Skip to main content

Tag: ransomware operations

48 articles

Person typing on laptop in modern office workspace surrounded by papers and notes.

Aurora Ransomware Operators Leverage AI Tool Cursor in Targeted Attacks

Aurora ransomware operators are using AI tool Cursor to plan and execute targeted attacks, even going so far as to instruct it in Russian to exclude certain regions and domains. This sophisticated approach has enabled the group to breach over 20 organizations across nine countries in just a few months.

Analyst 207
Empty office with computer and papers, blurred cityscape behind.

Rockstar Games Leak Exposes Insider Threat Risks

The leak of Grand Theft Auto VI footage by CyberLeek has highlighted the devastating risks of insider threats, where stolen IP can destroy the hard work and livelihoods of employees and companies. This breach has exposed a gaping hole between traditional copyright enforcement and the evolving tactics of threat actors.

Analyst 207
Bank lobby with blurred employee in background, flooded with natural daylight through large window or glass door.

US Bank Probes LockBit Ransomware Claim, Faces Data Leak Deadline

US Bank is investigating a potential cybersecurity incident after LockBit ransomware crew claimed to have breached the institution and stolen sensitive data. The bank has assured that there's currently no indication of internal system impacts or unauthorized network access.

Analyst 207
Dimly lit, cluttered office with scattered equipment and a lone chair in front of a computer screen.

Ransomware Affiliate Exploits Fellow Extortionists with 'Recovery' Scam

In a shocking twist, a ransomware affiliate is turning the tables on its own gang by posing as a recovery service, offering victims a way out for a fraction of the original ransom demand. The scammer, operating under the guise of "Ransom Busters," claims to have infiltrated the ransomware gangs' infrastructure and recovered stolen data.

Analyst 207
Brightly-lit industrial control system terminal on a rack in a factory setting.

Clop Ransomware Operation Exploits Windchill Flaw with Custom Web Shell

The Clop ransomware operation has exploited a critical flaw in PTC Windchill and FlexPLM servers, deploying a custom web shell that allows for easy credential theft and massive data exfiltration. This sneaky move gives attackers a direct path to sensitive data, with no extra tools needed.

Analyst 207
Server room interior with technicians in background and highlighted server components.

China APT Exploits VMware Flaw in Targeted Attacks

A recent investigation revealed that a suspected China-nexus APT group is actively exploiting a critical VMware vCenter vulnerability, CVE-2026-59310, to execute arbitrary code and deploy a backdoor, with ransomware seemingly used as a smokescreen to distract from the underlying intrusion. The attackers' true intentions appear to go beyond mere ransomware deployment.

Analyst 207
Modern office building exterior with subtle tech features and Shell fuel station.

Shell Probes Data Breach After Clop Ransomware Gang Claims Theft

Shell is investigating a potential data breach after the notorious Clop ransomware gang claimed to have stolen 89GB of sensitive information from the energy giant. The company is working closely with its security teams and experts to get to the bottom of the incident.

Analyst 207
Dimly lit server room with computer equipment and a security camera.

Akira Ransomware Affiliate Foiled by Evasion Tactic

Meet the Akira ransomware affiliate who got thwarted by a clever evasion tactic, but not before attempting to pull off a classic double extortion scam by stealing and leaking sensitive files. The attacker gained initial access through a vulnerable SonicWall SSL VPN, highlighting the importance of multifactor authentication.

Analyst 207
Cluttered office desk with laptop showing Windows login or blue screen, surrounded by papers and supplies near a window.

Akira Ransomware Gang Foiled by Safe Mode Reboot

In a surprising twist, an Akira ransomware affiliate inadvertently sabotaged its own attack by rebooting a victim's system into Safe Mode, thwarting the mass-encryption step but not before exfiltrating sensitive credentials and files. This unexpected turn of events highlights the unpredictable nature of cyber attacks.

Analyst 207
A typical office setting with computers and a blurred server room door in the foreground.

China-Linked Hackers Deploy StormEncryptor Ransomware via N-central Flaw

Meet StormEncryptor, a sneaky new ransomware strain linked to China that's leaving a trail of encrypted files and ransom notes in its wake. This malicious software, written in C++, is marked by its telltale .encrypted file extension and !!!README_FIRST!!!.txt ransom notes.

Analyst 207
Empty corporate office with computer workstations and daylight through tall windows.

Medusa Affiliate Unveils StormEncryptor Ransomware

A former Medusa affiliate, now tracked as Storm-1175, has resurfaced with a new ransomware called StormEncryptor, marking a significant shift away from Medusa and a return to malicious activity after a months-long hiatus. This development signals a fresh threat in the cybersecurity landscape.

Analyst 207
Rack-mounted networking equipment, including a remote-access gateway device, in a well-lit IT room with a blurred…

Ransomware gangs exploit SonicWall SMA1000 flaws

Ransomware gangs are actively exploiting two recently patched flaws in SonicWall's SMA1000 remote-access gateway, which can let attackers hijack vulnerable servers and send requests on their behalf. The vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, were patched in mid-July, but threat actors are now using them in real-world attacks.

Analyst 207
Mid-level manager looks concerned while gazing at laptop screen in office setting.

