Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-20 · 02:03 UTC
articleTotal: 593 reports

Filtered Reports

23 / 23 results
Active filter:tag: #ransomware✕ clear
Armenia Detains Russian National on U.S. REvil Ransomware Warranthighperson_alertThreat Actor
person_alertThreat Actor

Armenia Detains Russian National on U.S. REvil Ransomware Warrant

REvil (also known as Sodinokibi) is a Russia-linked ransomware-as-a-service (RaaS) operation that emerged in 2019 and became one of the most prolific cybercrime groups before law enforcement disruption in 2021-2022.

The Hacker News08:53 UTC
JadePuffer: First LLM-Driven Ransomware Operation Documentedhighperson_alertThreat Actor
person_alertThreat Actor

JadePuffer: First LLM-Driven Ransomware Operation Documented

JadePuffer is a ransomware family representing the first documented instance of a ransomware operation conducted entirely by a large language model (LLM) agent.

BleepingComputer12:16 UTC
Avalon Modular Malware Framework Delivers CrownX Ransomwarehighperson_alertThreat Actor
person_alertThreat Actor

Avalon Modular Malware Framework Delivers CrownX Ransomware

Avalon is a previously undocumented modular malware framework discovered by cybersecurity researchers. The framework is distributed through multi-stage phishing campaigns and represents a comprehensive attack platform integrating multiple offensive c…

The Hacker News16:55 UTC
Anubis Ransomware Exploits Citrix Bleed 2 (CVE-2025-5777) for Accesshighperson_alertThreat Actor
person_alertThreat Actor

Anubis Ransomware Exploits Citrix Bleed 2 (CVE-2025-5777) for Access

Anubis is a threat actor group operating the Anubis ransomware. The group demonstrates sophisticated tradecraft by exploiting recent vulnerabilities in enterprise infrastructure to gain initial access.

CVE-2025-577716:30 UTC
JADEPUFFER: First AI-Agent-Orchestrated Ransomware Attackcriticalperson_alertThreat Actor
person_alertThreat Actor

JADEPUFFER: First AI-Agent-Orchestrated Ransomware Attack

JADEPUFFER is a threat actor identified by Sysdig as the operator behind what is claimed to be the first fully AI-agent-orchestrated ransomware attack. The actor leveraged artificial intelligence agents to automate the entire attack lifecycle, repres…

Langflow07:13 UTC
DeepSeek AI Used to Generate Novel Browser-Based Ransomwarehighperson_alertThreat Actor
person_alertThreat Actor

DeepSeek AI Used to Generate Novel Browser-Based Ransomware

DeepSeek refers to the AI model leveraged by unknown threat actors to generate functional browser-based ransomware code. This marks the first documented instance of a frontier AI model being weaponized to create a novel ransomware technique.

Chromium10:59 UTC
Edgecution: Malicious Edge Extension Enables Sandbox Escapehighperson_alertThreat Actor
person_alertThreat Actor

Edgecution: Malicious Edge Extension Enables Sandbox Escape

Edgecution is a malicious browser extension targeting Microsoft Edge, not a threat actor group. It functions as a tool deployed during ransomware operations to facilitate sandbox escape and establish persistence.

Microsoft18:58 UTC
Dual ransomware actors operate simultaneously in Microsoft environmentshighbug_reportVulnerability
bug_reportVulnerability

Dual ransomware actors operate simultaneously in Microsoft environments

Organizations using Microsoft environments, particularly those with insufficient network segmentation and endpoint visibility. No specific product vulnerability; threat involves operational security gaps enabling parallel intrusions.

Microsoft14:00 UTC
Prinz Eugen ransomware targets recently modified files, omits ransom notehighperson_alertThreat Actor
person_alertThreat Actor

Prinz Eugen ransomware targets recently modified files, omits ransom note

Prinz Eugen is a newly identified ransomware family characterized by unconventional operational tactics. Unlike traditional ransomware operations that encrypt files indiscriminately and leave detailed ransom notes, Prinz Eugen employs a selective enc…

BleepingComputer13:23 UTC
Gentlemen RaaS Deploys GentleKiller EDR Evasion Frameworkhighperson_alertThreat Actor
person_alertThreat Actor

Gentlemen RaaS Deploys GentleKiller EDR Evasion Framework

Gentlemen is a ransomware-as-a-service (RaaS) operation that provides infrastructure, tooling, and support to affiliate threat actors. The group actively develops and distributes specialized frameworks to enhance affiliate success rates, including th…

The Hacker News16:33 UTC
Gentlemen RaaS Develops EDR Killer Tools for Affiliate Operationshighperson_alertThreat Actor
person_alertThreat Actor

Gentlemen RaaS Develops EDR Killer Tools for Affiliate Operations

Gentlemen is a ransomware-as-a-service (RaaS) operation that provides infrastructure, tools, and support to affiliate threat actors who conduct ransomware attacks.

