-
A newly surfaced criminal AI service named MessiahGPT is being marketed on BreachForums as an unrestricted offensive model capable of generating ransomware, phishing kits, stealers, crypters, rootkits, and social-engineering content on demand. The Trel…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An Akira ransomware affiliate has been observed rebooting a compromised Windows host into Safe Mode with Networking to disable endpoint protection an anti-EDR tactic linked to the operation. The intrusion failed to encrypt files after the stripped-down…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Gunra ransomware has added a Linux encryptor to its arsenal, giving affiliates control over how they lock enterprise data. The command-line payload can launch up to 100 encryption threads, a design that compresses the time defenders have to detect and …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
DeadLock, an emerging financially motivated ransomware operation that couples conventional intrusion tradecraft with decentralized infrastructure engineered to survive disruption. First observed in July 2025, the operation uses double extortion: encryp…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
CISA and international law-enforcement partners have issued a joint #StopRansomware advisory warning that Gunra ransomware affiliates are exploiting exposed edge infrastructure, including VPN gateways, firewall appliances and RDP-accessible systems, to…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Play ransomware is using a familiar Windows-administration disguise to reduce suspicion during intrusions: a custom service binary named PSexesvc.exe. The group’s use of a custom service binary named PSexesvc.exe, mimicking Microsoft Sysinternals PsExe…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Interlock ransomware incident that shows how unprotected endpoints can give attackers enough time to steal credentials, establish persistence, and reach a domain controller before defenders intervene. During a March 2026 response engagement, Sophos Eme…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Ransomware operations are increasingly targeting the people behind critical business processes, not just privileged IT administrators. Over a one-month observation period, ThreatLabz identified 351 victims across 334 organizations connected to a single…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Ransomware operators are now abusing Ethereum smart contracts as stealthy command‑and‑control resolvers, with a Gentlemen ransomware affiliate using the EtherRAT backdoor to pull rotating C2 domains directly from the blockchain instead of hardcoding th…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


