Skip to main content
← All Articles

Tag

#Ransomware

159 articles

Advertisement

HIGH
Threat Intel

Ransomware Attackers Target Backup Infrastructure to Block Recovery

Explore how ransomware operators neutralize backup systems to prevent recovery. This analysis covers attacker TTPs and mitigation steps for backups.

Runtime Rebel Intel
3 min read · May 6, 2026
MuddyWater Exploits Microsoft Teams for False Flag Ransomware
HIGH
Threat Intel

MuddyWater Exploits Microsoft Teams for False Flag Ransomware

Iranian APT MuddyWater is leveraging Microsoft Teams social engineering to deploy false flag ransomware, obscuring state-sponsored espionage activities.

Runtime Rebel Intel
3 min read · May 6, 2026
MEDIUM
Threat Intel

Karakurt Extortion Gang Negotiator Sentenced to 8.5 Years in Prison

A Latvian national and key negotiator for the Karakurt extortion gang has been sentenced to 102 months for his role in U.S.-based data theft operations.

Runtime Rebel Intel
3 min read · May 5, 2026
BlackCat Ransomware: Cybersecurity Pros Sentenced for 2023 Attacks
MEDIUM
Threat Intel

BlackCat Ransomware: Cybersecurity Pros Sentenced for 2023 Attacks

Two cybersecurity professionals receive four-year prison sentences for their roles in facilitating BlackCat (ALPHV) ransomware attacks against U.S. victims.

Runtime Rebel Intel
3 min read · May 1, 2026
INFO
Threat Intel

Quantifying Cyber Risk: CISO Budgeting with Insurance Data

CISOs now have powerful data from cyber insurance policies to quantify cyber risk, demonstrate ROI, and justify critical security investments to boards.

Runtime Rebel Intel
4 min read · Apr 29, 2026
HIGH
Malware

VECT 2.0 Ransomware Analysis: Encryption Flaws Act as Data Wiper

VECT 2.0 ransomware features a critical flaw in its encryption logic that permanently wipes large files, making data recovery impossible even with a key.

Runtime Rebel Intel
3 min read · Apr 29, 2026

Advertisement

VECT 2.0 Ransomware Acts as Wiper on Windows, Linux, and ESXi
MEDIUM
Malware

VECT 2.0 Ransomware Acts as Wiper on Windows, Linux, and ESXi

VECT 2.0 ransomware permanently destroys files over 131KB on Windows, Linux, and ESXi systems due to flawed encryption, making data recovery impossible.

Runtime Rebel Intel
4 min read · Apr 28, 2026
HIGH
Malware

Trigona Ransomware: Custom Tool for Faster Data Exfiltration

Trigona ransomware operators are employing a new custom command-line tool to accelerate data exfiltration, posing a significant threat to compromised networks.

Runtime Rebel Intel
5 min read · Apr 23, 2026
The Gentlemen Ransomware Group: Rapid Escalation and Sophistication
HIGH
Threat Intel

The Gentlemen Ransomware Group: Rapid Escalation and Sophistication

An analysis of 'The Gentlemen' ransomware group, highlighting their rapid operational scaling and sophisticated attack methods impacting organizations globally.

Runtime Rebel Intel
4 min read · Apr 23, 2026
HIGH
Malware

Kyber Ransomware Targets Windows, ESXi with Post-Quantum Encryption

Kyber ransomware is encrypting Windows and VMware ESXi systems, with one variant leveraging Kyber1024 post-quantum encryption, posing new decryption challenges.

Runtime Rebel Intel
4 min read · Apr 22, 2026
BlackCat Ransomware Negotiator Scheme: Insider Threat Implications
MEDIUM
Threat Intel

BlackCat Ransomware Negotiator Scheme: Insider Threat Implications

A ransomware negotiator's guilty plea in a BlackCat scheme highlights critical insider threat risks and the importance of stringent controls in ransom payment processes.

Runtime Rebel Intel
5 min read · Apr 22, 2026
INFO
Threat Intel

Security Expert Aids BlackCat Ransomware, Exposing IR Risks

A US security expert pleaded guilty to collaborating with the BlackCat ransomware group, leveraging his negotiation role.

