Prinz Eugen Ransomware Uses RemotePC RMM and PowerShell Stagers to Evade Detection
A new ransomware group is deploying the Go-based Prinz Eugen ransomware by abusing legitimate remote management software (RemotePC) and PowerShell stagers. The campaign has already hit major financial...
GentleKiller: Inside the Ransomware Framework Disabling 400+ EDR Security Products
ESET researchers have exposed GentleKiller, the in-house EDR-killing framework of the Gentlemen ransomware gang, capable of disabling over 400 security processes across 48 products using BYOVD kernel driver...
CISA Adds Oracle PeopleSoft Zero-Day CVE-2026-35273 to KEV Catalog After Ransomware Gang Exploitation
CISA has added a critical Oracle PeopleSoft vulnerability (CVE-2026-35273) to its Known Exploited Vulnerabilities catalog after confirming active exploitation in ransomware campaigns. The flaw allows unauthenticated attackers to...
DragonForce Ransomware Abuses Microsoft Teams TURN Relay to Hide Malicious C2 Traffic
Symantec researchers have discovered that DragonForce ransomware actors used a novel Go-based backdoor called Backdoor.TURN to route C2 communications through Microsoft Teams TURN relay servers — the first...
CVE-2026-50751: Check Point VPN 0-Day Actively Exploited to Deploy Qilin Ransomware
A critical CVSS 9.3 authentication bypass in Check Point Remote Access VPN (CVE-2026-50751) is being actively exploited in the wild, with confirmed post-compromise activity linked to the Qilin...
The Gentlemen Ransomware Group: Fortinet Exploits, AI Operations, and Custom C2 Make Them 2026’s Most Dangerous Crew
Russian-speaking ransomware group The Gentlemen ranks second in 2026 activity, exploiting Fortinet vulnerabilities, deploying the custom G-BOT C2 framework, using AI for negotiations, and linking operationally to Black...
‘The Gentlemen’ Ransomware: Self-Propagating Go Encryptor Uses SYSTEM Scheduled Tasks to Lock Entire Networks
A new Go-based ransomware called The Gentlemen (tracked as Storm-2697 by Microsoft) spreads automatically across networks using eight simultaneous propagation methods, escalates to SYSTEM privileges via scheduled tasks,...
NightSpire Ransomware Exploits RDP and Remote Admin Tools to Hit 64 Organizations in 33 Countries
NightSpire ransomware has hit at least 64 organizations across 33 countries by exploiting Remote Desktop Protocol access and installing legitimate remote administration tools like AnyDesk and Chrome Remote...