Ransomware — Page 5

Fake Interpol Arrest Notices Are Delivering Ransomware to Small Businesses
Criminals are impersonating the international police agency to frighten small business owners into downloading malware. The tactic is simple. It's working.

FortiBleed: 11,000 Fortinet Firewalls Still Compromised, Now Tied to INC and Lynx Ransomware
Researchers say the same crew that hoarded credentials from hundreds of thousands of Fortinet firewalls has been sitting inside the negotiation panels of two major ransomware gangs.

Ransomware Surge Led by Lockbit and Conti Offshoots
July sees a resurgence in ransomware attacks, with Lockbit and Conti offshoots dominating the landscape.

Anubis Affiliates Ride Citrix Bleed 2 Into Enterprise Networks
Ransomware crews are chaining CVE-2025-5777 with RMM tooling and stolen credentials to skip past MFA entirely.

FortiBleed: Stolen FortiGate Credentials Now Fueling INC and Lynx Ransomware Attacks
Credentials harvested from hundreds of thousands of compromised FortiGate devices are feeding active ransomware operations — and defenders who haven't rotated credentials post-patch are still exposed.

FortiBleed Credential Haul Now Feeding INC and Lynx Ransomware Crews
A single operator was spotted running negotiation panels for both gangs, turning stolen FortiGate logins into ransomware payloads.

Sysdig Flags 'JADEPUFFER' as First End-to-End AI-Run Ransomware Attack
Researchers say a large language model handled intrusion, lateral movement and destruction of a production database without a human at the keyboard.

Double Trouble: Two Unrelated Attacks Thrive on Unpatched SharePoint
Microsoft DART uncovers dual intrusions on same server, complicating response efforts.

War Room Debrief: How a Fictional Grocery Chain Got Crushed by APT 64
A tabletop exercise at Infosecurity Europe put ransomware, AI poisoning, and deepfake CEO videos inside a simulated supermarket attack. The blue team held the line. The red team shorted the stock anyway.

The Gentlemen RaaS Platform Enhances Arsenal with EDR Killer Framework
The Gentlemen's new EDR killer, 'GentleKiller', arms affiliates with advanced intrusion tools.

The Gentlemen RaaS Ships an In-House EDR Killer to Affiliates
GentleKiller bundles signed-driver abuse, third-party utilities, and a kill list of roughly 400 security processes — handed out as part of the affiliate package.

INC Ransomware Fills the LockBit Vacuum, Racks Up 830+ Victims
Two years after a quiet debut, INC has graduated from boutique RaaS to one of 2026's busiest extortion brands — riding the affiliate exodus from LockBit and BlackCat.

DragonForce Crew Tunnels RAT Traffic Through Microsoft Teams Relays
A Go-based backdoor dubbed Backdoor.Turn piggybacks on Teams' own relay infrastructure to hide C2 calls inside a U.S. services firm's network.

The Gentlemen: A RaaS Affiliate That Grew Up and Wrote Its Own Worm
A double-extortion crew that started out renting LockBit, Qilin, and Medusa lockers has graduated to its own toolkit — including a payload with self-propagation.

AI Tools Surge in Ransomware Markets, Lowering Entry Barriers
Underground markets see a boom in AI-driven tools, making ransomware more accessible and profitable.