Ransomware — Page 3

Ransomware

The Gentlemen RaaS Platform Enhances Arsenal with EDR Killer Framework

The Gentlemen's new EDR killer, 'GentleKiller', arms affiliates with advanced intrusion tools.

2 min read
Ransomware

The Gentlemen RaaS Ships an In-House EDR Killer to Affiliates

GentleKiller bundles signed-driver abuse, third-party utilities, and a kill list of roughly 400 security processes — handed out as part of the affiliate package.

2 min read
Ransomware

INC Ransomware Fills the LockBit Vacuum, Racks Up 830+ Victims

Two years after a quiet debut, INC has graduated from boutique RaaS to one of 2026's busiest extortion brands — riding the affiliate exodus from LockBit and BlackCat.

2 min read
Ransomware

DragonForce Crew Tunnels RAT Traffic Through Microsoft Teams Relays

A Go-based backdoor dubbed Backdoor.Turn piggybacks on Teams' own relay infrastructure to hide C2 calls inside a U.S. services firm's network.

3 min read
Ransomware

The Gentlemen: A RaaS Affiliate That Grew Up and Wrote Its Own Worm

A double-extortion crew that started out renting LockBit, Qilin, and Medusa lockers has graduated to its own toolkit — including a payload with self-propagation.

3 min read
Ransomware

AI Tools Surge in Ransomware Markets, Lowering Entry Barriers

Underground markets see a boom in AI-driven tools, making ransomware more accessible and profitable.

2 min read
Ransomware

Gentlemen Ransomware Spreads Before It Encrypts — That's the Whole Point

Microsoft's analysis of the Go-based Gentlemen encryptor shows why lateral movement, not file-locking, is now the primary design goal of serious ransomware operations.

2 min read
Ransomware

More Than Half of CISOs Would Pay a Ransomware Demand. The Maths Are Not Flattering.

A survey of 750 CISOs in the US and UK finds 58% would hand over money to ransomware operators — despite law enforcement advice, incomplete decryption rates, and the lingering question of whether the data stays exclusive.

3 min read
Ransomware

Operation Saffron Yanks the Plug on First VPN, the Getaway Car of at Least 25 Ransomware Crews

French and Dutch police led the takedown of a bulletproof VPN service that prosecutors say routed traffic for Conti, LockBit affiliates, and roughly two dozen other ransomware brands.

2 min read
© 2026 Threat Vectr