Ransomware Blog- 2026 2025 2024 2023 2021 2020 2019 2018
AI blog APT blog Attack blog BigBrother blog BotNet blog CyberCrime blog Cyber blog Cryptocurrency blog Exploit blog Hacking blog ICS blog Incident blog IoT blog Malware blog OS Blog Phishing blog Ransom blog Safety blog Security blog Social blog Spam blog Vulnerebility blog
DATE | NAME | Info | CATEG. | WEB |
|
12.9.26 |
When Detection Arrives After the Damage: Ransomware as a Patient-Safety Emergency | Healthcare ransomware is a patient-safety emergency, not just a data-privacy incident: when ransomware encrypts hospital systems, it disrupts the technology clinicians use to diagnose, treat, and stabilize patients — diverting ambulances, delaying procedures, and forcing a return to paper at the moment care is most time-sensitive. | Ransom blog | MORPHISEC |
|
5.9.26 |
Ungentlemanly behavior: Insights into a ransomware operation | Analysis of 15 intrusions revealed tradecraft used by GOLD SHERWOOD affiliates | Ransom blog | SOPHOS |
|
5.9.26 |
Orova: A New Linux Ransomware Targeting ESXi Hypervisors | This week, the SonicWall Capture Labs Threat Research Team identified and analyzed an emerging ransomware family known as Orova. The sample is an ELF 64-bit binary targeting Linux servers and VMware ESXi hypervisors. This target has drawn growing attention from ransomware operators due to the concentrated value of virtual machine datastores. | Ransom blog | SonicWall |
|
31.8.26 |
Introducing the Aur0ra Ransomware Group | During a recent incident response engagement for an external organization, the BHIS ActiveSOC team investigated activity attributed to the Aur0ra ransomware group. In this incident, initial access was gained through vishing following aggressive email bombing. This foothold was followed up by the deployment of a unique C2 mechanism with noisy lateral movement & ransomware attempts. | Ransom blog | BLACKHILLS |
|
31.8.26 |
Aurora ransomware targets ESXi, abuses Cursor Agent for exploitation | Gambit Security’s Threat Intelligence team investigates emerging attacker tradecraft and the evolving ways threat actors disrupt organizations. As part of this research, we track threat actors and their operations to identify new techniques, tooling, and approaches to disruption. | Ransom blog | GAMBIT SECURITY |
|
29.8.26 |
CRPx0 is a ClickFix-delivered ransomware-as-a-service operation whose lures impersonate Windows and macOS update prompts and reCAPTCHA checks to trick victims into running a copied command. |
|||
|
29.8.26 |
The first in CloudSEK's "Caught in 4K" series, where we pull ransomware operations out of the shadows and show exactly how they work. A misconfigured server opened a window straight into an Aurora ransomware operator's playbook: attacker tools, AI-assisted planning, and a look inside the actual negotiation panel where a victims and the operator settled on payment. |
|||
|
29.8.26 |
Ransomware leak sites have become a prominent feature of modern cyber extortion campaigns, publishing claims about breached organizations and stolen data. This article explains how leak sites work and how to use them to assess risk, monitor threat activity and make better-informed security decisions. |
|||
| 27.8.26 | How Play Achieves Encryption | GuidePoint Security analysts are often called to support and consult on Digital Forensics and Incident Response (DFIR) efforts in remediation, recovery and forensic analysis of ransomware events. Play (also tracked as PlayCrypt) is a ransomware group that has been active since June 2022. Thus far, Play has claimed hundreds of victims across North America, South America and Europe. | Ransom blog | GUIDESECURITY |
| 27.8.26 | Email Bombing and Quick Assist: A New Ransomware Playbook | The email bomb was not just noise. It was the setup. The attacker manufactured the problem, waited for the frustration to become impossible to ignore, and then arrived as the person who could "fix" it. | Ransom blog | ZEROBEC BLOG |
|
22.8.26 |
Beware the Ransomware Rescuer: Ransom Busters | The GuidePoint Research and Intelligence Team (GRIT) has responded to several recent ransomware incidents in which victims received an unexpected email from an ostensible third-party entity referring to itself as “Ransom Busters.” | Ransom blog | GUIDESECURITY |
|
22.8.26 |
The Gentlemen ransomware: Inside one of the fastest-growing extortion operations | The Gentlemen has emerged as one of the fastest-growing ransomware-as-a-service operations. This threat profile examines the group's origins, affiliate model, attack chain, infrastructure, known tactics, techniques and procedures (TTPs), and the operational-security failures that exposed its internal workings. | Ransom blog | BARRACUDA |
