Ransomware

Ransomware groups, affiliate programs, and the initial-access techniques feeding them, written up with detection and containment steps.

Other conventional threat types

Showing 1–15 of 15 threats, newest first

ransomwareextortionsocial-engineeringfrauddouble-extortionfake-recovery-service

A suspected ransomware affiliate is impersonating a legitimate data recovery firm called 'Ransom Busters,' contacting victims prior to public disclosure of breaches and offering fraudulent decryption keys and data deletion services for payment. This represents a secondary extortion layer that exploits victim desperation and confusion during active incident response, potentially resulting in double payment with no guarantee of data recovery or deletion.

Updated Aug 20, 2026

clopweb-shelldata-theftplmwindchillflexplmextortion

The Clop ransomware gang has deployed a custom Java-based web shell specifically engineered to target PTC Windchill and FlexPLM product lifecycle management servers. The tool is purpose-built to decrypt stored credentials, enumerate file repositories, and exfiltrate sensitive design and engineering data for extortion purposes. This represents an evolution in Clop's tactics toward targeted, application-specific tooling rather than generic ransomware payloads.

Updated Aug 19, 2026

ransomwareEDR-evasionsafe-modedata-exfiltrationakiradouble-extortion

An Akira ransomware affiliate compromised a target network and rebooted a system into Safe Mode with Networking to disable endpoint detection and response (EDR) protections. The attacker successfully exfiltrated data but failed to deploy the encryption payload, resulting in a partial (extortion-only) compromise rather than full ransomware impact.

Updated Aug 14, 2026

ransomwareblockchaindata-leakresilient-infrastructuredecentralized-C2extortion

DeadLock is a ransomware operation that leverages blockchain-backed decentralized infrastructure to host its victim communication portals and data-leak sites, making takedown efforts by law enforcement and security researchers significantly more difficult. This resilience model represents an evolving trend among ransomware groups seeking to evade traditional infrastructure disruption tactics.

Updated Aug 12, 2026

ransomwarechina-linkedstorm-1175n-centralrmm-exploitationdouble-extortion

Microsoft has identified Storm-1175, a financially motivated China-linked threat actor, deploying a new ransomware strain called StormEncryptor, marking a shift from their prior use of Medusa ransomware. Initial access is suspected to involve exploitation of a flaw in N-central, a remote monitoring and management (RMM) platform commonly used by MSPs to administer client endpoints and infrastructure.

Updated Aug 11, 2026

ransomwarelaw-enforcementsentencingcybercrimeransom-cartel

Maksim Silnikau, creator and administrator of the Ransom Cartel ransomware operation, has been sentenced to 16 years in prison for orchestrating attacks against at least 18 companies worldwide. This is a law enforcement outcome rather than an active ongoing threat, though affiliates and derivative variants of the ransomware family may still pose risk to organizations that have not fully remediated prior infections.

Updated Aug 6, 2026

ransomwareVPNSonicWallexploitationdata-leak-siteedge-deviceinitial-accessagent-relevant

The INC Ransomware group has become the dominant threat actor exploiting recently disclosed vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances, with a sharp increase in activity since early August 2026. Multiple victims have already been listed on the group's data leak site, indicating active and successful exploitation in the wild.

Updated Aug 4, 2026

ransomware-as-a-serviceRaaSaffiliate-modelDevManFunky MantisPRODAFTextortion

DevMan is a ransomware-as-a-service operation running a centralized web portal that lets affiliates build custom payloads, track victim status, and manage payouts. PRODAFT is tracking the broader operator infrastructure under the name Funky Mantis, indicating a structured, business-like criminal enterprise lowering the barrier to entry for ransomware deployment. The centralized tooling suggests active recruitment and scaling of affiliates, increasing the likely volume and diversity of attacks.

Updated Jul 27, 2026

Cl0pFIN11ransomwaredata-extortionPLMRCEpre-authPTC-WindchillFlexPLM

Cl0p-affiliated threat actors (FIN11, Graceful Spider, Lace Tempest) are exploiting internet-exposed PTC Windchill and FlexPLM PLM software through a chained vulnerability enabling unauthenticated remote code execution. The campaign appears focused on data theft and extortion rather than traditional file encryption, consistent with Cl0p's established MO of mass exploitation of enterprise file transfer and PLM platforms.

Updated Jul 27, 2026

ransomwareextortionsupply-chainthird-party-riskmanufacturingrail-industryEverest-gang

Swiss rail vehicle manufacturer Stadler Rail was targeted by the Everest ransomware gang, which breached a data exchange platform shared with one of its suppliers and demanded a $12.3 million ransom. Stadler rejected the demand, indicating the attack likely originated through a third-party or supplier-connected system rather than Stadler's core infrastructure.

Updated Jul 23, 2026

ransomwaremanufacturingOT-disruptionfood-and-beveragesupply-chain-disruptioncritical-infrastructure

Coca-Cola disclosed that a ransomware attack against its Fairlife dairy subsidiary has disrupted operations, forcing a temporary suspension of Fairlife product manufacturing across the United States. The incident highlights continued targeting of large food and beverage manufacturers by ransomware operators seeking to leverage operational disruption for extortion leverage.

Updated Jul 17, 2026

ryukransomwarelegal-actioncybercrimelaw-enforcement

An Armenian national has pleaded guilty in U.S. federal court to participating in Ryuk ransomware attacks against American companies, facing up to 15 years in prison. This is a legal/law enforcement development rather than a new active threat campaign, though it underscores the continued prosecution of Ryuk-affiliated actors.

Updated Jul 11, 2026

malwareransomwarephishingmodular-frameworkcredential-theftlateral-movementCrownXagent-relevant

Researchers have identified Avalon, a previously undocumented modular malware framework distributed via a multi-stage phishing chain designed to evade traditional security controls. The framework integrates credential harvesting, lateral movement, remote access, backup/recovery disruption, and ransomware deployment (CrownX) into a single unified toolkit, making it a versatile end-to-end intrusion and extortion platform.

Updated Jul 6, 2026

ransomwareransomware-as-a-serviceaffiliate-recruitmentattributioncybercrimedouble-extortion

The Gentlemen is a rapidly growing ransomware-as-a-service (RaaS) operation that has become the second most active ransomware gang by victim count, driven by an aggressive affiliate recruitment strategy offering 90% of ransom proceeds. Investigative reporting by Krebs on Security examines OSINT clues pointing to the real-world identity of the group's administrator, highlighting the operational and personal risks facing RaaS operators as attribution efforts intensify.

Updated Jul 5, 2026

RansomwareHealthcareRaaS

Fourth-generation LockBit ransomware-as-a-service with enhanced encryption completing full-disk encryption in under four minutes. Actively targeting hospitals, municipal governments, and manufacturing.

Updated Jul 3, 2026 · CVSS 9.8