Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channelCisco Talos·Jul 23, 10:00 UTC · Jul 23, 2026Ransomware57
Additional Entities Targeted by DarkSide Affiliate, TAG-21; Links to WellMess and Sliver InfrastructureRecorded Future·Jul 15, 00:00 UTC · Jul 15, 2025Ransomware57
Mespinoza Ransomware Gang Calls Victims “Partners,” Attacks with Gasket, "MagicSocks" ToolsPalo Alto Unit 42·Jun 6, 12:21 UTC · Jun 6, 2024Ransomware57
Attackers use domain fronting technique to target Myanmar with Cobalt StrikeCisco Talos·Nov 16, 12:00 UTC · Nov 16, 2021Ransomware57
Andariel evolves to target South Korea with ransomwareKaspersky Securelist·Jun 15, 12:40 UTC · Jun 15, 2021Ransomware57
Xbash Combines Botnet, Ransomware, Coinmining in Worm that Targets Linux and WindowsPalo Alto Unit 42·Mar 24, 08:51 UTC · Mar 24, 2022Ransomware57
Iranian linked conglomerate MuddyWater comprised of regionally focused subgroupsCisco Talos·Mar 10, 13:02 UTC · Mar 10, 2022Ransomware57
Head Mare hacktivists: attacks on companies in Russia and BelarusKaspersky Securelist·Sep 2, 10:00 UTC · Sep 2, 2024RansomwareCVE-2023-3883160
GhostSec’s joint ransomware operation and evolution of their arsenalCisco Talos·Mar 5, 13:00 UTC · Mar 5, 2024Ransomware60
Modified Zyklon and plugins from IndiaCisco Talos·May 23, 13:05 UTC · May 23, 2017RansomwareCVE-2013-3906CVE-2012-185660
Introducing ToyMaker, an initial access broker working in cahoots with double extortion gangsCisco Talos·Apr 23, 10:00 UTC · Apr 23, 2025Ransomware60
IT threat evolution Q3 2022Kaspersky Securelist·Nov 18, 08:00 UTC · Nov 18, 2022RansomwareCVE-2017-1027160
Sowing Discord: Reaping the benefits of collaboration app abuseCisco Talos·Apr 7, 12:06 UTC · Apr 7, 2021Ransomware157
Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went OfflineThe Hacker News·Jun 17, 16:00 UTC · Jun 17, 2026Ransomware57
TrickBot Linux Variants Active in the Wild Despite Recent TakedownThe Hacker News·Oct 29, 05:07 UTC · Oct 29, 2020Ransomware60
Matrix Push C2 Uses Browser Notifications for Fileless, CrossThe Hacker News·Dec 9, 08:03 UTC · Dec 9, 2025RansomwareCVE-2025-5928760
Analysis of Cuba ransomware gang activity and toolingKaspersky Securelist·Sep 11, 10:00 UTC · Sep 11, 2023RansomwareCVE-2021-31207CVE-2021-34473CVE-2021-34523+8 CVEs60
Kaspersky Q4 2021 DDoS attack reportKaspersky Securelist·Feb 10, 10:00 UTC · Feb 10, 2022RansomwareCVE-2017-6079CVE-2021-22205CVE-2021-3626060
SQUIRRELWAFFLE Leverages malspam to deliver Qakbot, Cobalt StrikeCisco Talos·Oct 26, 12:00 UTC · Oct 26, 2021Ransomware45
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and EdgeThe Hacker News·Jul 23, 13:11 UTC · Jul 23, 2026Ransomware57
Adversary Infrastructure Report 2020: A Defender’s ViewRecorded Future·Jan 2, 00:00 UTC · Jan 2, 2026Ransomware57
New eCh0raix Ransomware Variant Targets QNAP and Synology NetworkPalo Alto Unit 42·Jun 6, 12:17 UTC · Jun 6, 2024RansomwareCVE-2021-28799160
Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser processHelp Net Security·Jul 23, 00:00 UTC · Jul 23, 2026Ransomware57
Researchers Uncover ~200 Unique C2 Domains Linked to Raspberry Robin Access BrokerThe Hacker News·Mar 26, 04:30 UTC · Mar 26, 2025Ransomware57
ToolShell under siege: Check Point analyzes Chinese APT StormSecurity Affairs·Aug 1, 11:19 UTC · Aug 1, 2025Ransomware57
The Cyclops Blink botnet has been disruptedHelp Net Security·Jan 10, 13:54 UTC · Jan 10, 2024Ransomware45
Trickbot uses compromised MikroTik routers as C2 communication proxiesHelp Net Security·Mar 17, 00:00 UTC · Mar 17, 2022RansomwareCVE-2018-1484760
Iranian APT MuddyWater targets Turkish users via malicious PDFs, executablesCisco Talos·Jan 31, 13:00 UTC · Jan 31, 2022Ransomware57
New OS X Ransomware KeRanger Infected Transmission BitTorrent Client InstallerPalo Alto Unit 42·Jan 28, 22:01 UTC · Jan 28, 2022Ransomware57