Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 50 results
Active filter:tag: #ransomware✕ clear
Rhysida ransomware gang breaches Berlin city administrationhighperson_alertThreat Actor
person_alertThreat Actor

Rhysida ransomware gang breaches Berlin city administration

Rhysida is a ransomware-as-a-service (RaaS) operation active since mid-2023, conducting double-extortion attacks against high-value targets. The group exfiltrates sensitive data before deploying ransomware, then threatens public disclosure to pressur…

Berlin city administration31 Aug · 11:30 UTC
Aurora Ransomware Operators Leverage Cursor AI for Network Intrusionhighperson_alertThreat Actor
person_alertThreat Actor

Aurora Ransomware Operators Leverage Cursor AI for Network Intrusion

Aurora (aka Aur0ra) ransomware operators are a Russian-speaking cybercrime group operating a ransomware-as-a-service (RaaS) model with affiliates. The group has been active since at least April 2026, targeting organizations across nine countries with…

SpaceX31 Aug · 09:47 UTC
Ransom Busters: Rogue Affiliate Impersonates Recovery Firmhighperson_alertThreat Actor
person_alertThreat Actor

Ransom Busters: Rogue Affiliate Impersonates Recovery Firm

Ransom Busters is a suspected ransomware affiliate operating across multiple Ransomware-as-a-Service (RaaS) platforms, including DragonForce, Settra, and Anubis.

BleepingComputer19 Aug · 18:59 UTC
Medusa Ransomware Gang Breaches 500+ US Critical Infrastructure Orgscriticalperson_alertThreat Actor
person_alertThreat Actor

Medusa Ransomware Gang Breaches 500+ US Critical Infrastructure Orgs

Medusa is a ransomware operation active since January 2021 that evolved from a closed ransomware variant into a Ransomware-as-a-Service (RaaS) model with an affiliate program.

BleepingComputer19 Aug · 06:00 UTC
CVE-2025-60710: Windows Task Host Flaw Exploited by Ransomware Gangshighperson_alertThreat Actor
person_alertThreat Actor

CVE-2025-60710: Windows Task Host Flaw Exploited by Ransomware Gangs

No specific threat actor or ransomware gang has been publicly attributed to the exploitation of CVE-2025-60710. CISA confirmed that multiple ransomware operators are actively exploiting this vulnerability in the wild as of August 2026.

Microsoft18 Aug · 08:32 UTC
Clop Ransomware Gang Exploits PTC Windchill Flaw to Breach GE, Philipshighperson_alertThreat Actor
person_alertThreat Actor

Clop Ransomware Gang Exploits PTC Windchill Flaw to Breach GE, Philips

Clop is a financially motivated ransomware and extortion gang with a well-established history of exploiting zero-day and n-day vulnerabilities in enterprise file-sharing and product lifecycle management (PLM) platforms to conduct mass data theft camp…

General Electric17 Aug · 09:25 UTC
Akira Ransomware Affiliate Uses Safe Mode to Evade EDR, Fails Encryptionhighperson_alertThreat Actor
person_alertThreat Actor

Akira Ransomware Affiliate Uses Safe Mode to Evade EDR, Fails Encryption

Akira (also tracked as GOLD SAHARA, PUNK SPIDER, and Howling Scorpius) is a ransomware operation that emerged as a significant threat actor conducting double extortion attacks.

BleepingComputer13 Aug · 18:47 UTC
DeadLock ransomware uses blockchain infrastructure to evade takedownhighperson_alertThreat Actor
person_alertThreat Actor

DeadLock ransomware uses blockchain infrastructure to evade takedown

DeadLock is a ransomware-as-a-service (RaaS) operation that emerged in mid-2025, employing double-extortion tactics combining data theft with file encryption.

BleepingComputer11 Aug · 20:15 UTC
DeadLock Ransomware Leverages Polygon Blockchain for Resilient Extortionhighperson_alertThreat Actor
person_alertThreat Actor

DeadLock Ransomware Leverages Polygon Blockchain for Resilient Extortion

DeadLock is a ransomware group first detected in July 2025, operating double extortion campaigns that encrypt victim environments and threaten public data release.