|
22.8.26 |
Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities | Learn how Tenable One Cloud Exposure helps you unmask the sophisticated tactics of cybercrime group Storm-0501, which carries out Azure-based cloud ransomware campaigns. Tenable One Cloud Exposure uses AI-powered threat stories to expose Storm-0501 TTPs, backed by precision-engineered threat detection alerts. | Ransom blog | TENABLE |
|
22.8.26 |
Clop Returns with Custom Implant in Mass-Extortion Campaign | This is external threat intelligence from the ReliaQuest Threat Research team. The findings describe threats, vulnerabilities, and attacker activity affecting third parties and the broader threat landscape—not ReliaQuest's own environment. Nothing in this report should be interpreted as a vulnerability in ReliaQuest's systems or data. | Ransom blog | RELIAQUEST |
|
22.8.26 |
Ransomware Threats in the Americas H1 2026: Dissecting the Regional Attack Patterns and Dominant Actors | The Americas carried the heaviest ransomware burden of any region on the planet in the first half of 2026 with 2,188 attacks. | Ransom blog | Cyble |
|
15.8.26 |
When Patching Isn't Enough: What the Fairlife Ransomware Attack Says About Network Edge Risk | A recent ransomware incident at Coca-cola owned dairy company Fairlife provides a potent example of network edge devices being targeted for exploitation, and of the scale of outcomes attackers can achieve by exploiting them. | Ransom blog | Eclypsium |
|
15.8.26 |
Ransomware Now Shows Up in Nearly Half of All Breaches: A Survival Playbook for Lean Security Teams | Ransomware now drives nearly half of breaches. Explore a practical survival playbook for lean security teams, from prevention to recovery in 2026.! | Ransom blog | Cyble |
|
15.8.26 |
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure | Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion tactics used to pressure victims. | Ransom blog | Microsoft blog |
|
15.8.26 |
The State of Ransomware Q2 2026 | For the past year, the ransomware conversation has centered on concentration: a handful of dominant RaaS operations controlling most of the damage, and a shrinking pool of active groups fighting over the same territory. The State of Ransomware Q2 2026 report from Check Point Research shows that picture starting to shift. The leaders are still winning, but the road to joining them has gotten a great deal shorter. | Ransom blog | CHECKPOINT |
|
8.8.26 |
Ransomware Moves up the Org Chart: Managers Are Prime Targets | When a ransomware attack makes headlines, attention usually turns to the organization that was breached, the systems encrypted, data stolen, and disruption or ransom demand that followed. Less, if anything, is revealed about the employees compromised at the start of the attack, and what makes those individuals valuable targets. | Ransom blog | Zscaler |
|
8.8.26 |
Interlock ransomware gang creates volatile situation | Multiple legitimate DFIR tools abused by GOLD EMBRACE double-extortion specialists | Ransom blog | SOPHOS |
|
8.8.26 |
Ransomware Threats in Europe H1 2026: A Deep Dive into Regional Attack Patterns and Dominant Threat Actors | Europe faced a ransomware onslaught in the first half of 2026 that sets a troubling precedent for the remainder of the year. According to Cyble Research and Intelligence Labs (CRIL), the region experienced 866 documented… | Ransom blog | Cyble |
|
8.8.26 |
AI Meets Ransomware : Open‑Weight AI Models Fueling Ransomware Evolution | This week, the SonicWall Capture Labs Threat Research team analyzed an interesting ransomware sample discovered about an year ago, that leverages AI capabilities in its attack workflow. Unlike conventional ransomware that embeds its malicious logic directly within the binary, PromptLock adopts a fundamentally different approach. | Ransom blog | SonicWall |
|
1.8.26 |
[Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group) | This technical analysis report was prepared as part of the joint cybersecurity advisory titled “Advisory on Cyberattacks Targeting Korean Citizens and Businesses by State-Sponsored Hacking Groups” issued by the Republic of Korea’s National Intelligence Service (NIS), National Police Agency (NPA), Korea Internet & Security Agency (KISA), and Financial Security Institute (FSI). | Ransom blog | AHNLAB |
|
1.8.26 |
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel | The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN. | Ransom blog | CISCO TALOS |
|
25.7.26 |
