Attackers use domain fronting technique to target Myanmar with Cobalt StrikeCisco Talos·Nov 16, 12:00 UTC · Nov 16, 2021Ransomware57
Blowing Cobalt Strike Out of the Water With Memory AnalysisPalo Alto Unit 42·Jun 5, 17:24 UTC · Jun 5, 2024Ransomware57
Hackers Found Using CrossC2 to Expand Cobalt Strike Beacon’s Reach to Linux and macOSThe Hacker News·Aug 15, 00:00 UTC · Aug 15, 2025Ransomware57
China-Linked Bronze Starlight Group Targeting Gambling Sector with Cobalt Strike BeaconsThe Hacker News·Jan 22, 08:28 UTC · Jan 22, 2025Ransomware57
SpearTip Finds New Diavol Ransomware Does Steal DataSecurity Affairs·Jul 15, 17:34 UTC · Jul 15, 2021Ransomware57
Mespinoza Ransomware Gang Calls Victims “Partners,” Attacks with Gasket, "MagicSocks" ToolsPalo Alto Unit 42·Jun 6, 12:21 UTC · Jun 6, 2024Ransomware57
China-linked APT Bronze Starlight deploys ransomware as a smokescreenSecurity Affairs·Jun 26, 13:40 UTC · Jun 26, 2022Ransomware57
Connecting the Bots - Hancitor fuels Cuba Ransomware OperationsSecurity Affairs·May 7, 09:59 UTC · May 7, 2021Ransomware57
Ransomware Group Rebrands Multiple Times to Evade DetectionInfosecurity Magazine·Nov 30, 10:20 UTC · Nov 30, 2021Ransomware57
JADEPUFFER: First End-to-End AISecurity Affairs·Jul 3, 11:29 UTC · Jul 3, 2026Ransomware in the wildCVE-2025-3248CVE-2021-2944160
Uncovering Qilin attack methods exposed through multiple casesCisco Talos·Oct 27, 02:00 UTC · Oct 27, 2025Ransomware57
Trojanized KeePass opens doors for ransomware attackersHelp Net Security·May 20, 00:00 UTC · May 20, 2025Ransomware57
Analysis of Cuba ransomware gang activity and toolingKaspersky Securelist·Sep 11, 10:00 UTC · Sep 11, 2023RansomwareCVE-2021-31207CVE-2021-34473CVE-2021-34523+8 CVEs60
FireEye: More than 1,900 distinct hacking groups are active todayThe Record·Jan 26, 00:00 UTC · Jan 26, 2023Ransomware57
State-Backed Hackers Using Ransomware as a Decoy for Cyber Espionage AttacksThe Hacker News·Jun 25, 04:04 UTC · Jun 25, 2022Ransomware57
Conti Group Encrypts Karma Ransomware Extortion NotesInfosecurity Magazine·Mar 1, 09:59 UTC · Mar 1, 2022Ransomware57
A Multi-Method Approach to Identifying Rogue Cobalt Strike ServersRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Ransomware57
Malicious use of Cobalt Strike down 80% after crackdown, Fortra saysThe Record·Mar 7, 19:06 UTC · Mar 7, 2025Ransomware57
Black Basta ransomware gang linked to a malware campaignSecurity Affairs·Aug 15, 08:40 UTC · Aug 15, 2024RansomwareCVE-2022-2692360
Global Police Operation Shuts Down 600 Cybercrime Servers Linked to Cobalt StrikeThe Hacker News·Jul 7, 16:50 UTC · Jul 7, 2024Ransomware57
Cobalt Strike: International law enforcement operation tackles illegal uses of ‘Swiss army knife’ pentesting toolThe Record·Jul 3, 15:25 UTC · Jul 3, 2024Ransomware57
Cyber Intrusion Detection Time at an AllInfosecurity Magazine·Apr 18, 14:00 UTC · Apr 18, 2023Ransomware57
State-of-the-art EDRs are not perfect, fail to detect common attacksThe Record·Jan 9, 00:00 UTC · Jan 9, 2023Ransomware57
Quarterly Report: Incident Response Trends in Q3 2022Cisco Talos·Oct 25, 12:00 UTC · Oct 25, 2022RansomwareCVE-2020-147260
Avos ransomware group expands with new attack arsenalCisco Talos·Jun 21, 11:58 UTC · Jun 21, 2022RansomwareCVE-2021-44228CVE-2021-45046CVE-2021-45105+1 CVEs60
Meteoric attack deploys Quantum ransomware in mere hoursHelp Net Security·Apr 26, 00:00 UTC · Apr 26, 2022Ransomware57
Dridex Malware Deploying Entropy Ransomware on Hacked ComputersThe Hacker News·Feb 25, 13:40 UTC · Feb 25, 2022Ransomware57
FIN12 ransomware gang don't implement double extortion to prioritize speedSecurity Affairs·Oct 7, 21:38 UTC · Oct 7, 2021Ransomware57
Conti ransomware gang also breached Ireland Department of Health (DoH)Security Affairs·May 19, 11:33 UTC · May 19, 2021Ransomware57
Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went OfflineThe Hacker News·Jun 17, 16:00 UTC · Jun 17, 2026Ransomware57
Attackers are bypassing MFA on SonicWall VPNs because something was wrong with previous fixSecurity Affairs·May 21, 14:29 UTC · May 21, 2026Ransomware in the wildCVE-2024-1280260
Google Attributes Axios npm Supply Chain Attack to North Korean Group UNC1069The Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Ransomware57
OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain IncidentThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026RansomwareCVE-2026-3363460
Google links Axios npm supply chain attack to North KoreaSecurity Affairs·Apr 1, 13:47 UTC · Apr 1, 2026Ransomware57
Hive0163 Uses AI-Assisted Slopoly Malware for Persistent Access in Ransomware AttacksThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2026Ransomware57