Runtime Rebel Intel
5 min read · Apr 21, 2026
SystemBC C2 Analysis: 1,570 Victims of The Gentlemen Ransomware
HIGH
Threat Intel

SystemBC C2 Analysis: 1,570 Victims of The Gentlemen Ransomware

Analysis of a SystemBC C2 server linked to The Gentlemen ransomware reveals over 1,570 victims and the use of SOCKS5 tunnels for persistent access.

Runtime Rebel Intel
3 min read · Apr 21, 2026
HIGH
Threat Intel

Insider Threat: Former Negotiator Pleaded Guilty to BlackCat Attacks

A former cybersecurity negotiator at DigitalMint has pleaded guilty to conducting BlackCat (ALPHV) ransomware attacks against U.S. organizations.

Runtime Rebel Intel
4 min read · Apr 21, 2026
CRITICAL
Vulnerabilities

CVE-2023-46604: Apache ActiveMQ RCE Exploited by HelloKitty - Patch Now

Over 6,400 Apache ActiveMQ servers are exposed to RCE via CVE-2023-46604. Threat actors like HelloKitty are actively exploiting this high-severity flaw.

Runtime Rebel Intel
4 min read · Apr 21, 2026
MEDIUM
Threat Intel

Beyond Backups: Essential BCDR for Ransomware & Operational Resilience

Learn why traditional data backups are insufficient for business continuity. This analysis highlights the critical role of BCDR in mitigating ransomware and outage…

Runtime Rebel Intel
5 min read · Apr 20, 2026
MEDIUM
Malware

Payouts King Ransomware Deploys QEMU VMs to Evade EDR Solutions

Payouts King ransomware leverages QEMU virtualization and reverse SSH tunnels to bypass endpoint security and encrypt MSSQL servers on corporate networks.

Runtime Rebel Intel
3 min read · Apr 17, 2026
CRITICAL
Vulnerabilities

CVE-2023-46604: Apache ActiveMQ RCE Exploited in the Wild

CISA warns of active exploitation for CVE-2023-46604, a critical RCE flaw in Apache ActiveMQ used by ransomware groups. Update to version 5.18.3 or later.

Runtime Rebel Intel
3 min read · Apr 17, 2026
HIGH
Threat Intel

Germany Ransomware Surge: How SafePay and Qilin Target Mittelstand

Germany sees a 92% surge in data leaks as ransomware actors like SafePay and Qilin pivot toward the Mittelstand and professional services sectors.

Runtime Rebel Intel
4 min read · Apr 16, 2026
6-Year Ransomware Campaign Targets Turkish SMBs: An Analysis
HIGH
Threat Intel

6-Year Ransomware Campaign Targets Turkish SMBs: An Analysis

A persistent six-year ransomware operation has targeted Turkish home users and SMBs, exploiting under-reporting to maintain operational longevity.

Runtime Rebel Intel
3 min read · Apr 16, 2026
Storm-1175: High-Velocity Medusa Ransomware Campaigns
HIGH
Threat Intel

Storm-1175: High-Velocity Medusa Ransomware Campaigns

Runtime Rebel reports on Storm-1175's rapid Medusa ransomware campaigns, exploiting N-day and zero-day vulnerabilities for financial gain.

Runtime Rebel Intel
5 min read · Apr 8, 2026
HIGH
Threat Intel

German Authorities Identify GandCrab and REvil Ransomware Leaders

German and US authorities identify Russian nationals behind GandCrab and REvil ransomware operations, marking a major step in ransomware attribution.

Runtime Rebel Intel
4 min read · Apr 7, 2026
Qilin and Warlock Ransomware Bypass 300+ EDR Tools via BYOVD
HIGH
Malware

Qilin and Warlock Ransomware Bypass 300+ EDR Tools via BYOVD

Threat actors Qilin and Warlock use Bring Your Own Vulnerable Driver (BYOVD) tactics and msimg32.dll to disable security software on compromised endpoints.

Runtime Rebel Intel
3 min read · Apr 6, 2026
BKA Unmasks REvil Leadership Behind 130 German Ransomware Attacks
INFO
Threat Intel

BKA Unmasks REvil Leadership Behind 130 German Ransomware Attacks

Germany's BKA unmasks the leadership of the REvil (Sodinokibi) ransomware group, including the representative UNKN, following a major threat intel investigation.

Runtime Rebel Intel
3 min read · Apr 6, 2026