The Signs Were There: What the First Autonomous Ransomware Case Confirms | An AI agent has run a ransomware intrusion on its own for the first time, from break-in to data destruction. The autonomous attacks TrendAI™ Research predicted are beginning to arrive, and defending against them shifts from blocking known indicators to detecting behavior. | Ransom blog | Trend Micro |
|
18.7.26 |
Spirals: New Stealthy Ransomware Deployed Against Asian IT Company | Attack using previously unseen ransomware payload occurred in June 2026. The skill of its operators suggests wider campaigns may follow. | Ransom blog | SECURITY.COM |
|
18.7.26 |
GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses | Third iteration of ransomware from Hyadina developers who first launched the Monster ransomware in 2022. | Ransom blog | SECURITY.COM |
| 4.7.26 | Vect and TeamPCP partner for ransomware campaigns | Credentials harvested through supply chain compromises enable large‑scale ransomware deployment | Ransom blog | SOPHOS |
| 19.6.26 | Killing me gently: Inside Gentlemen’s EDR killer framework | ESET Research shares the results of a months-long investigation into the suite of EDR killers maintained by the RaaS gang Gentlemen | Ransom blog | Eset |
| 30.5.26 | The Gentlemen ransomware: Dissecting a self-propagating Go encryptor | Microsoft Threat Intelligence presents a comprehensive analysis of The Gentlemen, a Go-based ransomware deployed by affiliates of Storm-2697 that combines per-file ephemeral key encryption with an aggressive self-propagation module to deploy itself across an entire network using series of simultaneous lateral movement techniques per target. | Ransom blog | Microsoft blog |
| 23.5.26 | WantToCry ransomware remotely encrypts files | Brute-force attempts against SMB services can be early signs of an attack | Ransom blog | SOPHOS |
| 23.5.26 | Why Australian Dark Web Data Is Now Being Sold in Bundles — and What It Means for Organizational Exposure in 2026 | Australian dark web data is fueling bundled breach sales, with ransomware groups expanding cyber risks across industries in 2025. | Ransom blog | Cyble |
| 16.5.26 | The Ransomware Chimera That Does Everything | Malware typically falls into well-defined categories. Ransomware encrypts files and demands payment. Banking trojans steal credentials. Botnets await remote commands. However, some samples defy these conventional classifications by incorporating multiple threat vectors into a single executable. | Ransom blog | SonicWall |
| 16.5.26 | The State of Ransomware – Q1 2026 | Consolidation after peak fragmentation: The top 10 ransomware groups accounted for 71% of all Q1 2026 victims, a sharp reversal from the fragmentation seen in Q3 2025. The ransomware ecosystem is once again consolidating around fewer, more dominant operators. | Ransom blog | CHECKPOINT |
| 16.5.26 | Thus Spoke…The Gentlemen | On May 4th, 2026, The Gentlemen RaaS administrator acknowledged on underground forums that an internal backend database (Rocket) had been leaked. This leak exposed 9 accounts, including zeta88 (aka hastalamuerte), who runs the infrastructure, builds the locker and RaaS panel, manages payouts, and effectively acts as the administrator of the program. | Ransom blog | CHECKPOINT |
| 16.5.26 | State-sponsored actors, better known as the friends you don’t want | Responding to a state-sponsored threat is nothing like responding to ransomware, and the differences can make or break the outcome. Learn why your IR plan might need revisiting, and the factors you should consider. | Ransom blog | CISCO TALOS |
| 2.5.26 | ANZ Organizations Are in the Ransomware Crosshairs— What the Dark Web Is Telling Us | Ransomware in ANZ is evolving into a scalable cybercrime model, with dark web intelligence revealing targeted attacks, data theft, and rising risks. | Ransom blog | Cyble |
| 2.5.26 | VECT: Ransomware by design, Wiper by accident | Check Point Research discovers that the VECT 2.0 ransomware permanently destroys “large files” rather than encrypting them. A critical flaw in the encryption implementation, identical across all three platform variants (Windows, Linux, ESXi), discards three of four decryption nonces for every file above 131,072 bytes (128 KB). | Ransom blog | CHECKPOINT |
| 25.4.26 | DFIR Report – The Gentlemen & SystemBC: A Sneak Peek Behind the Proxy | The Gentlemen ransomware‑as‑a‑service (RaaS) program is rapidly gaining popularity, attracting numerous affiliates and publicly claiming over 320 victims, with the majority of attacks (240) occurring in the first months of 2026. | Ransom blog | CHECKPOINT |
| 25.4.26 | What the ransom note won’t say | An attack is what you see, but a business operation is what you’re up against | Ransom blog | Eset |
