Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Ransomware

20 articles

Krebs on Security Ransomware 6h ago

Who Runs the Ransomware Group ‘The Gentlemen?’

A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hacker...

Krebs on Security →

SecurityWeek Ransomware 6h ago

Infostealers Turn Millions of Devices Into Credential Theft Machines

As attackers increasingly favor stolen credentials over exploits, infostealers have become a primary source of access for ransomware and other cybercrime ope...

T1078 T1598

SecurityWeek →

Graham Cluley Ransomware 6h ago

Why schools remain one of cybercriminals’ favourite targets

Schools on both sides of the Atlantic have been revealed in recent days to have been hit by hackers, reminding all of us that ransomware gangs see educationa...

Graham Cluley →

GBHackers Ransomware 14h ago

Hackers Use ClickFix Chain to Deploy MLTBackdoor Malware

A sophisticated new backdoor family, tracked as MLTBackdoor, that operators are deploying through a multi-stage ClickFix infection chain to establish foothol...

GBHackers →

CSO Online Ransomware Amazon Check Point 1d ago

Check Point warns of ransomware-linked attacks exploiting outdated VPN protocol

Check Point has issued emergency hotfixes for a pair of vulnerabilities affecting VPN deployments that still use the deprecated Internet Key Exchange version...

CSO Online →

SecurityWeek Ransomware 2d ago

Silent Ransom Group Uses DNS Fast Flux in Attacks

Focusing on hacking law firms in the US, the ransomware group relies on fast flux to hide its C&C infrastructure. The post Silent Ransom Group Uses DNS Fast ...

SecurityWeek →

SC Media Ransomware 4d ago

Pro-Russian hacker group launches 'Patriotic Online Games' campaign targeting European organizations

The group is leveraging Telegram to enlist "patriotic volunteers," offering cryptocurrency rewards for participating in various cyber activities, including D...

T1498 T1592

SC Media →

CSO Online Ransomware 5d ago

AI tools becoming hot commodities on ransomware marketplaces

Sales of AI-based tools is accelerating within underground ransomware marketplaces, lowering the barrier to entry for new actors in the process. An analysis ...

T1598

CSO Online →

GBHackers Ransomware Microsoft 5d ago

VECT 2.0 Ransomware Breaks Files Beyond Its Own Recovery

VECT 2.0 ransomware can leave victims with files that even the attacker’s own decryptor cannot reliably restore.

GBHackers →

SC Media Ransomware 6d ago

U.S. sanctions Iran's largest crypto exchange Nobitex for facilitating terrorism financing

Nobitex is accused of processing over 50% of Iranian digital asset inflows in 2025 and enabling transactions connected to the Islamic Revolutionary Guard Cor...

SC Media →

GBHackers Ransomware 6d ago

Payouts King Ransomware Bypasses EDR via Obfuscation and Direct Syscalls

Payouts King ransomware has emerged as a notable post-BlackBasta threat, leveraging advanced obfuscation and direct system calls to evade endpoint detection ...

T1566 T1027

GBHackers →

BleepingComputer Ransomware 6d ago

The U.S. sanctions Nobitex crypto exchange used by ransomware

The U.S.

BleepingComputer →

SC Media Ransomware Microsoft Cloudflare Sophos Jun 3

AI accelerates development of ransomware toolkit with EDR evasion capabilities

The toolkit, discovered by Sophos, includes features such as Cobalt Strike profiles to disguise beacon traffic, a Telegram bot API for command and control, P...

T1562 T1071

SC Media →

GBHackers Ransomware Amazon Fortinet Jun 3

Gentlemen Ransomware Exploits Fortinet Flaws, AI, and Custom C2 Tools

A newly analyzed leak tied to The Gentlemen ransomware group reveals how modern ransomware operations are evolving in structure and tooling while relying on ...

GBHackers →

Help Net Security Ransomware Jun 3

A small Slovenian team handles 6,000 cyber incidents a year

Online fraud complaints, ransomware cases, and phishing tips reach Slovenia’s national cyber response center in steady volume, and a team of around a dozen a...

T1566

Help Net Security →

BleepingComputer Ransomware Jun 2

AI-built ransomware toolkit automates EDR evasion, AD discovery

A threat actor is using an AI-built ransomware attack toolkit that automates Active Directory discovery and helps evade endpoint detection and response (EDR)...

T1562

BleepingComputer →

SC Media Ransomware Jun 1

Ransomware leak posts show weekday peak, October spikes

The data analyzed by the Ransomnews Research Team indicates that ransomware operations largely follow a business week, with significantly fewer posts on Sund...

SC Media →

SC Media Ransomware Intel Jun 1

Digital Intelligence Lab launches observatory to connect cyber events with geopolitical context

The DIL Observatory maps cyber incidents, including ransomware attacks, data breaches, and cyber militia activity, alongside their geopolitical and social co...

SC Media →

Security Affairs Ransomware Intel Jun 1

Ransomware Operators Keep Business Hours. The Data Proves It

16,699 ransomware leak posts over 2 years show 84% drop Monday–Friday, peak at European afternoon hours. October spikes yearly.

Security Affairs →

Security Affairs Ransomware Intel Jun 1

Ransomware Operators Keep Business Hours. The Data Proves It

16,699 ransomware leak posts over 2 years show 84% drop Monday–Friday, peak at European afternoon hours. October spikes yearly.

Security Affairs →

1 2 3 ... 8 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA