Understanding the Emerging Threat of “Helldown Ransomware”

CategoryDetailsThreat ActorsHelldown Ransomware groupCampaign OverviewRecently expanded to target Linux systems in addition to Windows; employs…

OSINT Updates for November 19 , 2024

https://twitter.com/MachinaRecord/status/1858714358534336790 https://twitter.com/MachinaRecord/status/1858704546748658035 https://twitter.com/MachinaRecord/status/1858684648391668071 https://twitter.com/DarkWebVc/status/1858798998829801905 https://twitter.com/cyberfeeddigest/status/1858790761090723894 https://twitter.com/marktsec46065/status/1858764345842323575

Lynx Ransomware Threat Intel

CategoryDetailsThreat ActorsLynx ransomware group, Successor to INC ransomware group.Campaign OverviewEmerged in 2024; ransomware-as-a-service (RaaS) model;…

BLACK BASTA : RANSOMWARE

CategoryDetailsThreat ActorsBlack Basta (Ransomware-as-a-Service Group)Campaign OverviewOperates via phishing, vulnerability exploitation, social engineering (Microsoft Teams impersonation).…

Russian National in US custody in Phobos ransomware investigation

Category Details Threat Actors Phobos ransomware operators, including alleged administrator Evgenii Ptitsyn (aliases: "derxan" and…

Ransomware Gang Akira leaks unprecedented number of victims’ data in one day

Category Details Threat Actors Akira ransomware Group (Ransomware-as-a-Service). Campaign Overview Published data from 35 victims…

Ransomware Group called Hunters Claims attack for Mantinga.

CategoryDetailsThreat ActorsHunters International ( Acquired the Hive source code and website from the Original Developers. )Campaign…

OSINT Updates for November 18, 2024

https://twitter.com/marktsec46065/status/1858429053016912154 https://twitter.com/Ethic10Hackz/status/1858425229480976418 https://twitter.com/FalconFeedsio/status/1858299994794795372 https://twitter.com/DailyRansomware/status/1858422637107560596 https://twitter.com/fuxsociety1337/status/1858362542810190332 https://twitter.com/OSINTMilitia/status/1858371638452011326

Dissecting Sodinokibi Ransomware Attacks: Bringing Incident Response and Intelligence Together in the Fight

Category Details Threat Actors Sodinokibi (REvil), QakBot operators, Valak operators, Ransomware affiliates Campaign Overview Ransomware…

Threat actor believed to be spreading new MedusaLocker variant since 2022

CategoryDetailsThreat ActorsFinancially motivated group, possibly an Initial Access Broker (IAB) or affiliate of a ransomware…