| 18.4.26 | QEMU abused to evade detection and enable ransomware delivery | The use of hidden virtual machines (VMs) enables long-term access, credential harvesting, data exfiltration, and PayoutsKing ransomware deployment | Ransom blog | SOPHOS |
| 18.4.26 | Black Hat Asia 2026 Is Coming to Singapore — Here’s What the Threat Landscape Looks Like Ahead of It | Black Hat Asia 2026 explores ransomware growth, AI-driven cyber threats, and supply chain risks reshaping global cybersecurity and digital resilience. | Ransom blog | Cyble |
| 11.4.26 | Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations | The financially motivated cybercriminal threat actor Storm-1175 operates high-velocity ransomware campaigns that weaponize recently disclosed vulnerabilities to obtain initial access, exfiltrate data, and deploy Medusa ransomware. | Ransom blog | Microsoft blog |
| 4.4.26 | An overview of ransomware threats in Japan in 2025 and early detection insights from Qilin cases | There were 134 ransomware incidents reported in Japan in 2025, representing a 17.5% year-over-year increase from 2024. | Ransom blog | CISCO TALOS |
| 4.4.26 | Ransomware in 2025: Blending in is the strategy | A summary of the top ransomware trends from the Talos 2025 Year in Review, with a focus on identity, attacker tactics, and practical defenses. | Ransom blog | CISCO TALOS |
| 28.3.26 | The Energy Sector’s Ransomware Nightmare: Why Critical Infrastructure Can’t Catch a Break | Energy sector ransomware nightmare continued in 2025 but here’s lessons to learn for critical infrastructure protection in 2026. | Ransom blog | Cyble |
| 21.3.26 | Since 2018, when many financially motivated threat actors began shifting their monetization strategy to post-compromise ransomware deployments, ransomware has become one of the most pervasive threats to organizations across almost every industry vertical and region. | Ransom blog | GTI | |
| 21.3.26 | Everyday tools, extraordinary crimes: the ransomware exfiltration playbook | Attackers use trusted tools for data theft, making traditional detection unreliable. The Exfiltration Framework enables defenders to spot exfiltration by focusing on behavioral signals across endpoints, networks, and cloud environments rather than static tool indicators. | Ransom blog | CISCO TALOS |
| 14.2.26 | Naming and shaming: How ransomware groups tighten the screws on victims | When corporate data is exposed on a dedicated leak site, the consequences linger long after the attack fades from the news cycle | Ransom blog | Eset |
| 7.2.2026 | Ransomware Attacks Have Surged 30% Since Q4 2025 | Ransomware groups have averaged nearly 700 victims a month in the last four months, and many attacks have posed supply chain risks. | Ransom blog | Cyble |
| 7.2.2026 | Black Basta: Defense Evasion Capability Embedded in Ransomware Payload | A recent Black Basta attack campaign was notable because the ransomware contained a bring-your-own-vulnerable-driver (BYOVD) defense evasion component embedded within the ransomware payload itself. | Ransom blog | SECURITY.COM |
| 1.2.26 | Eeny, meeny, miny, moe? How ransomware operators choose victims | Most ransomware attacks are opportunistic, not targeted at a specific sector or region | Ransom blog | SOPHOS |
| 24.1.26 | Osiris: New Ransomware, Experienced Attackers? | Poortry driver and modified Rustdesk tool used in recent attack campaign, which bears similarities to previous Inc ransomware attacks. | Ransom blog | SECURITY.COM |
| 24.1.26 | Ransomware: Tactical Evolution Fuels Extortion Epidemic | New whitepaper reveals record number of attacks as threat landscape evolves with new players and new tactics. | Ransom blog | SECURITY.COM |
| 17.1.26 | In December 2025, organizations experienced an average of 2,027 cyber attacks per organization per week. ... | Ransom blog | CHECKPOINT | |
| 17.1.26 | Sicarii Ransomware: Truth vs Myth | Sicarii is a newly observed RaaS operation that surfaced in late 2025 and has only published 1 claimed victim. | Ransom blog | |
| 10.1.26 | 5 ways your firewall can keep ransomware out — and lock it down if it gets in | Ransomware continues to cripple organizations worldwide, draining budgets and halting operations. For IT teams already stretched thin, a single attack can mean days of downtime and irreversible data loss. | Ransom blog | SOPHOS |
| 10.1.26 | TRACKING RANSOMWARE : DEC 2025 | EXECUTIVE SUMMARY Ransomware activity in December 2025 highlights an evolution toward cartel-style, collaborative ecosystems, where initial access, persistence, encryption, and | Ransom blog |