Skip to main content

Malware & Ransomware

TA829 and UNK_GreenSec Collaborate on Strategies and Infrastructure in Ongoing Malware Operations

TA829 and UNK_GreenSec Collaborate on Strategies and Infrastructure in Ongoing Malware Operations

TA829 and UNK_GreenSec join forces to enhance strategies and infrastructure in ongoing malware operations, boosting cyber threat capabilities.

Analyst 207
Aeza Group Penalized for Operating Ransomware and Infostealer Servers

Aeza Group Penalized for Operating Ransomware and Infostealer Servers

Aeza Group faces penalties for running ransomware and infostealer servers, highlighting the growing crackdown on cybercrime operations.

Analyst 207
US Imposes Sanctions on Aeza Group for Facilitating Infostealers and Ransomware Activities

US Imposes Sanctions on Aeza Group for Facilitating Infostealers and Ransomware Activities

US sanctions Aeza Group for enabling infostealers and ransomware, targeting their role in cybercrime and enhancing national security efforts.

Analyst 207
Swiss Health Foundation Ransomware Attack Reveals Sensitive Government Information

Swiss Health Foundation Ransomware Attack Reveals Sensitive Government Information

Swiss Health Foundation ransomware attack exposes sensitive government data, raising concerns over cybersecurity and patient privacy.

Analyst 207
Ransomware Strikes Again: Another Billing Software Vendor Compromised

Ransomware Strikes Again: Another Billing Software Vendor Compromised

“Ransomware attacks escalate as a leading billing software vendor suffers a breach, compromising sensitive data and disrupting operations.”

Analyst 207
Scattered Spider’s Crime Wave Soars: Spotlight on the Aviation Industry

Scattered Spider’s Crime Wave Soars: Spotlight on the Aviation Industry

“Explore Scattered Spider’s escalating crime wave targeting the aviation industry, highlighting security risks and emerging threats in air travel.”

Analyst 207
Blind Eagle Exploits Proton66 Hosting for Phishing and RAT Attacks on Colombian Banks

Blind Eagle Exploits Proton66 Hosting for Phishing and RAT Attacks on Colombian Banks

Blind Eagle uses Proton66 hosting to execute phishing and RAT attacks targeting Colombian banks, compromising sensitive financial information.

Analyst 207
Ransomware Payments Persist: Nearly 50% Still Affected in 2025

Ransomware Payments Persist: Nearly 50% Still Affected in 2025

Ransomware payments remain a critical issue in 2025, with nearly 50% of organizations still impacted, highlighting ongoing cybersecurity challenges.

Analyst 207
GIFTEDCROOK Malware Transforms: From Browser Theft to Advanced Intelligence Gathering

GIFTEDCROOK Malware Transforms: From Browser Theft to Advanced Intelligence Gathering

Explore GIFTEDCROOK malware’s evolution from simple browser theft to sophisticated intelligence gathering, highlighting its growing threat landscape.

Analyst 207
Mustang Panda’s Tibet-Specific Attack: The Role of PUBLOAD and Pubshell Malware

Mustang Panda’s Tibet-Specific Attack: The Role of PUBLOAD and Pubshell Malware

Explore Mustang Panda’s targeted attacks in Tibet, focusing on PUBLOAD and Pubshell malware’s roles in cyber espionage and data theft.

Analyst 207
Silver Fox: Chinese Group Deploys Sainbox RAT and Hidden Rootkit via Fake Websites

Silver Fox: Chinese Group Deploys Sainbox RAT and Hidden Rootkit via Fake Websites

Chinese group Silver Fox uses fake websites to deploy Sainbox RAT and hidden rootkits, targeting unsuspecting users for cyber espionage.

Analyst 207
OneClik Malware Exploits Microsoft ClickOnce and Golang Backdoors to Attack Energy Sector

OneClik Malware Exploits Microsoft ClickOnce and Golang Backdoors to Attack Energy Sector

OneClik malware targets the energy sector by exploiting Microsoft ClickOnce and deploying Golang backdoors for advanced cyberattacks.

Analyst 207
Cryptohack Update: Malware Exploits Images to Compromise Wallets

Cryptohack Update: Malware Exploits Images to Compromise Wallets

Cryptohack Update reveals new malware that uses images to exploit and compromise cryptocurrency wallets, posing serious security threats to users.

Analyst 207
New FileFix Technique Raises Alarm After 517% Surge in ClickFix Attacks

New FileFix Technique Raises Alarm After 517% Surge in ClickFix Attacks

New FileFix technique raises concerns as ClickFix attacks surge by 517%, prompting urgent calls for enhanced cybersecurity measures.

Analyst 207
ClickFix Experiences 517% Surge in Attacks in 2025

ClickFix Experiences 517% Surge in Attacks in 2025

ClickFix reports a staggering 517% increase in attacks in 2025, highlighting urgent security concerns and the need for enhanced safety measures.

Analyst 207
Interpol Alerts on Surge of Cybercrime Across Africa

Interpol Alerts on Surge of Cybercrime Across Africa

Interpol warns of a rising wave of cybercrime in Africa, highlighting urgent need for enhanced security measures and international cooperation.

Analyst 207
Surge of ‘Fake Interviews’ Deploys 35 NPM Packages to Distribute Malware

Surge of ‘Fake Interviews’ Deploys 35 NPM Packages to Distribute Malware

“Discover how a surge in fake interviews is leveraging 35 NPM packages to distribute malware, posing risks to developers and users alike.”

Analyst 207
Cyber Assault: Open-Source Tools Target Financial Institutions in Africa

Cyber Assault: Open-Source Tools Target Financial Institutions in Africa

Explore how open-source tools are empowering cyber assaults on financial institutions in Africa, raising concerns about security and resilience.

Analyst 207
Ransomware Attacks Decrease in May Amid Ongoing Retail Threats

Ransomware Attacks Decrease in May Amid Ongoing Retail Threats

Ransomware attacks dropped in May, yet retail sectors remain vulnerable to ongoing cyber threats. Stay informed on the latest security trends.

Analyst 207
UK Ransom Payments Surge as Victims Lag Behind Global Counterparts

UK Ransom Payments Surge as Victims Lag Behind Global Counterparts

UK ransom payments soar as victims struggle to keep pace with global trends, highlighting increasing cybersecurity challenges and vulnerabilities.

Analyst 207
North Korea-Linked Cyberattack: 35 Malicious npm Packages Target Developers

North Korea-Linked Cyberattack: 35 Malicious npm Packages Target Developers

North Korea-linked cyberattack reveals 35 malicious npm packages targeting developers, posing serious security risks and undermining software integrity.

Analyst 207
Cybercriminals Exploit Signed ConnectWise Installers to Distribute Malware

Cybercriminals Exploit Signed ConnectWise Installers to Distribute Malware

Cybercriminals are exploiting signed ConnectWise installers to distribute malware, posing significant risks to businesses and IT systems.

Analyst 207
Rogue WordPress Plugin Exploits Malware Campaign to Steal Credit Card Information

Rogue WordPress Plugin Exploits Malware Campaign to Steal Credit Card Information

Rogue WordPress plugin exploits vulnerabilities to launch a malware campaign, targeting sites to steal credit card information from unsuspecting users.

Analyst 207
Four REvil Ransomware Criminals Avoid Harsh Sentences After Pleading Guilty

Four REvil Ransomware Criminals Avoid Harsh Sentences After Pleading Guilty

Four REvil ransomware criminals receive lenient sentences after pleading guilty, raising concerns over accountability in cybercrime enforcement.

Analyst 207