BleepingComputer20:31 UTC
INC Ransomware Expands Operations Following LockBit and BlackCat Disruptionshighperson_alertThreat Actor
person_alertThreat Actor

INC Ransomware Expands Operations Following LockBit and BlackCat Disruptions

INC is a ransomware-as-a-service (RaaS) operation that has emerged as a major threat actor since August 2023. The group operates a multi-affiliate model, providing ransomware tooling and infrastructure to criminal partners in exchange for a share of…

The Hacker News12:12 UTC
DragonForce Deploys Backdoor.Turn RAT via Microsoft Teams Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

DragonForce Deploys Backdoor.Turn RAT via Microsoft Teams Infrastructure

DragonForce is a threat actor associated with ransomware operations. The group has demonstrated advanced capabilities in developing custom tooling and leveraging legitimate cloud infrastructure for command-and-control communications.

Microsoft11:30 UTC
DragonForce Ransomware Gang Deploys Backdoor.Turn via Teams Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

DragonForce Ransomware Gang Deploys Backdoor.Turn via Teams Infrastructure

DragonForce is a ransomware gang that has developed custom tooling to support their extortion operations. The group demonstrates advanced capabilities in developing bespoke malware and leveraging legitimate cloud infrastructure for command-and-contro…

Microsoft08:18 UTC
Conti Operator Pleads Guilty After Extradition to United Stateshighperson_alertThreat Actor
person_alertThreat Actor

Conti Operator Pleads Guilty After Extradition to United States

Conti is a prolific ransomware-as-a-service (RaaS) operation that emerged in 2020 and became one of the most active and financially successful cybercrime groups before its infrastructure was leaked and operations fragmented in 2022.

BleepingComputer15:54 UTC
Europol Disrupts AudiA6 Cryptocurrency Laundering Servicehighperson_alertThreat Actor
person_alertThreat Actor

Europol Disrupts AudiA6 Cryptocurrency Laundering Service

AudiA6 was a cryptocurrency laundering service utilized by ransomware gangs and cybercriminal networks to obfuscate and legitimize illicit proceeds. The service facilitated the conversion and movement of cryptocurrency obtained through ransomware ope…

The Hacker News04:38 UTC
The Gentlemen ransomware group claims 478 victims via multi-RaaS modelhighperson_alertThreat Actor
person_alertThreat Actor

The Gentlemen ransomware group claims 478 victims via multi-RaaS model

The Gentlemen is a financially motivated ransomware threat group that has claimed 478 victims through a hybrid operational model. Initially operating as an affiliate leveraging multiple ransomware-as-a-service (RaaS) platforms—including LockBit, Qili…

The Hacker News14:50 UTC
Law Enforcement Dismantles AudiA6 Cryptocurrency Laundering Servicehighperson_alertThreat Actor
person_alertThreat Actor

Law Enforcement Dismantles AudiA6 Cryptocurrency Laundering Service

AudiA6 was a cryptocurrency laundering service that facilitated money laundering operations for ransomware actors and other cybercriminals. The service allegedly processed over $380 million in illicit proceeds before being dismantled by law enforceme…

BleepingComputer13:55 UTC
The Gentlemen Ransomware: Aggressive Affiliate Model Drives Rapid Growthhighperson_alertThreat Actor
person_alertThreat Actor

The Gentlemen Ransomware: Aggressive Affiliate Model Drives Rapid Growth

The Gentlemen is a ransomware-as-a-service (RaaS) operation that has rapidly ascended to become the second most active ransomware group by victim count.

Krebs on Security12:03 UTC
Storm-2697 Deploys The Gentlemen Go-Based Ransomware with Worm Capabilitieshighperson_alertThreat Actor
person_alertThreat Actor

Storm-2697 Deploys The Gentlemen Go-Based Ransomware with Worm Capabilities

Storm-2697 is a threat actor tracked by Microsoft Threat Intelligence that operates as a ransomware affiliate group. The actor deploys The Gentlemen ransomware, a sophisticated Go-based encryption tool, suggesting technical proficiency in modern prog…

Microsoft13:00 UTC
International Law Enforcement Seizes First VPN Service Used by Cybercriminalshighperson_alertThreat Actor
person_alertThreat Actor

International Law Enforcement Seizes First VPN Service Used by Cybercriminals

First VPN was a commercial VPN service exploited by multiple threat actors to anonymize their operations. The service provided infrastructure enabling cybercriminals to mask their origin during ransomware deployments and data exfiltration campaigns.

BleepingComputer11:09 UTC
Fox Tempest Provides Malware-Signing Services to Ransomware Operatorshighperson_alertThreat Actor
person_alertThreat Actor

Fox Tempest Provides Malware-Signing Services to Ransomware Operators

Fox Tempest is a financially motivated cybercriminal actor that operates as a malware-signing service provider within the ransomware ecosystem. Rather than conducting attacks directly, Fox Tempest enables other threat actors—including Vanilla Tempest…

Microsoft Security13:07 UTC
Ransomware Campaigns Target Slovenia via Email, RDP, and Exploitshighperson_alertThreat Actor
person_alertThreat Actor

Ransomware Campaigns Target Slovenia via Email, RDP, and Exploits

Unattributed ransomware operators targeting Slovenia. Motivation appears financially driven, consistent with commodity ransomware campaigns. No specific actor attribution available; likely represents multiple threat groups employing common ransomware…

SI-CERT (Slovenia)08:32 UTC