TukTuk Malware Gives Ransomware Crews Cross-Platform Control and EDR-Killing Tools
Researchers recovered a previously undocumented command-and-control framework linked to the Gentlemen ransomware ecosystem. TukTuk supports Windows and Linux agents, credential prompts, screen capture, remote commands, and preparation for...
TITAN Ransomware Claims Its AI Can Sift 700GB of Stolen Data an Hour to Maximize Extortion
A relatively new ransomware-as-a-service operation called TITAN is marketing an AI-powered analysis platform that it says can classify and mine stolen corporate data at 700GB per hour, helping...
Ransomware Affiliate Used AI Coding Tool Cursor to Plan Attacks on 20+ Companies Across 9 Countries
An exposed staging server has given researchers an unusually detailed look at how a Russian-speaking Aurora ransomware affiliate used the AI coding assistant Cursor to help plan and...
Shell Launches Investigation After Cl0p Extortion Group Claims Theft of Nearly 90GB of Internal Data
Energy giant Shell has activated its incident response process after the Cl0p extortion syndicate listed the company on its dark-web leak site, claiming to have stolen roughly 89GB...
Gunra Ransomware Gang Turns Fortinet VPN Bugs Into a Backdoor Around MFA
A joint advisory from the FBI, CISA, NSA, and South Korean authorities warns that the Gunra ransomware operation is exploiting known Fortinet VPN flaws to sidestep multi-factor authentication...
The Gentlemen Ransomware Uses a Malicious Kernel Driver to Blind Security Tools Before Striking
A ransomware operation dubbed The Gentlemen is using a custom kernel-level driver to silently kill nearly 180 security processes before it starts encrypting files. Researchers say the driver...
SonicWall VPN Gateways Hit by Zero-Click Root Takeover Chain Tied to INC Ransomware
Attackers are chaining two SonicWall SMA 1000 series flaws to gain root access to VPN gateways without a password or any user interaction. Researchers at Resecurity tie the...
GenieLocker: A New Cross-Platform Ransomware Hitting Windows, Linux and ESXi Alike
Researchers have identified GenieLocker, a new ransomware strain built by the financially motivated Toy Ghouls group to hit Windows, Linux and VMware ESXi environments in one campaign. The...