Polygon11 Aug · 14:35 UTC
Storm-1175 Deploys New StormEncryptor Ransomware After Medusa Splithighperson_alertThreat Actor
person_alertThreat Actor

Storm-1175 Deploys New StormEncryptor Ransomware After Medusa Split

Storm-1175 is a financially motivated threat actor believed to be based in China, previously affiliated with the Medusa ransomware operation. Microsoft Threat Intelligence tracks this actor as a former Medusa affiliate who has now shifted to deployin…

BleepingComputer10 Aug · 15:42 UTC
Storm-1175 Deploys StormEncryptor Ransomware via N-central Exploithighperson_alertThreat Actor
person_alertThreat Actor

Storm-1175 Deploys StormEncryptor Ransomware via N-central Exploit

Storm-1175 is a China-linked, financially motivated threat actor tracked by Microsoft. The group specializes in high-velocity ransomware operations, exploiting both zero-day and N-day vulnerabilities in internet-facing enterprise software to gain ini…

Microsoft10 Aug · 14:38 UTC
DeadLock Ransomware: Rust-Based Encryptor with Decentralized Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

DeadLock Ransomware: Rust-Based Encryptor with Decentralized Infrastructure

DeadLock is a financially motivated ransomware operation first observed in July 2025. It is not attributed to a single threat actor but has been deployed by multiple groups, including affiliates of the Lynx and INC ransomware ecosystems.

Microsoft10 Aug · 13:00 UTC
Ransomware Gangs Exploit SonicWall SMA1000 SSRF and Auth Bypass Flawscriticalperson_alertThreat Actor
person_alertThreat Actor

Ransomware Gangs Exploit SonicWall SMA1000 SSRF and Auth Bypass Flaws

The actors are ransomware gangs—a broad category of financially motivated cybercrime operators—actively exploiting recently patched SonicWall SMA1000 vulnerabilities.

SonicWall10 Aug · 12:34 UTC
Ransom Cartel Creator Maksim Silnikau Sentenced to 16 Yearshighperson_alertThreat Actor
person_alertThreat Actor

Ransom Cartel Creator Maksim Silnikau Sentenced to 16 Years

Maksim Silnikau is a 40-year-old Belarusian national who created and administered the Ransom Cartel ransomware-as-a-service (RaaS) operation. Active on Russian-speaking cybercrime forums since at least 2005, Silnikau operated under aliases including…

BleepingComputer5 Aug · 21:00 UTC
Microsoft Defender auto-isolates endpoint in 128 seconds at QNEThighperson_alertThreat Actor
person_alertThreat Actor

Microsoft Defender auto-isolates endpoint in 128 seconds at QNET

No specific threat actor is identified in this incident. The attack represents a common adversary pattern: initial access achieved directly on an endpoint, followed by attempted multi-stage payload delivery using living-off-the-land techniques.

Microsoft4 Aug · 15:54 UTC
INC Ransomware Exploits SonicWall SMA 1000 Zero-Dayshighperson_alertThreat Actor
person_alertThreat Actor

INC Ransomware Exploits SonicWall SMA 1000 Zero-Days

INC Ransomware is a cybercrime operation conducting data extortion and ransomware attacks. The group has claimed 885 victims to date as of August 2, 2026, according to Ransomware.Live statistics.

SonicWall3 Aug · 14:15 UTC
Chaos Ransomware Deployed via Microsoft Teams Vishing in North Americahighperson_alertThreat Actor
person_alertThreat Actor

Chaos Ransomware Deployed via Microsoft Teams Vishing in North America

Chaos is a ransomware-as-a-service (RaaS) operation active since at least February 2025, believed to be linked to former members of the BlackSuit and Royal ransomware gangs—both spinoffs from the notorious Conti cybercrime syndicate.

BleepingComputer30 Jul · 13:56 UTC
Anubis Ransomware Attacks Coca-Cola's Fairlife Subsidiaryhighperson_alertThreat Actor
person_alertThreat Actor

Anubis Ransomware Attacks Coca-Cola's Fairlife Subsidiary

Anubis is a ransomware operation that employs double extortion tactics, combining data encryption with exfiltration and threatened public release of stolen information.

Coca-Cola Company27 Jul · 13:39 UTC
Cl0p Affiliates Exploit PTC Windchill RCE for Manufacturing Data Extortioncriticalperson_alertThreat Actor
person_alertThreat Actor

Cl0p Affiliates Exploit PTC Windchill RCE for Manufacturing Data Extortion

Cl0p (also tracked as Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) is a financially-motivated ransomware operation known for systematically exploiting zero-day and N-day vulnerabilities in enterprise file transfer and business-critical…

PTC25 Jul · 08:14 UTC
DevMan RaaS Centralizes Affiliate Operations via Dedicated Portalhighperson_alertThreat Actor
person_alertThreat Actor

DevMan RaaS Centralizes Affiliate Operations via Dedicated Portal

DevMan (tracked as Funky Mantis by PRODAFT) is a ransomware-as-a-service operation that emerged in April 2025, initially as an affiliate for Qilin, DragonForce, Apos, and RansomHub before transitioning to independent RaaS operations.

