2025-04-02 06:02 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Learn about technical details on the ransomware and Storage Software tool, how the criminals use the affiliate panel as well as information on the Hunters International ransomware group from its emergence to the end of the operation.
P15
2025-03-04 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Explore 2024's top cyber threats, including ransomware trends, advanced phishing tactics, and targeted industries. Stay ahead—download the Huntress 2025 Cyber Threat Report now!
P15
2025-02-12 06:59 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discover how ransomware has evolved into a sophisticated cyber threat, with groups like RansomHub leading the charge. Learn more about their adaptability, TTPs, and the rise of Ransomware-as-a-service in this first-of-three-part trilogy.
P15
2025-02-11 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress’ 2025 Cyber Threat Report is here! Explore the year's biggest threats—RATs, phishing, ransomware—and how evolving tactics demand smarter defense.
P15
2025-01-28 06:43 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
In this blog, we observed how the Lynx Ransomware-as-a-Service (RaaS) group operates, detailing the workflow of their affiliates within the panel, their cross-platform ransomware arsenal, customizable encryption modes, and advanced technical capabilities.
P15
2024-10-17 07:26 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
In this blog, we observed how the Cicada3301 Ransomware-as-a-Service (RaaS) group operates, detailing the workflow of their affiliates within the panel and examining the Windows, Linux, ESXi, and PowerPC variants of the ransomware.
P15
2024-09-25 07:00 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
In this blog, we look at the DragonForce ransomware group, which poses a severe threat with two variants—a LockBit fork and a customized Conti fork with advanced features and SystemBC malware.
P15
2024-09-22 16:48 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress analysts see a number of attacks on a daily and weekly basis, some of which include ransomware attacks. Now and again, Huntress analysts will observe a ransomware attack that stands out in some novel manner.
P15
2024-09-20 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Tracking various indicators associated with different attacks, Huntress analysts have been able to identify specific indicators (threat actor workstation names, passwords associated with new user account creation or current account modification, CloudFlare tunnel tokens) that are associated with Akira ransomware infections. By detecting these indicators much earlier in the attack chain, organizations can inhibit or even obviate file encryption malware deployment.
P15
2024-08-28 06:52 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Learn why RansomHub's new affiliate program and its advanced ransomware tactics—recruiting former Scattered Spider members, exploiting unprotected RDP services, and exfiltrating large data volumes—are critical for staying ahead of modern cyber threats.
P15
2024-08-14 06:45 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Deep dive into Brain Cipher ransomware group's activities and techniques, and how they are seemingly linked to other ransomware groups such as EstateRansomware and SenSayQ
P15
2024-07-17 06:00 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discover the insidious tactics of the Qilin ransomware group, notorious for their $50 million attack on the healthcare sector, impacting key NHS hospitals.
P15
2024-07-10 05:55 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Delaying security updates and neglecting regular reviews created vulnerabilities that were exploited by attackers, resulting in severe ransomware consequences.
P20
2024-07-03 05:59 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
All about Eldorado Ransomware and how its affiliates make their own samples for distribution.
P15
2024-06-08 06:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn what’s causing a surge in ransomware attacks on healthcare organizations and find out how new guidelines from HHS are addressing the problem.
P15
2024-06-06 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Explore the latest ransomware and BEC threats targeting healthcare today. And learn how to navigate emerging threats with insights from our 2024 Cyber Threat Report.
P15
2024-05-22 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Explore the interesting changes in the world of ransomware and more key findings from Huntress' 2024 Cyber Threat Report.
P15
2024-05-03 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Ransomware is spreading like wildfire. Learn about its growing threat to healthcare, its impact on patient care, and how Huntress managed solutions can better protect your organization from cyberattacks.
P15
2024-05-01 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress has observed INC ransomware deployed in the past but recent activity indicates a possible continued shift in/or improvement of tactics employed by these threat actors.
P15
2024-03-13 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
“Double extortion” attacks, often perpetrated by ransomware threat actors, include data exfiltration prior to file encryption. Huntress analysts have observed various means of data exfiltration, but recently observed the use of a legitimate backup application seen by others to be associated with a Noberus/ALPHV ransomware affiliate.
P15
2024-02-29 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
The publication of the first blog post led a Huntress SOC analyst to identify and escalate a second, similar incident. A deeper investigation into the activity made it clear that the Huntress SOC had obviated several Trigona ransomware attacks, protecting customers from the impact of a ransomware infection.
P15
2024-02-28 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
This blog post provides a detailed look at the TTPs of a ransomware affiliate operator. In this case, the endpoint had been moved to another infrastructure (as illustrated by various command lines, and confirmed by the partner), so while Huntress SOC analysts reported the activity to the partner, no Huntress customer was impacted by the ransomware deployment.
P15
2024-01-17 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress analysts continue to observe access to endpoints via legacy TeamViewer installations, and/or compromised TeamViewer credentials.
P15
2023-11-08 07:59 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Take a deep dive into the operations of one of the most active players in the Ransomware-as-a-Service market.
P15
2023-11-07 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
CVE-2023-22518 is being exploited in Confluence for Cerber ransomware deployment. Read up on Huntress’ observations and mitigation guidance.
P20
2023-09-26 07:55 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
No sleep until the Cybercrime Fighters Club is done with finding the answer as to who is behind this new ransomware-as-a-service affiliate.
P15
2023-08-11 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
The Huntress team investigated a ransomware attack of a new INC Ransom threat actor group. Here is the activity we observed.
P15
2023-05-15 08:20 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
All you need to know about Qilin ransomware and its operations targeting critical sectors.
P15
2023-04-04 17:24 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB uncovers a new stealthy ransomware strain
P15
2023-02-17 07:57 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
What happens when you combine ransomware with information stealers, remote access Trojans, and other malware in one easy-to-download package?
P15