Tag: ransomware operations
48 articles

Aurora Ransomware Operators Leverage AI Tool Cursor in Targeted Attacks
Aurora ransomware operators are using AI tool Cursor to plan and execute targeted attacks, even going so far as to instruct it in Russian to exclude certain regions and domains. This sophisticated approach has enabled the group to breach over 20 organizations across nine countries in just a few months.

Rockstar Games Leak Exposes Insider Threat Risks
The leak of Grand Theft Auto VI footage by CyberLeek has highlighted the devastating risks of insider threats, where stolen IP can destroy the hard work and livelihoods of employees and companies. This breach has exposed a gaping hole between traditional copyright enforcement and the evolving tactics of threat actors.

US Bank Probes LockBit Ransomware Claim, Faces Data Leak Deadline
US Bank is investigating a potential cybersecurity incident after LockBit ransomware crew claimed to have breached the institution and stolen sensitive data. The bank has assured that there's currently no indication of internal system impacts or unauthorized network access.

Ransomware Affiliate Exploits Fellow Extortionists with 'Recovery' Scam
In a shocking twist, a ransomware affiliate is turning the tables on its own gang by posing as a recovery service, offering victims a way out for a fraction of the original ransom demand. The scammer, operating under the guise of "Ransom Busters," claims to have infiltrated the ransomware gangs' infrastructure and recovered stolen data.

Clop Ransomware Operation Exploits Windchill Flaw with Custom Web Shell
The Clop ransomware operation has exploited a critical flaw in PTC Windchill and FlexPLM servers, deploying a custom web shell that allows for easy credential theft and massive data exfiltration. This sneaky move gives attackers a direct path to sensitive data, with no extra tools needed.

China APT Exploits VMware Flaw in Targeted Attacks
A recent investigation revealed that a suspected China-nexus APT group is actively exploiting a critical VMware vCenter vulnerability, CVE-2026-59310, to execute arbitrary code and deploy a backdoor, with ransomware seemingly used as a smokescreen to distract from the underlying intrusion. The attackers' true intentions appear to go beyond mere ransomware deployment.

Shell Probes Data Breach After Clop Ransomware Gang Claims Theft
Shell is investigating a potential data breach after the notorious Clop ransomware gang claimed to have stolen 89GB of sensitive information from the energy giant. The company is working closely with its security teams and experts to get to the bottom of the incident.

Akira Ransomware Affiliate Foiled by Evasion Tactic
Meet the Akira ransomware affiliate who got thwarted by a clever evasion tactic, but not before attempting to pull off a classic double extortion scam by stealing and leaking sensitive files. The attacker gained initial access through a vulnerable SonicWall SSL VPN, highlighting the importance of multifactor authentication.

Akira Ransomware Gang Foiled by Safe Mode Reboot
In a surprising twist, an Akira ransomware affiliate inadvertently sabotaged its own attack by rebooting a victim's system into Safe Mode, thwarting the mass-encryption step but not before exfiltrating sensitive credentials and files. This unexpected turn of events highlights the unpredictable nature of cyber attacks.

China-Linked Hackers Deploy StormEncryptor Ransomware via N-central Flaw
Meet StormEncryptor, a sneaky new ransomware strain linked to China that's leaving a trail of encrypted files and ransom notes in its wake. This malicious software, written in C++, is marked by its telltale .encrypted file extension and !!!README_FIRST!!!.txt ransom notes.

Medusa Affiliate Unveils StormEncryptor Ransomware
A former Medusa affiliate, now tracked as Storm-1175, has resurfaced with a new ransomware called StormEncryptor, marking a significant shift away from Medusa and a return to malicious activity after a months-long hiatus. This development signals a fresh threat in the cybersecurity landscape.

Ransomware gangs exploit SonicWall SMA1000 flaws
Ransomware gangs are actively exploiting two recently patched flaws in SonicWall's SMA1000 remote-access gateway, which can let attackers hijack vulnerable servers and send requests on their behalf. The vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, were patched in mid-July, but threat actors are now using them in real-world attacks.

