Emerging DOGE Big Balls ransomware campaign leverages multi-stage tooling and BYOVD exploits
A recent analysis of newly discovered payloads linked to the DOGE Big Balls ransomware operation reveals a complex infection chain combining open-source tools, kernel-level exploits, and psychological warfare....
Stealthy Linux backdoor leveraging residential proxies and NHAS reverse SSH
A recently discovered Linux backdoor (SHA256: ea41b2bf1064efcb6196bb79b40c5158fc339a36a3d3ddee68c822d797895b4e) employs advanced evasion techniques to bypass detection while establishing persistent access via SOCKS5 proxies and in-memory payload execution. This analysis breaks...
US indicts Black Kingdom ransomware operator: technical analysis of ProxyLogon exploitation and law enforcement response
The U.S. Department of Justice unsealed charges against Yemeni national Rami Khaled Ahmed (36) for deploying Black Kingdom ransomware via ProxyLogon exploits (CVE-2021-26855) against 1,500+ systems, including U.S....
Hijacking Trust: how Gmail and Google APIs are being weaponized for stealthy C2 channels
In the ever-evolving landscape of cybersecurity, attackers are increasingly exploiting trusted services to establish covert command-and-control (C2) channels. By leveraging platforms like Gmail and Google Drive, threat actors...
Kintetsu World Express ransomware attack: technical overview and response
Kintetsu World Express (KWE), a major Japanese global logistics provider, has confirmed a significant ransomware attack that began impacting its operations in late April 2025. The incident has...
JFL Hospital targeted in ransomware attack amid wave of cyber incidents in US Virgin Islands
Governor Juan F. Luis Hospital & Medical Center (JFL) in the US Virgin Islands has become the latest government entity to suffer a cybersecurity breach, confirming a ransomware...
Malicious NPM packages targeting PayPal users: a recap analysis
FortiGuard Labs recently uncovered a series of malicious NPM packages designed to steal sensitive information from compromised systems. These packages, created between March 5 and March 14, were...
Everest ransomware gang faces unprecedented blow: leak site hacked and defaced
In a surprising turn of events, the Everest ransomware gang—a notorious Russia-linked cybercriminal organization—has suffered a significant setback. Over the weekend, their dark web leak site was hacked...