-2022-2985560
Attackers exploited a Mitel VOIP zeroSecurity Affairs·Jun 25, 11:59 UTC · Jun 25, 2022RansomwareCVE-2022-2949960
AvosLocker ransomware reboots in Safe Mode and installs tools for remote accessSecurity Affairs·Dec 23, 19:31 UTC · Dec 23, 2021Ransomware57
Iran-Linked Seedworm APT target orgs in the Middle EastSecurity Affairs·Dec 15, 10:56 UTC · Dec 15, 2021Ransomware57
ChaChi, a GoLang Trojan used in ransomware attacks on US schoolsSecurity Affairs·Jun 24, 13:13 UTC · Jun 24, 2021Ransomware57
Cobalt Iron's Cyber Shield locks down data access control, greatly reducing financial riskHelp Net Security·Sep 12, 00:00 UTC · Sep 12, 2019Ransomware57