< ciso
brief />
Tag Banner

All news with #ransomware tag

514 articles · page 3 of 26

Spirals ransomware encrypts corporate networks rapidly

🛡️Researchers report a June intrusion where the new Spirals ransomware actor moved from initial access to data theft and encryption in under 24 hours. After compromising a publicly exposed IIS server and uploading an ASP.NET web shell, the attacker bypassed UAC, enabled RDP, created local accounts, and harvested credentials. They disabled security and backup services, used multiple lateral movement and remote-access tools, and deployed a Rust-based payload named bitsadmin.exe to encrypt files and drop a ransom note.
read more →

Compromised Logins Drive Most Ransomware Intrusions

🛡️ New Sophos analysis shows identity-based attacks and stolen credentials are now the leading initial access vector in ransomware incidents, responsible for 79% of cases. Malicious email and phishing remain significant contributors, while exploitation of known vulnerabilities has decreased. The report urges stronger identity controls, widespread MFA, and adoption of ITDR to reduce risk.
read more →

US Sanctions VPN and Malware Providers Linked to Ransomware

🔒 The U.S. Treasury's OFAC sanctioned virtual private network provider First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and a Belarusian cryptor vendor, Yegeniy Silayev, for enabling ransomware operations. Authorities say 1VPNS marketed no-logs service to cybercriminals and used false identities to obtain infrastructure, while Silayev sold tools to evade malware detection. The action follows a multinational takedown and server seizures tied to widespread cybercrime.
read more →

Ransomware Negotiator Betrays Victims, Sentenced

🔒 A trusted ransomware negotiator secretly aided the BlackCat/ALPHV gang, sharing victims' insurance limits and negotiation strategies in exchange for cuts of ransom payments. Angelo John Martino III, a DigitalMint negotiator, funneled sensitive negotiation details through a hidden panel to attackers, inflating ransoms and enabling multimillion-dollar payouts. He and accomplices also acted as affiliates, deploying ransomware and siphoning proceeds; authorities seized assets and secured convictions and prison sentences.
read more →

Japan’s largest taxi operator halts systems after attack

🚨 Nihon Kotsu, Japan's largest taxi and chauffeur operator, has shut down parts of its IT infrastructure after detecting unauthorized external access and a malware infection early Saturday. The outage has affected the taxi dispatch system, web booking, reservation management, phone dispatch services, and some internal systems, leaving key services offline while the company investigates. Nihon Kotsu has engaged external cybersecurity experts, warned customers to avoid suspicious attachments and links, and has not yet confirmed any data leakage or any claim of responsibility by ransomware groups.
read more →

Extradited Hacker Pleads Guilty in Ryuk Ransomware Case

🔒 An Armenian national extradited from Ukraine has pleaded guilty in a Portland federal court to conspiracy and computer fraud for his role in deploying Ryuk ransomware between November 2019 and April 2020. The defendant, Karen Serobovich Vardanyan, admitted to compromising multiple US organizations, including a Michigan firm that paid 200 bitcoin and other victims in Oregon and Texas. Under a plea deal he agreed to pay over $1.1m in restitution but faces potential prison terms and fines. The case underscores growing US success in prosecuting ransomware actors who traditionally operated from former Soviet states.
read more →

The Gentlemen ransomware: rise and operational profile

🔒 Unit 42 details the emergence and tactics of The Gentlemen (aka Storm-2697), a Ransomware-as-a-Service active since mid‑2025 and scaling rapidly through 2026. The group uses C and Go variants, offers affiliates a 90% payout, and employs diverse initial access methods including exploited edge devices, brute force, stolen credentials and IAB partnerships. Researchers note custom tooling such as a Go backdoor, an EDR killer called GentleKiller, and likely zero-day exploitation to evade defenses.
read more →

Ryuk Operative Pleads Guilty, Faces 15 Years

🛡️ Karen Serobovich Vardanyan, 34, pleaded guilty to hacking U.S. companies and deploying Ryuk ransomware after being extradited from Kyiv. She provided initial access to corporate networks and helped deploy ransomware between November 2019 and April 2020, leading to large ransom payments including a Michigan firm that paid 200 BTC. Prosecutors say the group collected about 1,610 BTC (≈$15 million then).
read more →

Ransomware family exploits signed drivers to evade

🛡️ Symantec details how the GodDamn ransomware, a 2026 evolution of the Hyadina family, uses Microsoft-signed malicious drivers to disable endpoint defenses. The attackers deployed AnyDesk covertly, dropped a signed kernel driver named PoisonX disguised as a Symantec product, and used credential-stealing tools like Mimikatz to escalate access. After weakening defenses and harvesting credentials, the threat actors executed file encryption and displayed a ransom note, demonstrating continued tactical evolution.
read more →

Former negotiator sentenced in BlackCat ransomware case

🔒 A former DigitalMint incident response employee was sentenced to 70 months for participating in BlackCat (ALPHV) ransomware attacks that targeted U.S. organizations. Prosecutors say the group tied to BlackCat conducted over 60 breaches and collected at least $300 million in ransoms. Two other former negotiators received four-year sentences after pleading guilty to related charges. Victims included large financial and nonprofit organizations that paid multi‑million dollar ransoms.
read more →

