Blowing Cobalt Strike Out of the Water With Memory AnalysisPalo Alto Unit 42·Jun 5, 17:24 UTC · Jun 5, 2024Ransomware57
Sodin ransomware exploits Windows vulnerability and processor architectureKaspersky Securelist·Jul 3, 10:00 UTC · Jul 3, 2019RansomwareCVE-2018-845360
Dtrack expands its operations to Europe and Latin AmericaKaspersky Securelist·Nov 15, 10:00 UTC · Nov 15, 2022Ransomware57
Modified Zyklon and plugins from IndiaCisco Talos·May 23, 13:05 UTC · May 23, 2017RansomwareCVE-2013-3906CVE-2012-185660
FIN8 Group spotted delivering the BlackCat RansomwareSecurity Affairs·Jul 18, 19:45 UTC · Jul 18, 2023Ransomware57
Lemon Duck brings cryptocurrency miners back into the spotlightCisco Talos·Oct 13, 14:59 UTC · Oct 13, 2020Ransomware57
At least 3 different groups have been leveraging the NSA EternalBlue exploit, what's went wrong?Security Affairs·Aug 22, 08:11 UTC · Aug 22, 2017Ransomware57
Security leaders say the next two years are going to be 'insane'CyberScoop·Mar 27, 17:16 UTC · Mar 27, 2026Ransomware157
ThrottleStop driver abused to terminate AV processesKaspersky Securelist·Aug 6, 10:00 UTC · Aug 6, 2025RansomwareCVE-2025-777160
Exploring vulnerable Windows driversCisco Talos·Dec 19, 11:04 UTC · Dec 19, 2024RansomwareCVE-2022-369960
Researchers Discover "Bootkitty" – First UEFI Bootkit Targeting Linux KernelsThe Hacker News·Dec 2, 16:30 UTC · Dec 2, 2024RansomwareCVE-2023-4023860
A deep dive into Phobos ransomware, recently deployed by 8Base groupCisco Talos·Nov 17, 13:01 UTC · Nov 17, 2023Ransomware57
Kaspersky crimeware report: GoPIX, Lumar, and Rhysida.Kaspersky Securelist·Oct 24, 10:00 UTC · Oct 24, 2023Ransomware57
Andariel deploys DTrack and Maui ransomwareKaspersky Securelist·Aug 9, 14:25 UTC · Aug 9, 2022RansomwareCVE-2017-1027160
New Snort, ClamAV coverage strikes back against Cobalt StrikeCisco Talos·Sep 21, 04:01 UTC · Sep 21, 2020Ransomware157
FIN6 group starts using LockerGoga and Ryuk RansomwareSecurity Affairs·Apr 6, 19:56 UTC · Apr 6, 2019Ransomware57
A Dissection of the “EsteemAudit” Windows Remote Desktop ExploitPalo Alto Unit 42·May 31, 12:00 UTC · May 31, 2017RansomwareCVE-2017-907360
⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and MoreThe Hacker News·Jul 6, 13:02 UTC · Jul 6, 2026RansomwareCVE-2026-48276CVE-2026-48283CVE-2026-48277+69 CVEs160
The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security ProcessesThe Hacker News·Jun 23, 17:43 UTC · Jun 23, 2026Ransomware57
Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went OfflineThe Hacker News·Jun 17, 16:00 UTC · Jun 17, 2026Ransomware57
OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain IncidentThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026RansomwareCVE-2026-3363460
Fake Tech Support Spam Deploys Customized Havoc C2 Across OrganizationsThe Hacker News·Mar 3, 17:15 UTC · Mar 3, 2026Ransomware57
For the first time, a RomCom payload has been observed being distributed via SocGholish.Security Affairs·Nov 26, 20:16 UTC · Nov 26, 2025Ransomware57
Hackers Found Using CrossC2 to Expand Cobalt Strike Beacon’s Reach to Linux and macOSThe Hacker News·Aug 15, 00:00 UTC · Aug 15, 2025Ransomware57
Charon Ransomware targets Middle East with APT attack methodsSecurity Affairs·Aug 13, 08:43 UTC · Aug 13, 2025Ransomware57
Storm-2603 Exploits SharePoint Flaws to Deploy Warlock Ransomware on Unpatched SystemsThe Hacker News·Jul 28, 15:57 UTC · Jul 28, 2025Ransomware in the wildCVE-2025-49706CVE-2025-4970460
Iranian APT UNC1860 Linked to MOIS Facilitates Cyber Intrusions in Middle EastThe Hacker News·Sep 20, 12:44 UTC · Sep 20, 2024RansomwareCVE-2019-060460
Albabat, Kasseika, Kuiper: New Ransomware Gangs Rise with Rust and GolangThe Hacker News·Jan 30, 07:39 UTC · Jan 30, 2024Ransomware157
Hackers Weaponize Windows Flaw to Deploy CryptoThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2024RansomwareCVE-2023-3602560
Analysis of Cuba ransomware gang activity and toolingKaspersky Securelist·Sep 11, 10:00 UTC · Sep 11, 2023RansomwareCVE-2021-31207CVE-2021-34473CVE-2021-34523+8 CVEs60
UNRAVELING EternalBlue: inside the WannaCry’s enablerSecurity Affairs·Sep 1, 14:43 UTC · Sep 1, 2023Ransomware57
FIN8 Group Using Modified Sardonic Backdoor for BlackCat Ransomware AttacksThe Hacker News·Jul 19, 03:25 UTC · Jul 19, 2023Ransomware57
Quarterly Report: Incident Response Trends in Q1 2023Cisco Talos·Apr 26, 12:00 UTC · Apr 26, 2023Ransomware57