-
A recent technical analysis of an Everest ransomware encryptor reveals a purpose-built, ConfuserEx-protected .NET 4.0 binary that combines heavy obfuscation, misleading cryptographic declarations, and uncommon network tactics to maximize impact and imp…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
TeamPCP’s wide-scale supply-chain compromises have materially fueled VECT ransomware operations by supplying a vast archive of stolen CI/CD credentials, reshaping how organizations should measure ransomware exposure. Rather than choosing victims in adv…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Gentlemen, a Go-based ransomware-as-a-service (RaaS) active since mid-2025, has distinguished itself with a potent combination of modern cryptography, aggressive worm-like propagation, and a broad toolkit for remote execution. Operators offer the platf…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A previously undocumented malware framework, tracked as Avalon, that uses a spoofed legal-document lure and a multi-stage, fileless-oriented chain to deliver a ransomware component internally labeled CrownX. The campaign demonstrates a shift toward con…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A new Sysdig report traces how an LLM agent abused a Langflow flaw, stole credentials, reached production MySQL, and destroyed Nacos config data in minutes flat.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The first instance of agentic ransomware: JADEPUFFER, an LLM-driven extortion operation that automated an end-to-end database-crippling campaign. The actor gained execution on an internet-facing Langflow instance via CVE-2025-3248, used the AI-host env…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A novel, practical ransomware technique that runs entirely inside the browser by abusing the File System Access API, demonstrating how AI can turn high-level malicious ideas into operational attack chains without any native payload. The proof-of-concep…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A direct operational link between the large-scale FortiBleed credential-harvesting campaign and two active ransomware-as-a-service (RaaS) groups: INC Ransom and Lynx. This finding provides the first confirmed evidence that mass theft of FortiGate crede…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Ransomware-proof backup planning helps IT teams protect clean data copies, isolate storage, test recovery, and keep operations running after cyber attacks fast.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Fake Interpol investigation emails are targeting small businesses with Proton Drive links that deliver ransomware, encrypt files, and route victims to Tox chat.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


