SystemBC Powers REM Proxy With 1,500 Daily VPS Victims Across 80 C2 ServersThe Hacker News·Sep 19, 14:26 UTC · Sep 19, 2025Ransomware60
Ransomware Attackers Using SystemBC Malware With RAT and Tor ProxyThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2020Ransomware in the wild60
SystemBC C2 Server Reveals 1,570+ Victims in The Gentlemen Ransomware OperationThe Hacker News·Apr 22, 05:42 UTC · Apr 22, 2026Ransomware57
Power Generator in South Africa hit with DroxiDat and Cobalt StrikeSecurity Affairs·Aug 12, 06:57 UTC · Aug 12, 2023Ransomware60
Black Basta ransomware gang linked to a malware campaignSecurity Affairs·Aug 15, 08:40 UTC · Aug 15, 2024RansomwareCVE-2022-2692360
The Gentlemen Ransomware Expands With Rapid Affiliate GrowthInfosecurity Magazine·Apr 21, 14:00 UTC · Apr 21, 2026Ransomware57
DroxiDat-Cobalt Strike Duo Targets Power Generator NetworkInfosecurity Magazine·Aug 11, 17:00 UTC · Aug 11, 2023Ransomware60
VMware ESXi Flaw Exploited by Ransomware Groups for Admin AccessThe Hacker News·Jul 31, 04:04 UTC · Jul 31, 2024Ransomware in the wildCVE-2024-37085CVE-2023-2825260
Uncovering Qilin attack methods exposed through multiple casesCisco Talos·Oct 27, 02:00 UTC · Oct 27, 2025Ransomware57
Kaspersky discovers new Ymir ransomware used together with RustyStealerKaspersky Securelist·Nov 11, 10:00 UTC · Nov 11, 2024Ransomware157
New Report Exposes Vice Society's Collaboration with Rhysida RansomwareThe Hacker News·Aug 10, 03:41 UTC · Aug 10, 2023Ransomware57
An overview of ransomware threats in Japan in 2025 and early detection insights from Qilin casesCisco Talos·Apr 2, 10:00 UTC · Apr 2, 2026Ransomware60
AI-assisted Slopoly malware powers Hive0163’s ransomware campaignsSecurity Affairs·Mar 13, 11:36 UTC · Mar 13, 2026Ransomware60
Qilin Ransomware Combines Linux Payload With BYOVD Exploit in Hybrid AttackThe Hacker News·Oct 28, 03:54 UTC · Oct 28, 2025Ransomware57
Dark Covenant 3.0: Controlled Impunity and Russia’s CybercriminalsRecorded Future·Oct 28, 00:00 UTC · Oct 28, 2025Ransomware57
⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & MoreThe Hacker News·Oct 6, 11:38 UTC · Oct 6, 2025RansomwareCVE-2025-61882CVE-2025-27915CVE-2025-4008+16 CVEs60
Security Affairs newsletter Round 542 by Pierluigi PaganiniSecurity Affairs·Sep 21, 15:44 UTC · Sep 21, 2025RansomwareCVE-2020-9273CVE-2025-1058560
Hackers Found Using CrossC2 to Expand Cobalt Strike Beacon’s Reach to Linux and macOSThe Hacker News·Aug 15, 00:00 UTC · Aug 15, 2025Ransomware57
Play ransomware group hit 900 organizations since 2022Security Affairs·Jun 6, 07:22 UTC · Jun 6, 2025RansomwareCVE-2024-5772760
Dutch Police Lead Shut Down of Counter AV Service AVCheckInfosecurity Magazine·Jun 2, 10:00 UTC · Jun 2, 2025Ransomware57
Law Enforcement Busts Initial Access Malware Used to Launch RansomwareInfosecurity Magazine·May 23, 11:30 UTC · May 23, 2025Ransomware57
Inside DragonForce, the Group Tied to M&S, CoInfosecurity Magazine·May 6, 13:25 UTC · May 6, 2025Ransomware60
RansomHub affiliate leverages multi-function Betruger backdoorHelp Net Security·Apr 2, 08:48 UTC · Apr 2, 2025RansomwareCVE-2022-24521CVE-2023-2753260
RansomHub affiliate uses custom backdoor BetrugerSecurity Affairs·Mar 21, 11:25 UTC · Mar 21, 2025RansomwareCVE-2022-24521CVE-2023-2753260
How the Shadowserver Foundation helps network defenders with free intelligence feedsHelp Net Security·Dec 5, 00:00 UTC · Dec 5, 2024Ransomware60
New Ymir Ransomware Exploits Memory for Stealthy Attacks; Targets Corporate NetworksThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2024RansomwareCVE-2024-4076660
Ymir ransomware, a new stealthy ransomware grow in the wildSecurity Affairs·Nov 12, 10:26 UTC · Nov 12, 2024Ransomware60
Microsoft Identifies Storm-0501 as Major Threat in Hybrid Cloud Ransomware AttacksThe Hacker News·Sep 28, 05:55 UTC · Sep 28, 2024Ransomware57
Modified LockBit and Conti ransomware shows up in DragonForce gang’s attacksThe Record·Sep 25, 15:11 UTC · Sep 25, 2024Ransomware57
FBI and CISA Warn of BlackSuit Ransomware That Demands Up to $500 MillionThe Hacker News·Aug 10, 14:19 UTC · Aug 10, 2024Ransomware60
Black Basta Ransomware May Have Exploited MS Windows ZeroThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2024Ransomware in the wildCVE-2024-2616960
Ukrainian Cyber Police Identify Suspected LockBit and Conti MemberInfosecurity Magazine·Jun 13, 10:15 UTC · Jun 13, 2024Ransomware57
Authorities Ramp Up Efforts to Capture the Mastermind Behind EmotetThe Hacker News·Jun 11, 06:07 UTC · Jun 11, 2024Ransomware57
The sliding doors of misinformation that come with AICisco Talos·Jun 6, 18:03 UTC · Jun 6, 2024Ransomware57
Vice Society: Profiling a Persistent Threat to the Education SectorPalo Alto Unit 42·Jun 5, 17:12 UTC · Jun 5, 2024RansomwareCVE-2021-3452760
Europol-Led Operation Endgame Hits Botnet, Ransomware NetworksInfosecurity Magazine·May 30, 17:15 UTC · May 30, 2024Ransomware57
Double-Extortion Play Ransomware Strikes 300 Organizations WorldwideThe Hacker News·Dec 19, 06:41 UTC · Dec 19, 2023RansomwareCVE-2022-41040CVE-2022-41082CVE-2018-13379+1 CVEs60
Analysis of Cuba ransomware gang activity and toolingKaspersky Securelist·Sep 11, 10:00 UTC · Sep 11, 2023RansomwareCVE-2021-31207CVE-2021-34473CVE-2021-34523+8 CVEs60