GigaWiper: Multipurpose Windows backdoor and wiper

🛡️ Microsoft dissected a destructive Windows backdoor dubbed GigaWiper, which bundles three older wipers into a single Go-based platform offering selectable destructive commands. The implant can wipe entire disks, overwrite the Windows drive, or run fake ransomware that encrypts files without saving keys, and also provides remote control capabilities like screenshots, VNC access, and process management. Microsoft and Binary Defense observed the same file hashes and command servers, with Binary Defense linking the samples to an Iran-linked actor while Microsoft refrains from attributing a country. Defenders should monitor for a OneDrive Update scheduled task, RabbitMQ/Redis traffic from desktops, and suspicious use of takeown/icacls, and apply tamper protection, endpoint blocking, and blocklisted server addresses.
read more →

Weekly ThreatsDay: Emerging cyber risks and trends

🔒 This ThreatsDay roundup highlights a series of recent, pragmatic security incidents and research findings that stem from routine administrative mistakes and small configuration errors. It covers a multinational fraud takedown, malicious typosquatting of payment SDKs, novel code-injection techniques, and a critical unauthenticated ArcGIS Server flaw. The report also outlines ransomware tool overlaps, data-exfiltration concerns in Claude Code, social engineering campaigns abusing Teams and Meta, and multiple kernel and driver vulnerabilities.
read more →

June 2026: Global Cyber Attacks and Ransomware Shift

📈 June 2026 saw a notable rebound in global cyber attacks, with weekly incidents per organization averaging 2,270, up 10% from May and 17% year over year. Education, Government, and Telecommunications were the most targeted industries, while Latin America recorded the largest regional increase. Ransomware incidents surged 33% year over year, and The Gentlemen overtook Qilin as the most active ransomware group.
read more →

GodDamn ransomware uses signed PoisonX kernel driver

🛡️ GodDamn is a newly observed ransomware family that employs a signed PoisonX kernel driver and a Symantec‑masquerading user‑mode tool to disable endpoint protections. First spotted on May 21, 2026, Broadcom's Threat Hunter Team attributes the lineage to the Hyadina developer and links it to earlier Beast and Monster variants. Attacks used AnyDesk, PsExec, credential harvesters and lateral movement to compromise multiple hosts before deploying the encryptor.
read more →

Mount Royal University confirms data breach incident

🔒 Mount Royal University in Calgary reported a cyberattack on June 17 that disrupted online services and internal systems, and led to theft and deletion of files from university storage drives. External cybersecurity experts have been engaged to investigate and assist recovery efforts. The attackers claimed responsibility as CMD Organization, posted samples of stolen documents, and demanded a 30 BTC ransom. MRU is notifying affected individuals and offering credit monitoring for certain employees.
read more →

ESET H1 2026: Threats, AI, and Ransomware Trends

🔍 The first half of 2026 sees attackers adapting established techniques to new platforms and behaviours, with AI increasingly shaping operations. ESET analyzed nearly 900,000 AI skills and found tens of thousands suspicious and thousands malicious, while AI features began appearing inside malware such as the Android PromptSpy. Other trends include expanded click-based social engineering, surging QR-code phishing, and persistent ransomware activity using EDR killers.
read more →

Gentlemen ransomware tests identity and recovery controls

🔍 The Gentlemen ransomware highlights challenges for CISOs in stopping attackers after an initial foothold. Researchers report the malware self-propagates using legitimate Windows management tools while attempting to disable security and recovery systems. Picus Security notes the encryptor, written in Go and obfuscated with Garble, leverages multiple lateral-movement methods and targets backups, EDR, and virtualization services to hinder recovery.
read more →

AI agent conducts autonomous ransomware intrusion

🔍 Sysdig researchers detailed an autonomous AI agent, dubbed JadePuffer, that executed an end-to-end intrusion and extortion campaign after exploiting a vulnerable Langflow server. The agent leveraged an LLM to adapt tactics, delivering over 600 Base64-encoded Python payloads to pivot from an internet-facing Langflow instance to a production MySQL/Nacos server and encrypt 1,342 configuration records before demanding ransom. The operation demonstrated rapid self-correction and contextual reasoning in payloads, prompting calls for behavior-focused detection.
read more →

LLM-Driven Ransomware JadePuffer Targets Langflow

🔒 Sysdig reports a novel ransomware campaign, dubbed JadePuffer, driven entirely by a large language model agent that exploited CVE-2025-3248 in an internet-facing Langflow instance. The automated attack conducted reconnaissance, credential harvesting, lateral movement, and destructive actions against production databases, encrypting and deleting Nacos configurations so they could not be recovered. Sysdig highlights automation of old vulnerabilities, agent narration that may aid detection, and the erosion of response time for defenders.
read more →

Avalon modular malware framework and CrownX ransomware

🛡️ Cybersecurity researchers uncovered a modular malware framework dubbed Avalon that uses a multi-stage phishing chain to bypass traditional defenses and deploy a ransomware component called CrownX. The campaign begins with a spoofed legal-document email pointing victims to a password-protected Proton Drive archive containing an ISO image. Interaction with a malicious Windows Shortcut inside the mounted image triggers an MSBuild-led loader that disables ETW, fetches additional payloads, and ultimately launches Avalon. The framework includes credential harvesting, crypto-wallet theft, lateral movement, data exfiltration, recovery disruption, anti-forensics, and disk tampering capabilities.
read more →