Advertisement
Ransomware Attackers Target Backup Infrastructure to Block Recovery
Explore how ransomware operators neutralize backup systems to prevent recovery. This analysis covers attacker TTPs and mitigation steps for backups.
MuddyWater Exploits Microsoft Teams for False Flag Ransomware
Iranian APT MuddyWater is leveraging Microsoft Teams social engineering to deploy false flag ransomware, obscuring state-sponsored espionage activities.
Karakurt Extortion Gang Negotiator Sentenced to 8.5 Years in Prison
A Latvian national and key negotiator for the Karakurt extortion gang has been sentenced to 102 months for his role in U.S.-based data theft operations.
BlackCat Ransomware: Cybersecurity Pros Sentenced for 2023 Attacks
Two cybersecurity professionals receive four-year prison sentences for their roles in facilitating BlackCat (ALPHV) ransomware attacks against U.S. victims.
Quantifying Cyber Risk: CISO Budgeting with Insurance Data
CISOs now have powerful data from cyber insurance policies to quantify cyber risk, demonstrate ROI, and justify critical security investments to boards.
VECT 2.0 Ransomware Analysis: Encryption Flaws Act as Data Wiper
VECT 2.0 ransomware features a critical flaw in its encryption logic that permanently wipes large files, making data recovery impossible even with a key.
Advertisement
VECT 2.0 Ransomware Acts as Wiper on Windows, Linux, and ESXi
VECT 2.0 ransomware permanently destroys files over 131KB on Windows, Linux, and ESXi systems due to flawed encryption, making data recovery impossible.
Trigona Ransomware: Custom Tool for Faster Data Exfiltration
Trigona ransomware operators are employing a new custom command-line tool to accelerate data exfiltration, posing a significant threat to compromised networks.
The Gentlemen Ransomware Group: Rapid Escalation and Sophistication
An analysis of 'The Gentlemen' ransomware group, highlighting their rapid operational scaling and sophisticated attack methods impacting organizations globally.
Kyber Ransomware Targets Windows, ESXi with Post-Quantum Encryption
Kyber ransomware is encrypting Windows and VMware ESXi systems, with one variant leveraging Kyber1024 post-quantum encryption, posing new decryption challenges.
BlackCat Ransomware Negotiator Scheme: Insider Threat Implications
A ransomware negotiator's guilty plea in a BlackCat scheme highlights critical insider threat risks and the importance of stringent controls in ransom payment processes.
Security Expert Aids BlackCat Ransomware, Exposing IR Risks
A US security expert pleaded guilty to collaborating with the BlackCat ransomware group, leveraging his negotiation role.
SystemBC C2 Analysis: 1,570 Victims of The Gentlemen Ransomware
Analysis of a SystemBC C2 server linked to The Gentlemen ransomware reveals over 1,570 victims and the use of SOCKS5 tunnels for persistent access.
Insider Threat: Former Negotiator Pleaded Guilty to BlackCat Attacks
A former cybersecurity negotiator at DigitalMint has pleaded guilty to conducting BlackCat (ALPHV) ransomware attacks against U.S. organizations.
CVE-2023-46604: Apache ActiveMQ RCE Exploited by HelloKitty - Patch Now
Over 6,400 Apache ActiveMQ servers are exposed to RCE via CVE-2023-46604. Threat actors like HelloKitty are actively exploiting this high-severity flaw.
Beyond Backups: Essential BCDR for Ransomware & Operational Resilience
Learn why traditional data backups are insufficient for business continuity. This analysis highlights the critical role of BCDR in mitigating ransomware and outage…
Payouts King Ransomware Deploys QEMU VMs to Evade EDR Solutions
Payouts King ransomware leverages QEMU virtualization and reverse SSH tunnels to bypass endpoint security and encrypt MSSQL servers on corporate networks.
CVE-2023-46604: Apache ActiveMQ RCE Exploited in the Wild
CISA warns of active exploitation for CVE-2023-46604, a critical RCE flaw in Apache ActiveMQ used by ransomware groups. Update to version 5.18.3 or later.
Germany Ransomware Surge: How SafePay and Qilin Target Mittelstand
Germany sees a 92% surge in data leaks as ransomware actors like SafePay and Qilin pivot toward the Mittelstand and professional services sectors.
6-Year Ransomware Campaign Targets Turkish SMBs: An Analysis
A persistent six-year ransomware operation has targeted Turkish home users and SMBs, exploiting under-reporting to maintain operational longevity.
Storm-1175: High-Velocity Medusa Ransomware Campaigns
Runtime Rebel reports on Storm-1175's rapid Medusa ransomware campaigns, exploiting N-day and zero-day vulnerabilities for financial gain.
German Authorities Identify GandCrab and REvil Ransomware Leaders
German and US authorities identify Russian nationals behind GandCrab and REvil ransomware operations, marking a major step in ransomware attribution.
Qilin and Warlock Ransomware Bypass 300+ EDR Tools via BYOVD
Threat actors Qilin and Warlock use Bring Your Own Vulnerable Driver (BYOVD) tactics and msimg32.dll to disable security software on compromised endpoints.
BKA Unmasks REvil Leadership Behind 130 German Ransomware Attacks
Germany's BKA unmasks the leadership of the REvil (Sodinokibi) ransomware group, including the representative UNKN, following a major threat intel investigation.