Attackers use domain fronting technique to target Myanmar with Cobalt StrikeCisco Talos·Nov 16, 12:00 UTC · Nov 16, 2021Ransomware57
Blowing Cobalt Strike Out of the Water With Memory AnalysisPalo Alto Unit 42·Jun 5, 17:24 UTC · Jun 5, 2024Ransomware57
Hackers Found Using CrossC2 to Expand Cobalt Strike Beacon’s Reach to Linux and macOSThe Hacker News·Aug 15, 00:00 UTC · Aug 15, 2025Ransomware57
Windows MSHTML 0-Day Exploited to Deploy Cobalt Strike Beacon in Targeted AttacksThe Hacker News·Nov 12, 15:17 UTC · Nov 12, 2021RansomwareCVE-2021-4044460
China-Linked Bronze Starlight Group Targeting Gambling Sector with Cobalt Strike BeaconsThe Hacker News·Jan 22, 08:28 UTC · Jan 22, 2025Ransomware57
Sabbath Ransomware target critical infrastructure in the US and CanadaSecurity Affairs·Dec 1, 07:29 UTC · Dec 1, 2021Ransomware60
SpearTip Finds New Diavol Ransomware Does Steal DataSecurity Affairs·Jul 15, 17:34 UTC · Jul 15, 2021Ransomware57
Mespinoza Ransomware Gang Calls Victims “Partners,” Attacks with Gasket, "MagicSocks" ToolsPalo Alto Unit 42·Jun 6, 12:21 UTC · Jun 6, 2024Ransomware57
China-linked APT Bronze Starlight deploys ransomware as a smokescreenSecurity Affairs·Jun 26, 13:40 UTC · Jun 26, 2022Ransomware57
Connecting the Bots - Hancitor fuels Cuba Ransomware OperationsSecurity Affairs·May 7, 09:59 UTC · May 7, 2021Ransomware57
⚡ Weekly Recap: Password Manager Flaws, Apple 0-Day, Hidden AI Prompts, In-theThe Hacker News·Aug 27, 05:11 UTC · Aug 27, 2025Ransomware in the wildCVE-2018-0171CVE-2025-43300CVE-2025-7353+5 CVEs60
DroxiDat-Cobalt Strike Duo Targets Power Generator NetworkInfosecurity Magazine·Aug 11, 17:00 UTC · Aug 11, 2023Ransomware60
Ransomware Group Rebrands Multiple Times to Evade DetectionInfosecurity Magazine·Nov 30, 10:20 UTC · Nov 30, 2021Ransomware57
JADEPUFFER: First End-to-End AISecurity Affairs·Jul 3, 11:29 UTC · Jul 3, 2026Ransomware in the wildCVE-2025-3248CVE-2021-2944160
Uncovering Qilin attack methods exposed through multiple casesCisco Talos·Oct 27, 02:00 UTC · Oct 27, 2025Ransomware57
Trojanized KeePass opens doors for ransomware attackersHelp Net Security·May 20, 00:00 UTC · May 20, 2025Ransomware57
Analysis of Cuba ransomware gang activity and toolingKaspersky Securelist·Sep 11, 10:00 UTC · Sep 11, 2023RansomwareCVE-2021-31207CVE-2021-34473CVE-2021-34523+8 CVEs60
Organizations are stepping up their game against cyber threatsHelp Net Security·Apr 24, 00:00 UTC · Apr 24, 2023Ransomware60
FireEye: More than 1,900 distinct hacking groups are active todayThe Record·Jan 26, 00:00 UTC · Jan 26, 2023Ransomware57
Log4Shell attacks began two weeks ago, Cisco and Cloudflare sayThe Record·Jan 18, 00:00 UTC · Jan 18, 2023Ransomware in the wild60
State-Backed Hackers Using Ransomware as a Decoy for Cyber Espionage AttacksThe Hacker News·Jun 25, 04:04 UTC · Jun 25, 2022Ransomware57
Conti Group Encrypts Karma Ransomware Extortion NotesInfosecurity Magazine·Mar 1, 09:59 UTC · Mar 1, 2022Ransomware57
Ransomware Group FIN12 Aggressively Going After Healthcare TargetsThe Hacker News·Oct 11, 07:09 UTC · Oct 11, 2021Ransomware60
UNC2447 gang exploited SonicWall ZeroSecurity Affairs·Apr 30, 16:26 UTC · Apr 30, 2021RansomwareCVE-2021-2001660
A Multi-Method Approach to Identifying Rogue Cobalt Strike ServersRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Ransomware57
Malicious use of Cobalt Strike down 80% after crackdown, Fortra saysThe Record·Mar 7, 19:06 UTC · Mar 7, 2025Ransomware57
Black Basta ransomware gang linked to a malware campaignSecurity Affairs·Aug 15, 08:40 UTC · Aug 15, 2024RansomwareCVE-2022-2692360
Global Police Operation Shuts Down 600 Cybercrime Servers Linked to Cobalt StrikeThe Hacker News·Jul 7, 16:50 UTC · Jul 7, 2024Ransomware57
Cobalt Strike: International law enforcement operation tackles illegal uses of ‘Swiss army knife’ pentesting toolThe Record·Jul 3, 15:25 UTC · Jul 3, 2024Ransomware57
TeamCity Flaw Leads to Surge in Ransomware, Cryptomining, and RAT AttacksThe Hacker News·Mar 21, 03:22 UTC · Mar 21, 2024RansomwareCVE-2024-2719860
City of Dallas has set a budget of $8.5 million to mitigate the May Royal ransomware attack.Security Affairs·Sep 23, 10:17 UTC · Sep 23, 2023Ransomware60
Power Generator in South Africa hit with DroxiDat and Cobalt StrikeSecurity Affairs·Aug 12, 06:57 UTC · Aug 12, 2023Ransomware60
CISA and FBI warn of Truebot infecting US and Canada based orgsSecurity Affairs·Jul 7, 05:58 UTC · Jul 7, 2023RansomwareCVE-2022-3119960