ZeroHour

Source: Infosecurity Magazine

3 stories in the last 24h

New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturingnew

Huntress details a new Settra ransomware variant deployed against retail and manufacturing victims since June, using MeshAgent RMM, recovery sabotage, and BYOVD techniques.

Huntress reported a new Settra ransomware variant, first observed in June, used in a July attack on a consumer services and retail organization and a September attack on a manufacturing firm. In the retail attack, MeshAgent RMM connected to attacker C2, the ransomware ran from C:\Perflogs, encrypted files with the .locked extension, and created a ransom note; the executable was named after the victim's domain in both incidents. Attackers cleared Windows Event Logs, disabled the Windows Recovery Environment, flushed DNS cache, used DiskPart to remove the recovery partition, and ran Cipher to overwrite free space. The September attack added BYOVD; prior research links Settra to double extortion, and initial access remains unconfirmed.

Infosecurity Magazineupdated · 20m agofirst · 35m agoRansomware in the wild 3 sources

Manufacturing Accounts for 22% of all Ransomware Victims

Black Kite finds manufacturing was the most ransomware-targeted sector for a fifth year, with incidents up roughly 40% and European victims growing 85.4%.

A Black Kite study reports manufacturing accounted for 22% of all ransomware victims from April 2025 to March 2026, the most-targeted sector for the fifth consecutive year. Disclosed manufacturing incidents rose from 847 to 1,183 between January 1 and July 29, 2026, with European victims up 85.4% (199 to 369) and Germany leading at 77. Researchers attribute European growth partly to SafePay's focus on German manufacturing, while Qilin (178 victims) and The Gentlemen (142) were the most active groups in early 2026. The 2025 Jaguar Land Rover attack, estimated to have cost the UK economy £1.9bn, illustrates the sector's financial exposure from downtime and IT-OT convergence.

Infosecurity Magazine · 6h agoRansomware in the wild 4 sources

FamousSparrow Swaps SparrowDoor For New SparroWocky Backdoor

China-aligned FamousSparrow deployed its new SparroWocky backdoor against Latin American governments since August 2025, initially accessing networks via exploited Exchange servers.

ESET attributes the SparroWocky campaign to FamousSparrow with high confidence, partly because early infections were delivered via the group's exclusive SparrowDoor implant. Since at least August 2025, the modular C++ backdoor was found at government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela, with 90% of the group's mid-2025 telemetry targets in the region. SparroWocky supports command execution, file execution, TCP proxying, host reconnaissance, screenshot capture, RC4-encrypted TLS exfiltration, and Cobalt Strike BOF loading, using runtime patching and call-stack forging for evasion. ESET links the regional focus to China's response to renewed US interest in Latin America and notes a possible, unclear link to Trend Micro's Earth Estries.

Infosecurity Magazineupdated · 18h agofirst · 23h agoThreat actor in the wild 9 sourcesCVE-2021-26855