ZeroHour

Search: “double-extortion”

3 stories in the last 7d

New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturingnew

Huntress details a new Settra ransomware variant deployed against retail and manufacturing victims since June, using MeshAgent RMM, recovery sabotage, and BYOVD techniques.

Huntress reported a new Settra ransomware variant, first observed in June, used in a July attack on a consumer services and retail organization and a September attack on a manufacturing firm. In the retail attack, MeshAgent RMM connected to attacker C2, the ransomware ran from C:\Perflogs, encrypted files with the .locked extension, and created a ransom note; the executable was named after the victim's domain in both incidents. Attackers cleared Windows Event Logs, disabled the Windows Recovery Environment, flushed DNS cache, used DiskPart to remove the recovery partition, and ran Cipher to overwrite free space. The September attack added BYOVD; prior research links Settra to double extortion, and initial access remains unconfirmed.

Infosecurity Magazineupdated · 23m agofirst · 38m agoRansomware in the wild 3 sources

JADEPUFFER Evolves Agentic Ransomware to Target AI Models and Training Data

Sysdig links JADEPUFFER, an AI-driven ransomware actor, to ENCFORGE, a new locker encrypting and destroying AI models, training data, and vector databases.

Sysdig reports the agentic ransomware actor JADEPUFFER returned in July 2026 to a previously compromised Langflow environment with ENCFORGE, a locker targeting roughly 180 extensions for model checkpoints, vector databases, embedding indexes, and training data. Initial access used CVE-2025-3248 (CVSS 9.8), an unauthenticated RCE in Langflow versions before 1.3.0, added to CISA's KEV catalog in May 2025 after active exploitation. The actor searched hosts for LLM-provider API keys and cloud credentials, encrypted and deleted data, and left a ransom demand, favoring destruction over double extortion. Sysdig estimates rebuilding a destroyed model costs $75,000-$500,000 and observed the agent correcting failed actions in about 31 seconds.

GBHackersupdated · 44m agofirst · 1h agoRansomware in the wild 2 sourcesCVE-2025-3248

Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use

Cisco Talos reports 90 ransomware incidents hit Japanese organizations in H1 2026, led by The Gentlemen, with Qilin using AI for efficiency.

Cisco Talos observed 90 ransomware incidents against Japanese organizations from January to July 2026, up about 4.7% year over year, with manufacturing accounting for 34% of victims. The Gentlemen was the most active group with 14 incidents; its leak-site listings grew from 48 in January to 105 in July. Qilin and SafePay followed with seven incidents each, and Talos notes Qilin is leveraging AI to improve operational efficiency.

Cisco Talosupdated · 6h agofirst · 1d agoRansomware in the wild 4 sources1