Ransomware Gangs Target Mid-Level Managers to Accelerate Payments
Ransomware gangs are now taking a sniper approach, targeting mid-level managers with precision to get payments faster. This new tactic is a far cry from the scattergun methods of the past, with one recent campaign hitting 351 victims across 334 organizations in just a month.

INC Ransomware Exploits SonicWall Zero-Days Amid Rising Attacks
INC ransomware is rapidly exploiting recently patched SonicWall zero-days, with researchers warning of a surge in attacks. This ransomware-as-a-service operation is now the most active threat actor taking advantage of the vulnerability chain.

INC Ransomware Exploits SonicWall SMA 1000 Flaws in Global Campaign
INC Ransomware has rapidly become a major player in the cyber threat landscape, exploiting SonicWall SMA 1000 flaws to claim a staggering 885 victims worldwide as of August 2, 2026. The group's activity has surged since early August, with multiple victims listed on its data leak site.

Toy Ghouls Unveils GenieLocker Ransomware
Meet GenieLocker, the latest ransomware threat from the notorious Toy Ghouls group, which has been wreaking havoc on businesses since March 2026, with a particular focus on Russian industries. The attackers are using clever tactics, like infiltrating through OpenVPN connections, to gain access and spread their malicious reach.

Microsoft Teams Impersonation Attacks Deploy Chaos Ransomware
Cyber attackers are impersonating IT helpdesk staff on Microsoft Teams to trick employees into installing ransomware, with one financially motivated operation deploying Chaos ransomware in a matter of minutes. They use convincing voice calls and chats to gain remote access, often within just 2-3 minutes.

JadePuffer Targets AI Model Data with Custom Ransomware
Meet JadePuffer, a threat actor with a targeted vendetta against AI model data, deploying custom ransomware to hold machine learning infrastructure hostage. Their malicious tool of choice, EncForge, is a Go-based payload designed to exploit vulnerabilities like CVE-2025-3248 and wreak havoc on AI/ML stacks.

Ryuk Ransomware Operative Pleads Guilty in US Court
A major player behind the notorious Ryuk Ransomware gang has taken responsibility for their crimes, with Karen Serobovich Vardanyan, a 34-year-old Armenian national, pleading guilty in a US court to conspiracy and computer fraud. As part of his plea deal, Vardanyan will pay over $1.1m in restitution for his role in the massive cyberattack that netted over $15m in bitcoin payments.

Ryuk Ransomware Operative Pleads Guilty, Faces 15-Year Sentence
A 34-year-old Armenian man, Karen Serobovich Vardanyan, has pleaded guilty to masterminding a brazen ransomware scheme that raked in around $15 million by infiltrating hundreds of computer networks and deploying Ryuk ransomware. Vardanyan's guilty plea comes after his extradition from Ukraine, where he was arrested in April 2025.

AI-Powered Ransomware Targets Victims with Autonomous Attacks
Imagine a ransomware attack that can think and act on its own - that's what Sysdig researchers recently observed, as an AI agent autonomously carried out a complex extortion operation with alarming speed and efficiency. This groundbreaking case of agentic ransomware has raised the stakes for cybersecurity, combining AI-driven decision-making with human-like orchestration to wreak havoc in just 31 seconds.

Sysdig Exposes First Fully Agentic Ransomware Campaign
Meet JadePuffer, the groundbreaking ransomware campaign that's fully driven by a large language model (LLM) and can launch a devastating attack in as little as 31 seconds. This AI-powered threat uses an adaptive and automated approach to exploit vulnerabilities and extort its targets.

Avalon Malware Framework Targets Enterprise with CrownX Ransomware
Meet Avalon, a sneaky malware framework that's targeting enterprises with a potent ransomware punch, known as CrownX, and discover how it infiltrates systems through clever phishing tactics. This modular menace combines credential collection, lateral movement, and more into a single, reusable threat.

FortiBleed Exposes Link to Ransomware Ops
A shocking new report reveals that the notorious FortiBleed vulnerability has a direct link to ransomware operations, with a key player found negotiating with both groups. This alarming connection has led to at least 12 ransomware deployments and hundreds of encrypted endpoints.