Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

20 / 50 results
Active filter:tag: #ransomware✕ clear
Anubis Ransomware Exploits Citrix Bleed 2 (CVE-2025-5777) for Accesshighperson_alertThreat Actor
person_alertThreat Actor

Anubis Ransomware Exploits Citrix Bleed 2 (CVE-2025-5777) for Access

Anubis is a threat actor group operating the Anubis ransomware. The group demonstrates sophisticated tradecraft by exploiting recent vulnerabilities in enterprise infrastructure to gain initial access.

CVE-2025-57772 Jul · 16:30 UTC
JADEPUFFER: First AI-Agent-Orchestrated Ransomware Attackcriticalperson_alertThreat Actor
person_alertThreat Actor

JADEPUFFER: First AI-Agent-Orchestrated Ransomware Attack

JADEPUFFER is a threat actor identified by Sysdig as the operator behind what is claimed to be the first fully AI-agent-orchestrated ransomware attack. The actor leveraged artificial intelligence agents to automate the entire attack lifecycle, repres…

Langflow2 Jul · 07:13 UTC
DeepSeek AI Used to Generate Novel Browser-Based Ransomwarehighperson_alertThreat Actor
person_alertThreat Actor

DeepSeek AI Used to Generate Novel Browser-Based Ransomware

DeepSeek refers to the AI model leveraged by unknown threat actors to generate functional browser-based ransomware code. This marks the first documented instance of a frontier AI model being weaponized to create a novel ransomware technique.

Chromium1 Jul · 10:59 UTC
Edgecution: Malicious Edge Extension Enables Sandbox Escapehighperson_alertThreat Actor
person_alertThreat Actor

Edgecution: Malicious Edge Extension Enables Sandbox Escape

Edgecution is a malicious browser extension targeting Microsoft Edge, not a threat actor group. It functions as a tool deployed during ransomware operations to facilitate sandbox escape and establish persistence.

Microsoft24 Jun · 18:58 UTC
Dual ransomware actors operate simultaneously in Microsoft environmentshighbug_reportVulnerability
bug_reportVulnerability

Dual ransomware actors operate simultaneously in Microsoft environments

Organizations using Microsoft environments, particularly those with insufficient network segmentation and endpoint visibility. No specific product vulnerability; threat involves operational security gaps enabling parallel intrusions.

Microsoft22 Jun · 14:00 UTC
Prinz Eugen ransomware targets recently modified files, omits ransom notehighperson_alertThreat Actor
person_alertThreat Actor

Prinz Eugen ransomware targets recently modified files, omits ransom note

Prinz Eugen is a newly identified ransomware family characterized by unconventional operational tactics. Unlike traditional ransomware operations that encrypt files indiscriminately and leave detailed ransom notes, Prinz Eugen employs a selective enc…

BleepingComputer20 Jun · 13:23 UTC
Gentlemen RaaS Deploys GentleKiller EDR Evasion Frameworkhighperson_alertThreat Actor
person_alertThreat Actor

Gentlemen RaaS Deploys GentleKiller EDR Evasion Framework

Gentlemen is a ransomware-as-a-service (RaaS) operation that provides infrastructure, tooling, and support to affiliate threat actors. The group actively develops and distributes specialized frameworks to enhance affiliate success rates, including th…

The Hacker News19 Jun · 16:33 UTC
Gentlemen RaaS Develops EDR Killer Tools for Affiliate Operationshighperson_alertThreat Actor
person_alertThreat Actor

Gentlemen RaaS Develops EDR Killer Tools for Affiliate Operations

Gentlemen is a ransomware-as-a-service (RaaS) operation that provides infrastructure, tools, and support to affiliate threat actors who conduct ransomware attacks.

BleepingComputer18 Jun · 20:31 UTC
INC Ransomware Expands Operations Following LockBit and BlackCat Disruptionshighperson_alertThreat Actor
person_alertThreat Actor

INC Ransomware Expands Operations Following LockBit and BlackCat Disruptions

INC is a ransomware-as-a-service (RaaS) operation that has emerged as a major threat actor since August 2023. The group operates a multi-affiliate model, providing ransomware tooling and infrastructure to criminal partners in exchange for a share of…

The Hacker News18 Jun · 12:12 UTC
DragonForce Deploys Backdoor.Turn RAT via Microsoft Teams Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

DragonForce Deploys Backdoor.Turn RAT via Microsoft Teams Infrastructure

DragonForce is a threat actor associated with ransomware operations. The group has demonstrated advanced capabilities in developing custom tooling and leveraging legitimate cloud infrastructure for command-and-control communications.

