The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations…
Tag: ransomware
Q&A: Ransomware is now a ‘fully fledged industry’, says cybercrime journalist Geoff White
Cybercrime no longer divides neatly between lone hackers, organised gangs and state-backed operations. These groups exchange tactics and tools, while…
PLEASE_READ_ME: The Opportunistic Ransomware Devastating MySQL Servers
Guardicore Labs uncovers a Ransomware detection campaign targeting MySQL servers. Attackers use Double Extortion and publish data to pressure victims.
Ransomware Attacks Are Targeting Managers and other Business Leaders
Zscaler findings show ransomware attackers increasingly target managers and business leaders.
Gunra Ransomware Exploits Fortinet, Schneider
Cybersecurity agencies from South Korea and the United States have released a joint advisory warning organizations about active Gunra ransomware campaigns…
DeadLock Ransomware Stores C2 Configuration on Polygon Blockchain to Resist Takedowns
DeadLock ransomware has emerged as a financially motivated threat that locks files while threatening to publish stolen information. First observed in July…
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and…
Ransomware gangs don’t need control system access to disrupt industrial production
Disrupting IT systems that support industrial environments can be enough to interrupt production, even when ransomware operators do not gain direct access…
CISA Warns of SonicWall SMA1000 Vulnerabilities Exploited in Attacks to Deploy Ransomware
The U.S. Cybersecurity and Infrastructure Security Agency warned that two SonicWall SMA1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410, are being…
CISA Warns SonicWall SMA1000 Flaws Are Exploited in Ransomware Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in SonicWall SMA1000 to its Known Exploited…
DeadLock Ransomware Disables Windows Defender, Backups and Event Logs Before Encrypting Files
DeadLock, an emerging financially motivated ransomware operation that couples conventional intrusion tradecraft with decentralized infrastructure…
CISA Urges Organizations to Patch Exposed VPNs and Segment Networks Against Gunra Ransomware
CISA and international law-enforcement partners have issued a joint #StopRansomware advisory warning that Gunra ransomware affiliates are exploiting…
Gunra Ransomware Exploits Fortinet VPN Flaws to Bypass MFA and Steal Enterprise Data
A joint cybersecurity advisory from the FBI, CISA, the Department of Defense Cyber Crime Center, the NSA, the U.S. Secret Service, and South Korea’s…
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain…
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized…
Ransomware Operators Disable EDR, Backup Software and Windows Telemetry Before Encryption
Ransomware crews are increasingly trying to blind a victim before they encrypt anything. Analysis shows that attackers can disable endpoint detection and…
Ransomware Attackers Target Managers to Steal Data and Move Deeper Into Corporate Networks
Ransomware campaigns are increasingly starting with people who hold the keys to everyday business decisions. Attackers are compromising managers whose…
Play Ransomware Masquerades as PsExec to Blend Into Legitimate Windows Administration
Play ransomware is using a familiar Windows-administration disguise to reduce suspicion during intrusions: a custom service binary named PSexesvc.exe. The…
Ransomware Attackers Compromise Multiple Employees Inside the Same Company
Ransomware operations are increasingly targeting the people behind critical business processes, not just privileged IT administrators. Over a one-month…
Ransomware gangs skip the CEO, head straight for the 40-something IT manager
Gen Xers who feel triggered by this should remember to unplug the network cable and call the cops