Ransomware Gangs Target Mid-Level Managers to Accelerate Payments

Ransomware gangs are now taking a sniper approach, targeting mid-level managers with precision to get payments faster. This new tactic is a far cry from the scattergun methods of the past, with one recent campaign hitting 351 victims across 334 organizations in just a month.

Analyst 207
Network equipment racks with a SonicWall device in a well-lit office IT room.

INC Ransomware Exploits SonicWall Zero-Days Amid Rising Attacks

INC ransomware is rapidly exploiting recently patched SonicWall zero-days, with researchers warning of a surge in attacks. This ransomware-as-a-service operation is now the most active threat actor taking advantage of the vulnerability chain.

Analyst 207
SonicWall SMA 1000 series appliance in an office setting with network closet door ajar.

INC Ransomware Exploits SonicWall SMA 1000 Flaws in Global Campaign

INC Ransomware has rapidly become a major player in the cyber threat landscape, exploiting SonicWall SMA 1000 flaws to claim a staggering 885 victims worldwide as of August 2, 2026. The group's activity has surged since early August, with multiple victims listed on its data leak site.

Analyst 207
Industrial facility interior with equipment and computer workstations.

Toy Ghouls Unveils GenieLocker Ransomware

Meet GenieLocker, the latest ransomware threat from the notorious Toy Ghouls group, which has been wreaking havoc on businesses since March 2026, with a particular focus on Russian industries. The attackers are using clever tactics, like infiltrating through OpenVPN connections, to gain access and spread their malicious reach.

Analyst 207
Person sitting at desk looks concerned, holding phone with blurred screen, while blurred figure looms in background.

Microsoft Teams Impersonation Attacks Deploy Chaos Ransomware

Cyber attackers are impersonating IT helpdesk staff on Microsoft Teams to trick employees into installing ransomware, with one financially motivated operation deploying Chaos ransomware in a matter of minutes. They use convincing voice calls and chats to gain remote access, often within just 2-3 minutes.

Analyst 207
Rows of servers and storage units in a brightly-lit data center with cables and network equipment.

JadePuffer Targets AI Model Data with Custom Ransomware

Meet JadePuffer, a threat actor with a targeted vendetta against AI model data, deploying custom ransomware to hold machine learning infrastructure hostage. Their malicious tool of choice, EncForge, is a Go-based payload designed to exploit vulnerabilities like CVE-2025-3248 and wreak havoc on AI/ML stacks.

Analyst 207
Defendant Karen Serobovich Vardanyan sits somberly in a US federal courtroom.

Ryuk Ransomware Operative Pleads Guilty in US Court

A major player behind the notorious Ryuk Ransomware gang has taken responsibility for their crimes, with Karen Serobovich Vardanyan, a 34-year-old Armenian national, pleading guilty in a US court to conspiracy and computer fraud. As part of his plea deal, Vardanyan will pay over $1.1m in restitution for his role in the massive cyberattack that netted over $15m in bitcoin payments.

Analyst 207
Formal courthouse interior with documents and law enforcement items under daylight.

Ryuk Ransomware Operative Pleads Guilty, Faces 15-Year Sentence

A 34-year-old Armenian man, Karen Serobovich Vardanyan, has pleaded guilty to masterminding a brazen ransomware scheme that raked in around $15 million by infiltrating hundreds of computer networks and deploying Ryuk ransomware. Vardanyan's guilty plea comes after his extradition from Ukraine, where he was arrested in April 2025.

Analyst 207
Rows of computer servers and storage equipment in a modern data center.

AI-Powered Ransomware Targets Victims with Autonomous Attacks

Imagine a ransomware attack that can think and act on its own - that's what Sysdig researchers recently observed, as an AI agent autonomously carried out a complex extortion operation with alarming speed and efficiency. This groundbreaking case of agentic ransomware has raised the stakes for cybersecurity, combining AI-driven decision-making with human-like orchestration to wreak havoc in just 31 seconds.

Analyst 207
Blurred figure of a person works amidst server racks and monitors in a brightly-lit data center.

Sysdig Exposes First Fully Agentic Ransomware Campaign

Meet JadePuffer, the groundbreaking ransomware campaign that's fully driven by a large language model (LLM) and can launch a devastating attack in as little as 31 seconds. This AI-powered threat uses an adaptive and automated approach to exploit vulnerabilities and extort its targets.

Analyst 207
Office workers in background, with a computer workstation and file cabinet in sharp focus in the foreground.

Avalon Malware Framework Targets Enterprise with CrownX Ransomware

Meet Avalon, a sneaky malware framework that's targeting enterprises with a potent ransomware punch, known as CrownX, and discover how it infiltrates systems through clever phishing tactics. This modular menace combines credential collection, lateral movement, and more into a single, reusable threat.

Analyst 207
Network operations room with computer servers and equipment showing signs of affected infrastructure.

FortiBleed Exposes Link to Ransomware Ops

A shocking new report reveals that the notorious FortiBleed vulnerability has a direct link to ransomware operations, with a key player found negotiating with both groups. This alarming connection has led to at least 12 ransomware deployments and hundreds of encrypted endpoints.

Analyst 207