Microsoft18 Jun · 11:30 UTC
DragonForce Ransomware Gang Deploys Backdoor.Turn via Teams Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

DragonForce Ransomware Gang Deploys Backdoor.Turn via Teams Infrastructure

DragonForce is a ransomware gang that has developed custom tooling to support their extortion operations. The group demonstrates advanced capabilities in developing bespoke malware and leveraging legitimate cloud infrastructure for command-and-contro…

Microsoft16 Jun · 08:18 UTC
Conti Operator Pleads Guilty After Extradition to United Stateshighperson_alertThreat Actor
person_alertThreat Actor

Conti Operator Pleads Guilty After Extradition to United States

Conti is a prolific ransomware-as-a-service (RaaS) operation that emerged in 2020 and became one of the most active and financially successful cybercrime groups before its infrastructure was leaked and operations fragmented in 2022.

BleepingComputer12 Jun · 15:54 UTC
Europol Disrupts AudiA6 Cryptocurrency Laundering Servicehighperson_alertThreat Actor
person_alertThreat Actor

Europol Disrupts AudiA6 Cryptocurrency Laundering Service

AudiA6 was a cryptocurrency laundering service utilized by ransomware gangs and cybercriminal networks to obfuscate and legitimize illicit proceeds. The service facilitated the conversion and movement of cryptocurrency obtained through ransomware ope…

The Hacker News12 Jun · 04:38 UTC
The Gentlemen ransomware group claims 478 victims via multi-RaaS modelhighperson_alertThreat Actor
person_alertThreat Actor

The Gentlemen ransomware group claims 478 victims via multi-RaaS model

The Gentlemen is a financially motivated ransomware threat group that has claimed 478 victims through a hybrid operational model. Initially operating as an affiliate leveraging multiple ransomware-as-a-service (RaaS) platforms—including LockBit, Qili…

The Hacker News11 Jun · 14:50 UTC
Law Enforcement Dismantles AudiA6 Cryptocurrency Laundering Servicehighperson_alertThreat Actor
person_alertThreat Actor

Law Enforcement Dismantles AudiA6 Cryptocurrency Laundering Service

AudiA6 was a cryptocurrency laundering service that facilitated money laundering operations for ransomware actors and other cybercriminals. The service allegedly processed over $380 million in illicit proceeds before being dismantled by law enforceme…

BleepingComputer11 Jun · 13:55 UTC
The Gentlemen Ransomware: Aggressive Affiliate Model Drives Rapid Growthhighperson_alertThreat Actor
person_alertThreat Actor

The Gentlemen Ransomware: Aggressive Affiliate Model Drives Rapid Growth

The Gentlemen is a ransomware-as-a-service (RaaS) operation that has rapidly ascended to become the second most active ransomware group by victim count.

Krebs on Security10 Jun · 12:03 UTC
Storm-2697 Deploys The Gentlemen Go-Based Ransomware with Worm Capabilitieshighperson_alertThreat Actor
person_alertThreat Actor

Storm-2697 Deploys The Gentlemen Go-Based Ransomware with Worm Capabilities

Storm-2697 is a threat actor tracked by Microsoft Threat Intelligence that operates as a ransomware affiliate group. The actor deploys The Gentlemen ransomware, a sophisticated Go-based encryption tool, suggesting technical proficiency in modern prog…

Microsoft28 May · 13:00 UTC
International Law Enforcement Seizes First VPN Service Used by Cybercriminalshighperson_alertThreat Actor
person_alertThreat Actor

International Law Enforcement Seizes First VPN Service Used by Cybercriminals

First VPN was a commercial VPN service exploited by multiple threat actors to anonymize their operations. The service provided infrastructure enabling cybercriminals to mask their origin during ransomware deployments and data exfiltration campaigns.

BleepingComputer21 May · 11:09 UTC
Fox Tempest Provides Malware-Signing Services to Ransomware Operatorshighperson_alertThreat Actor
person_alertThreat Actor

Fox Tempest Provides Malware-Signing Services to Ransomware Operators

Fox Tempest is a financially motivated cybercriminal actor that operates as a malware-signing service provider within the ransomware ecosystem. Rather than conducting attacks directly, Fox Tempest enables other threat actors—including Vanilla Tempest…

Microsoft Security19 May · 13:07 UTC
Ransomware Campaigns Target Slovenia via Email, RDP, and Exploitshighperson_alertThreat Actor
person_alertThreat Actor

Ransomware Campaigns Target Slovenia via Email, RDP, and Exploits

Unattributed ransomware operators targeting Slovenia. Motivation appears financially driven, consistent with commodity ransomware campaigns. No specific actor attribution available; likely represents multiple threat groups employing common ransomware…

SI-CERT (Slovenia)19 Jan · 08:32 UTC