New Ransomware Brand Galago Claims Ties to the Panzer Group, but Proof Is Thin So Far
A newly spotted ransomware operation calling itself Galago has surfaced with claimed links to the more established Panzer group, including an alleged 105GB theft from an Icelandic healthcare...
Extradited Ryuk Ransomware Conspirator Sentenced to Federal Prison in Oregon Case
Karen Vardanyan, an Armenian national extradited from Ukraine, has been sentenced to 24 months in federal prison and ordered to pay more than $1.2 million in restitution for...
PAYLOAD Group Weaponizes Windows Group Policy to Take Down an Entire Domain Without Touching a Single File
A ransomware crew calling itself PAYLOAD breached a Middle Eastern manufacturer's Windows domain and disrupted it enterprise-wide using nothing but malicious Group Policy Objects — no encryption, no...
ENCFORGE Ransomware Targets the Models, Datasets and Vector Stores Behind AI
The JADEPUFFER threat actor has progressed from improvised database destruction to ENCFORGE, ransomware built to encrypt AI models, datasets and vector indexes. Defenders need runtime detection and recovery...
Feral Wolf Ransomware Exploits Confluence and Exposed 1C Systems to Breach Networks
Feral Wolf ransomware operators are chaining known Confluence flaws, weak database credentials, and exposed 1C management services to penetrate Russian organizations. The intrusions combine custom backdoors, credential theft,...
Attackers Are Quietly Cloning Domain Controllers’ Password Database — Then Deleting the Evidence
Incident responders at Huntress have documented a stealthy attack pattern in which intruders use Windows' own shadow-copy tooling to clone and steal the Active Directory password database, then...
Mantax Otax Android Ransomware Adds Screen Spying, OTP Theft and Covert Photos
New Android malware called Mantax Otax combines file encryption with surveillance, credential theft, screen recording and covert camera access. The campaign relies on sideloaded APKs and appears focused...
Inside ‘The Gentlemen’: The Ransomware Operation That Can Take Down a Network Before Lunch
A ransomware-as-a-service operation dubbed 'The Gentlemen' by researchers is compromising networks and detonating encryption in as little as 24 hours, methodically disabling backups and security tooling before attackers...