PAYLOAD Group Weaponizes Windows Group Policy to Take Down an Entire Domain Without Touching a Single File
A ransomware crew calling itself PAYLOAD breached a Middle Eastern manufacturer's Windows domain and disrupted it enterprise-wide using nothing but malicious Group Policy Objects — no encryption, no...
ENCFORGE Ransomware Targets the Models, Datasets and Vector Stores Behind AI
The JADEPUFFER threat actor has progressed from improvised database destruction to ENCFORGE, ransomware built to encrypt AI models, datasets and vector indexes. Defenders need runtime detection and recovery...
Feral Wolf Ransomware Exploits Confluence and Exposed 1C Systems to Breach Networks
Feral Wolf ransomware operators are chaining known Confluence flaws, weak database credentials, and exposed 1C management services to penetrate Russian organizations. The intrusions combine custom backdoors, credential theft,...
Attackers Are Quietly Cloning Domain Controllers’ Password Database — Then Deleting the Evidence
Incident responders at Huntress have documented a stealthy attack pattern in which intruders use Windows' own shadow-copy tooling to clone and steal the Active Directory password database, then...
Mantax Otax Android Ransomware Adds Screen Spying, OTP Theft and Covert Photos
New Android malware called Mantax Otax combines file encryption with surveillance, credential theft, screen recording and covert camera access. The campaign relies on sideloaded APKs and appears focused...
Inside ‘The Gentlemen’: The Ransomware Operation That Can Take Down a Network Before Lunch
A ransomware-as-a-service operation dubbed 'The Gentlemen' by researchers is compromising networks and detonating encryption in as little as 24 hours, methodically disabling backups and security tooling before attackers...
TukTuk Malware Gives Ransomware Crews Cross-Platform Control and EDR-Killing Tools
Researchers recovered a previously undocumented command-and-control framework linked to the Gentlemen ransomware ecosystem. TukTuk supports Windows and Linux agents, credential prompts, screen capture, remote commands, and preparation for...
TITAN Ransomware Claims Its AI Can Sift 700GB of Stolen Data an Hour to Maximize Extortion
A relatively new ransomware-as-a-service operation called TITAN is marketing an AI-powered analysis platform that it says can classify and mine stolen corporate data at 700GB per hour, helping...