Tag: ransomware-as-a-service (RaaS)

The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes
News

The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes

Before deploying the encryptor, the Gentlemen ransomware-as-a-service (RaaS) organization actively develops and maintains a suite of endpoint detection and response (EDR) killers that it distributes to affiliates in order to weaken system defenses. The GentleKiller framework serves as the foundation for this well-developed collection of EDR-terminating solutions. According to a report shared with The Hacker News by ESET security researcher Jakub Souček, they also use third-party or leaked tools like HexKiller, ThrottleBlood, and HavocKiller. "These tools are standardized through a shared defense-evasion layer, impersonating predominantly security vendors using fake version information, and copied legitimate certificates and icons," Souček said. The ransomware team was also critic...
SystemBC C2 Server Reveals 1570+ Victims in The Gentlemen Ransomware Operation
News

SystemBC C2 Server Reveals 1570+ Victims in The Gentlemen Ransomware Operation

Threat actors connected to the Gentlemen ransomware-as-a-service (RaaS) operation have been seen trying to install SystemBC, a known proxy virus. A botnet with over 1,570 victims has been found thanks to the command-and-control (C2 or C&C) server connected to SystemBC, according to recent research released by Check Point. According to Check Point, SystemBC creates SOCKS5 network tunnels inside the victim's environment and uses a unique RC4-encrypted protocol to connect to its C&C server. Additionally, it has the ability to download and run other malware, with payloads that are either written to disk or injected straight into memory. The Gentlemen is one of the most active ransomware organizations, having claimed over 320 victims on its data leak site since it first appear...
Black Basta Ransomware Leader Added to EU Most Wanted and INTERPOL Red Notice
News

Black Basta Ransomware Leader Added to EU Most Wanted and INTERPOL Red Notice

Two Ukrainians are suspected of working for the Russia-affiliated ransomware-as-a-service (RaaS) company Black Basta, according to Ukrainian and German law enforcement authorities. Authorities also reported that Oleg Evgenievich Nefedov, a 35-year-old Russian national, has been placed on INTERPOL's Red Notice list and the European Union's Most Wanted list. The Cyber Police of Ukraine claimed in a statement that the suspects were involved in planning cyberattacks employing ransomware and were skilled in technical hacking of secured systems. According to the agency, the accused people worked as "hash crackers," who are experts at utilizing specialized software to retrieve passwords from information systems. Members of the ransomware organization entered into company networks after ...
VolkLocker Ransomware Exposed by Hard-Coded Master Key Allowing Free Decryption
News

VolkLocker Ransomware Exposed by Hard-Coded Master Key Allowing Free Decryption

With a new ransomware-as-a-service (RaaS) product dubbed VolkLocker, which includes implementation flaws in test artifacts and lets users decrypt files without paying an extortion charge, the pro-Russian hacktivist group CyberVolk (also known as GLORIAMIST) has reappeared. VolkLocker, also known as CyberVolk 2.x, first appeared in August 2025 and can target Linux and Windows systems, according to SentinelOne. Golang is used for writing. According to a report released last week by security researcher Jim Walter, operators creating new VolkLocker payloads must supply a bitcoin address, Telegram bot token ID, Telegram chat ID, encryption deadline, preferred file extension, and self-destruct options. After it is launched, the ransomware tries to increase its privileges, conducts syst...
Chaos RaaS Emerges After BlackSuit Takedown Demanding $300K from U.S. Victims
News

Chaos RaaS Emerges After BlackSuit Takedown Demanding $300K from U.S. Victims

A law enforcement seizure of BlackSuit's dark web infrastructure suggests that the recently formed Chaos ransomware-as-a-service (RaaS) gang is probably composed of former members of the BlackSuit group. Chaos, which first appeared in February 2025, is the most recent ransomware to launch double extortion and big game hunting attacks. According to Cisco Talos researchers Anna Bennett, James Nutland, and Chetan Raghuprasad, Chaos RaaS actors started with low-effort spam flooding and progressed to voice-based social engineering for access, RMM tool abuse for a persistent connection, and legitimate file-sharing software for data exfiltration. The ransomware maximizes impact while impeding identification and recovery by using multi-threaded quick selective encryption, anti-analysis a...
Newly Emerged GLOBAL GROUP RaaS Expands Operations with AI-Driven Negotiation Tools
News

Newly Emerged GLOBAL GROUP RaaS Expands Operations with AI-Driven Negotiation Tools

Since its inception in early June 2025, the new ransomware-as-a-service (RaaS) operation known as GLOBAL GROUP has targeted a variety of industries in Australia, Brazil, Europe, and the US, according to cybersecurity researchers. According to Arda Büyükkaya, a researcher at EclecticIQ, GLOBAL GROUP was "promoted on the Ramp4u forum by the threat actor known as '$$$,'" "The same actor controls the BlackLock RaaS and previously managed Mamona ransomware operations." After the DragonForce ransomware gang vandalized BlackLock's data leak website in March, it is thought that GLOBAL GROUP is a rebranding of BlackLock. It's important to note that BlackLock is merely a rebranding of Eldorado, another RaaS scheme. It has been discovered that the profit-driven gang primarily relies on init...
Qilin Ransomware Adds “Call Lawyer” Feature to Pressure Victims for Larger Ransoms
News

Qilin Ransomware Adds “Call Lawyer” Feature to Pressure Victims for Larger Ransoms

As the cybercrime gang steps up its efforts to fill the gap left by its competitors, the threat actors behind the Qilin ransomware-as-a-service (RaaS) scheme are now providing legal advice for affiliates to increase the pressure on victims to pay up. According to Israeli cybersecurity firm Cybereason, the new tool appears on the affiliate panel as a "Call Lawyer" feature. Given the sudden shutdowns, operational failures, and defacements of once-popular ransomware companies like LockBit, Black Cat, RansomHub, Everest, and BlackLock, the development signifies a newfound rebirth of the e-crime group. Since October 2022, the group—also known as Gold Feather and Water Galura—has been in operation. According to data gathered from ransomware groups' dark web leak websites, Qilin had the...
Anubis ransomware adds wiper to destroy files beyond recovery
News

Anubis ransomware adds wiper to destroy files beyond recovery

A wiper module has been introduced to the Anubis ransomware-as-a-service (RaaS) operation's file-encrypting software, which eliminates targeted files and prevents recovery even in the event that the ransom is paid. Anubis is a relatively new RaaS that was initially discovered in December 2024 but increased in activity at the start of the year. It should not be confused with the same-named Android virus that has a ransomware module. An affiliate program was announced by the operators on the RAMP forum on February 23. According to a KELA investigation at the time, Anubis gave ransomware affiliates an 80% cut of the money they made. A 60% cut was offered to data extortion associates, while a 50% cut was offered to initial access brokers. Only eight victims are listed on Anubis' exto...