AmCache artifact: forensic value and a tool for data extractionKaspersky Securelist·Oct 1, 10:00 UTC · Oct 1, 2025Ransomware57
Everyday tools, extraordinary crimes: the ransomware exfiltration playbookCisco Talos·Mar 19, 10:00 UTC · Mar 19, 2026Ransomware57
ThrottleStop driver abused to terminate AV processesKaspersky Securelist·Aug 6, 10:00 UTC · Aug 6, 2025RansomwareCVE-2025-777160
Customizable Elpaco ransomware abuses the Everything libraryKaspersky Securelist·Nov 26, 10:00 UTC · Nov 26, 2024RansomwareCVE-2020-147260
Kaspersky discovers new Ymir ransomware used together with RustyStealerKaspersky Securelist·Nov 11, 10:00 UTC · Nov 11, 2024Ransomware157
Incident response statistics and cases at educational institutions in BrazilKaspersky Securelist·Aug 3, 13:00 UTC · Aug 3, 2026Ransomware57
Microsoft Takes Down Malware-Signing Service Behind Ransomware AttacksThe Hacker News·May 20, 14:36 UTC · May 20, 2026Ransomware57
Chinese and N. Korean Hackers Target Global Infrastructure with RansomwareThe Hacker News·Jun 28, 04:02 UTC · Jun 28, 2024Ransomware60
Blowing Cobalt Strike Out of the Water With Memory AnalysisPalo Alto Unit 42·Jun 5, 17:24 UTC · Jun 5, 2024Ransomware57
New Avalon Malware Framework Packs CrownX Ransomware CapabilitiesThe Hacker News·Jul 3, 18:55 UTC · Jul 3, 2026RansomwareCVE-2025-324860
How to Detect Cobalt Strike: An Inside Look at the Popular Commercial PostRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Ransomware57
2024 Sees Sharp Increase in Microsoft Tool ExploitsInfosecurity Magazine·Dec 13, 13:45 UTC · Dec 13, 2024Ransomware57
Cisco Talos shares insights related to recent cyber attack on CiscoCisco Talos·Aug 10, 19:30 UTC · Aug 10, 2022Ransomware60
Avos ransomware group expands with new attack arsenalCisco Talos·Jun 21, 11:58 UTC · Jun 21, 2022RansomwareCVE-2021-44228CVE-2021-45046CVE-2021-45105+1 CVEs60
Iranian APT MuddyWater targets Turkish users via malicious PDFs, executablesCisco Talos·Jan 31, 13:00 UTC · Jan 31, 2022Ransomware57
TA505 Cybercrime targets system integrator companiesSecurity Affairs·Nov 12, 13:50 UTC · Nov 12, 2019Ransomware57
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root AccessThe Hacker News·Jul 20, 16:44 UTC · Jul 20, 2026RansomwareCVE-2026-15409CVE-2026-1541060
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain CredentialsThe Hacker News·Jul 3, 14:36 UTC · Jul 3, 2026RansomwareCVE-2025-577760
FortiBleed Credential Theft Linked to INC and Lynx Ransomware OperationsThe Hacker News·Jul 2, 13:05 UTC · Jul 2, 2026RansomwareCVE-2026-3561660
AI-Generated Browser Ransomware Abuses Chromium API on Windows, Linux, macOS, AndroidThe Hacker News·Jul 2, 05:15 UTC · Jul 2, 2026RansomwareCVE-2023-486360
Attackers are handing off access in 22 seconds, Mandiant findsHelp Net Security·Jun 19, 12:06 UTC · Jun 19, 2026RansomwareCVE-2025-31324CVE-2025-61882CVE-2025-53770+1 CVEs60
Microsoft disrupts Fox Tempest malware-signing-as-a-service platform tied to ransomware gangsThe Record·May 19, 16:40 UTC · May 19, 2026Ransomware160
Interlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026The Hacker News·Mar 21, 07:03 UTC · Mar 21, 2026Ransomware in the wildCVE-2026-2013160
Uncovering Qilin attack methods exposed through multiple casesCisco Talos·Oct 27, 02:00 UTC · Oct 27, 2025Ransomware57
IR Trends Q3 2025: ToolShell attacks dominate, highlighting criticality of segmentation and rapid responseCisco Talos·Oct 23, 10:00 UTC · Oct 23, 2025Ransomware in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+1 CVEs160
New HybridPetya Ransomware Bypasses UEFI Secure Boot With CVE-2024The Hacker News·Sep 15, 00:00 UTC · Sep 15, 2025Ransomware57
Someone Created the First AI-Powered Ransomware Using OpenAI's gptThe Hacker News·Sep 5, 12:39 UTC · Sep 5, 2025Ransomware in the wild60
2024 Malicious Infrastructure Insights: Key Trends and ThreatsRecorded Future·Aug 20, 00:00 UTC · Aug 20, 2025Ransomware57
Storm-2603 Deploys DNS-Controlled Backdoor in Warlock and LockBit Ransomware AttacksThe Hacker News·Aug 6, 14:41 UTC · Aug 6, 2025RansomwareCVE-2025-49706CVE-2025-4970460
Head Mare and Twelve: Joint attacks on Russian entitiesKaspersky Securelist·Mar 13, 10:07 UTC · Mar 13, 2025RansomwareCVE-2023-38831CVE-2021-2685560
Analysis of the BlackJack group: techniques, tools, and similarities with TwelveKaspersky Securelist·Sep 25, 10:00 UTC · Sep 25, 2024Ransomware57
IntelOwl: Open-source threat intelligence managementHelp Net Security·Aug 14, 00:00 UTC · Aug 14, 2024Ransomware60
Chinese State Actors Use Ransomware to Conceal Real IntentInfosecurity Magazine·Jun 27, 09:30 UTC · Jun 27, 2024Ransomware60
20 Essential Open-Source Cybersecurity Tools That Save You TimeHelp Net Security·Mar 25, 00:00 UTC · Mar 25, 2024Ransomware45
8Base Group Deploying New Phobos Ransomware Variant via SmokeLoaderThe Hacker News·Nov 20, 06:05 UTC · Nov 20, 2023Ransomware57
The FBI's Cynthia Kaiser on how the bureau fights ransomwareCyberScoop·Jul 21, 19:07 UTC · Jul 21, 2023Ransomware60