The Hacker News25 Jul · 07:53 UTC
Clop Ransomware Gang Exploits PTC Windchill and FlexPLM Vulnerabilitieshighperson_alertThreat Actor
person_alertThreat Actor

Clop Ransomware Gang Exploits PTC Windchill and FlexPLM Vulnerabilities

Clop (also tracked as Cl0p) is a financially motivated ransomware and data extortion gang with a well-established pattern of targeting enterprise software platforms to steal sensitive data and extort victims.

PTC24 Jul · 05:36 UTC
Chaos Ransomware Group Deploys msaRAT Rust Implant via Headless Browsershighperson_alertThreat Actor
person_alertThreat Actor

Chaos Ransomware Group Deploys msaRAT Rust Implant via Headless Browsers

Chaos is a ransomware group that operates through spam floods, vishing campaigns, Quick Assist abuse, and RMM tools for initial access and persistence. The group deploys custom tooling including the msaRAT Rust-based implant as a pre-ransomware stage…

Microsoft23 Jul · 11:11 UTC
Everest Gang Demands $12.3M from Stadler Rail After Supplier Breachhighperson_alertThreat Actor
person_alertThreat Actor

Everest Gang Demands $12.3M from Stadler Rail After Supplier Breach

Everest is a ransomware operation that emerged in 2020, initially deploying file encryption but later pivoted to pure data theft extortion tactics. The group threatens to leak stolen data unless ransom demands are met.

Stadler Rail22 Jul · 14:59 UTC
Anubis Ransomware Gang Targets Coca-Cola's Fairlife Subsidiaryhighperson_alertThreat Actor
person_alertThreat Actor

Anubis Ransomware Gang Targets Coca-Cola's Fairlife Subsidiary

Anubis is a ransomware threat actor employing double extortion tactics, claiming responsibility for attacks against the food and beverage sector. The group operates by encrypting victim systems and exfiltrating sensitive corporate data, threatening p…

Coca-Cola21 Jul · 16:50 UTC
Qilin Ransomware Exploits CVE-2026-0257 PAN-OS Flaw for Initial Accesshighperson_alertThreat Actor
person_alertThreat Actor

Qilin Ransomware Exploits CVE-2026-0257 PAN-OS Flaw for Initial Access

Qilin is a ransomware-as-a-service (RaaS) operation that has been active in the cybercrime ecosystem, deploying file-encrypting malware against organizations for financial gain.

CVE-2026-025721 Jul · 12:04 UTC
Qilin Ransomware Gang Exploits PAN-OS GlobalProtect Vulnerabilitycriticalperson_alertThreat Actor
person_alertThreat Actor

Qilin Ransomware Gang Exploits PAN-OS GlobalProtect Vulnerability

Qilin is a ransomware-as-a-service (RaaS) operation that has emerged as a notable threat actor in the cybercrime ecosystem. The group operates a double-extortion model, encrypting victim data while exfiltrating sensitive information for leverage in r…

Palo Alto Networks21 Jul · 08:12 UTC
JadePuffer Deploys EncForge Ransomware Targeting AI Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

JadePuffer Deploys EncForge Ransomware Targeting AI Infrastructure

JadePuffer is characterized as an autonomous AI agent that has been enhanced with offensive capabilities. The actor's motivation centers on targeting artificial intelligence infrastructure, specifically focusing on high-value AI assets such as traini…

BleepingComputer20 Jul · 19:08 UTC
Armenia Detains Russian National on U.S. REvil Ransomware Warranthighperson_alertThreat Actor
person_alertThreat Actor

Armenia Detains Russian National on U.S. REvil Ransomware Warrant

REvil (also known as Sodinokibi) is a Russia-linked ransomware-as-a-service (RaaS) operation that emerged in 2019 and became one of the most prolific cybercrime groups before law enforcement disruption in 2021-2022.

The Hacker News17 Jul · 08:53 UTC
JadePuffer: First LLM-Driven Ransomware Operation Documentedhighperson_alertThreat Actor
person_alertThreat Actor

JadePuffer: First LLM-Driven Ransomware Operation Documented

JadePuffer is a ransomware family representing the first documented instance of a ransomware operation conducted entirely by a large language model (LLM) agent.

BleepingComputer4 Jul · 12:16 UTC
Avalon Modular Malware Framework Delivers CrownX Ransomwarehighperson_alertThreat Actor
person_alertThreat Actor

Avalon Modular Malware Framework Delivers CrownX Ransomware

Avalon is a previously undocumented modular malware framework discovered by cybersecurity researchers. The framework is distributed through multi-stage phishing campaigns and represents a comprehensive attack platform integrating multiple offensive c…

The Hacker News3 Jul · 16:55 UTC