Inside ‘The Gentlemen’: The Ransomware Operation That Can Take Down a Network Before Lunch
A ransomware-as-a-service operation dubbed 'The Gentlemen' by researchers is compromising networks and detonating encryption in as little as 24 hours, methodically disabling backups and security tooling before attackers...
TukTuk Malware Gives Ransomware Crews Cross-Platform Control and EDR-Killing Tools
Researchers recovered a previously undocumented command-and-control framework linked to the Gentlemen ransomware ecosystem. TukTuk supports Windows and Linux agents, credential prompts, screen capture, remote commands, and preparation for...
TITAN Ransomware Claims Its AI Can Sift 700GB of Stolen Data an Hour to Maximize Extortion
A relatively new ransomware-as-a-service operation called TITAN is marketing an AI-powered analysis platform that it says can classify and mine stolen corporate data at 700GB per hour, helping...
Ransomware Affiliate Used AI Coding Tool Cursor to Plan Attacks on 20+ Companies Across 9 Countries
An exposed staging server has given researchers an unusually detailed look at how a Russian-speaking Aurora ransomware affiliate used the AI coding assistant Cursor to help plan and...
This Week in Cyber: An AI Coding Assistant Helped Run a Ransomware Attack, and Azure Logins for 9 Major Firms Hit the Dark Web
Two stories from this week show how enterprise security is being reshaped from both ends: a ransomware affiliate reportedly used an AI coding assistant to breach VPNs and...
CISA Sounds Alarm on Medusa Ransomware After 500+ Critical Infrastructure Hits
CISA, the FBI, and HHS have jointly updated their advisory on the Medusa ransomware-as-a-service operation, which has now hit more than 500 critical infrastructure organizations spanning healthcare, education,...
Gunra Ransomware Gang Turns Fortinet VPN Bugs Into a Backdoor Around MFA
A joint advisory from the FBI, CISA, NSA, and South Korean authorities warns that the Gunra ransomware operation is exploiting known Fortinet VPN flaws to sidestep multi-factor authentication...
The Gentlemen Ransomware Uses a Malicious Kernel Driver to Blind Security Tools Before Striking
A ransomware operation dubbed The Gentlemen is using a custom kernel-level driver to silently kill nearly 180 security processes before it starts encrypting files. Researchers say the driver...