DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
Microsoft reports DeadLock ransomware using Polygon smart contracts and Session messaging for extortion infrastructure, claiming 96 victims across Europe and the U.S.
Microsoft Threat Intelligence reports the DeadLock ransomware operation uses the Session messaging network and Polygon blockchain smart contracts to host victim chat, proxy server addresses, and its data leak blog, making takedowns harder. First detected in July 2025, the group has claimed 96 victims, mostly in Italy, Spain, Poland, Türkiye, and the U.S., with deployments by affiliates of Lynx and INC ransomware. The encryptor uses Curve25519 with XChaCha20, drops an interactive HTML recovery chat application, geofences CIS-linked countries, and clears logs and shadow copies to evade forensics.
Panzer Ransomware Targets Italian Manufacturers and Telecom Firms With ESXi-Ready RaaS
New Panzer ransomware-as-a-service operation lists Italian firms Doimo Cucine and NTE Italia as victims, offering encryptors for Windows, Linux, FreeBSD, and ESXi.
Panzer, a ransomware-as-a-service operation that surfaced August 5, listed a kitchen manufacturer in Treviso (Doimo Cucine) and a telecommunications engineering firm in Catanzaro (NTE Italia) among alleged victims, claiming 30 GB and 16 GB of stolen data respectively. The group advertises encryptors for Windows, Linux, FreeBSD, and VMware ESXi, a Tox-based affiliate recruitment process with screening, an affiliate dashboard, and an 80/20 revenue split. Neither victim had publicly confirmed the incidents when researcher Andrea Fortuna's report was published, and the group's first access method and payload have not been independently analyzed. Panzer posted victims across 11 countries as claimed Italian ransomware incidents reached 212 by September 6, already above 2025's full-year total of 169.
New pro-Ukraine hacker group targets Russian companies with custom ransomware
F6 links new pro-Ukraine ransomware group VantaCore, likely a Thor rebrand, to seven attacks on Russian firms using custom tooling and multimillion-dollar demands.
Russian cybersecurity firm F6 reports that VantaCore, a ransomware group believed to be a rebrand of pro-Ukrainian group Thor, has targeted at least seven Russian organizations with ransom demands reaching millions of dollars, operating as a ransomware-as-a-service operation with a Tor-based victim chat and a leak site. The group uses custom-built tooling including the VantaCore ransomware that encrypts servers and workstations, VantaCoreLoader for distribution, the VantaCoreRAT backdoor, and SnowKiller, which disables antivirus and security software. Initial access relies on poorly secured VPNs and remote-access tools, flaws in internet-facing applications, and credentials stolen from business partners. F6 notes pro-Ukrainian groups increasingly abandoned stock ransomware like LockBit 3 Black and Babuk in 2025-2026 in favor of custom malware.
Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations
Researchers confirmed extortion group ExfilSquad holds stolen sensitive data from at least 13 organizations, publishing leaked datasets via torrents.
Security researchers verified that the extortion group ExfilSquad possesses sensitive data stolen from at least 13 victim organizations. The group distributed the leaked datasets publicly through torrents rather than a traditional leak site. Independent verification of the stolen data lends credibility to the group's extortion claims against its victims.
Ransomware Now Shows Up in Nearly Half of All Breaches: A Survival Playbook for Lean Security Teams
Cyble reports 5,967 ransomware attacks in 2025, up 50%, accounting for nearly half of all tracked breaches.
Cyble's Global Cybersecurity Report 2025 documented 5,967 ransomware attacks, a 50% year-over-year jump. Against 6,046 data breaches and leaks recorded in the same period, ransomware accounted for 49.7% of the combined total. The blog lays out an incident response playbook for lean security teams facing this dominant threat.
Harley-Davidson Alleged Breach – CL0P Ransomware Adds Motorcycle Maker to the List
CL0P ransomware group listed Harley-Davidson on its extortion leak site, claiming a compromise; the motorcycle maker has not confirmed any breach.
The CL0P ransomware operation added Harley-Davidson to its public extortion portal, a listing highlighted by the ransomNews monitoring account on September 10, 2026. Harley-Davidson has not confirmed any compromise, and the initial access method, affected business unit, timing, and volume of stolen data remain unknown, with no sample files or technical indicators published. The article stresses that leak-site listings alone do not confirm a breach and can serve as negotiation pressure in double-extortion schemes. If verified, stolen data could fuel downstream phishing, BEC, credential-stuffing, and invoice fraud targeting dealers, suppliers, and customers.