Lemon Duck brings cryptocurrency miners back into the spotlightCisco Talos·Oct 13, 14:59 UTC · Oct 13, 2020Ransomware57
Iranian APT MuddyWater targets Turkish users via malicious PDFs, executablesCisco Talos·Jan 31, 13:00 UTC · Jan 31, 2022Ransomware57
Kaspersky discovers new Ymir ransomware used together with RustyStealerKaspersky Securelist·Nov 11, 10:00 UTC · Nov 11, 2024Ransomware157
Adaptive protection against invisible threatsKaspersky Securelist·Dec 14, 12:00 UTC · Dec 14, 2020Ransomware57
US, UK, New Zealand argue against disabling PowerShellThe Record·Jan 13, 00:00 UTC · Jan 13, 2023Ransomware57
What are script-based attacks and what can be done to prevent them?Help Net Security·Jul 31, 00:00 UTC · Jul 31, 2020RansomwareCVE-2017-0199CVE-2017-1188260
Uncovering Qilin attack methods exposed through multiple casesCisco Talos·Oct 27, 02:00 UTC · Oct 27, 2025Ransomware57
Twelve: from initial compromise to ransomware and wipersKaspersky Securelist·Sep 20, 13:33 UTC · Sep 20, 2024RansomwareCVE-2021-21972CVE-2021-2200560
Vice Society leverages PrintNightmare in ransomware attacksCisco Talos·Aug 12, 22:33 UTC · Aug 12, 2021RansomwareCVE-2021-1675CVE-2021-3452760
New ExtraHop capabilities target malicious PowerShell use across enterprise environmentsHelp Net Security·Nov 5, 00:00 UTC · Nov 5, 2025Ransomware60
Vice Society is using custom PowerShell tool for data exfiltrationSecurity Affairs·Apr 17, 11:18 UTC · Apr 17, 2023Ransomware57
TROJ_POSHCODER A ransomware uses Windows PowerShell featuresSecurity Affairs·Nov 14, 23:12 UTC · Nov 14, 2017Ransomware57
Head Mare and Twelve: Joint attacks on Russian entitiesKaspersky Securelist·Mar 13, 10:07 UTC · Mar 13, 2025RansomwareCVE-2023-38831CVE-2021-2685560
2 distinct campaigns delivered GandCrab ransomware and Ursnif TrojanSecurity Affairs·Jan 26, 08:29 UTC · Jan 26, 2019Ransomware57
GandCrab ransomware and Ursnif virus spreading via MS Word macrosThe Hacker News·Jan 25, 11:29 UTC · Jan 25, 2019Ransomware57
New BYOVD loader behind DeadLock ransomware attackCisco Talos·Dec 9, 11:00 UTC · Dec 9, 2025RansomwareCVE-2024-5132460
BlueSky Ransomware: Fast Encryption via MultithreadingPalo Alto Unit 42·Jun 5, 20:05 UTC · Jun 5, 2024RansomwareCVE-2020-0796CVE-2021-173260
PowerWare Ransomware Spoofing Locky Malware FamilyPalo Alto Unit 42·Jan 28, 21:51 UTC · Jan 28, 2022Ransomware57
Case Study: Incident Response is a relationshipCisco Talos·May 17, 12:00 UTC · May 17, 2021Ransomware60
OlympicDestroyer is here to trick the industryKaspersky Securelist·Mar 8, 17:00 UTC · Mar 8, 2018Ransomware57
The Gentlemen RaaS: rapid growth and a new ransomware variantKaspersky Securelist·Jun 30, 10:06 UTC · Jun 30, 2026Ransomware160
Storm-0249 Escalates Ransomware Attacks with ClickFix, Fileless PowerShell, and DLL SideloadingThe Hacker News·Dec 9, 13:37 UTC · Dec 9, 2025Ransomware157
Talos IR ransomware engagements and the significance of timeliness in incident responseCisco Talos·Jul 16, 10:00 UTC · Jul 16, 2025RansomwareCVE-2024-57727160
Vice Society Ransomware Using Stealthy PowerShell Tool for Data ExfiltrationThe Hacker News·Apr 17, 08:01 UTC · Apr 17, 2023Ransomware57
Quarterly Report: Incident Response trends in Q1 2022Cisco Talos·Apr 26, 13:11 UTC · Apr 26, 2022Ransomware in the wildCVE-2021-44228CVE-2021-45046CVE-2021-22204+1 CVEs60
Iranian linked conglomerate MuddyWater comprised of regionally focused subgroupsCisco Talos·Mar 10, 13:02 UTC · Mar 10, 2022Ransomware57
Microsoft Exchange vulnerabilities exploited once again for ransomware, this time with BabukCisco Talos·Nov 3, 12:00 UTC · Nov 3, 2021RansomwareCVE-2021-3694260
In Q2 2020, there was an average of 419 new threats per minuteHelp Net Security·Nov 6, 00:00 UTC · Nov 6, 2020Ransomware60
Attacker Uses Suspected AI-Generated PowerShell Script to Map Active DirectoryThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Ransomware160
Cybercriminals camouflaging threats as AI tool installersCisco Talos·May 29, 10:00 UTC · May 29, 2025Ransomware57
North Korean Hackers Exploit PowerShell Trick to Hijack Devices in New CyberattackThe Hacker News·Feb 12, 13:50 UTC · Feb 12, 2025Ransomware45
Unwrapping the emerging Interlock ransomware attackCisco Talos·Nov 7, 11:00 UTC · Nov 7, 2024Ransomware57
Analyzing the familiar tools used by the Crypt Ghouls hacktivistsKaspersky Securelist·Oct 18, 10:00 UTC · Oct 18, 2024Ransomware57
Avos ransomware group expands with new attack arsenalCisco Talos·Jun 21, 11:58 UTC · Jun 21, 2022RansomwareCVE-2021-44228CVE-2021-45046CVE-2021-45105+1 CVEs60
New Epsilon Red Ransomware appears in the threat landscapeSecurity Affairs·Jun 1, 19:26 UTC · Jun 1, 2021Ransomware57