Tag: ransomware attack

LeakNet Ransomware Uses ClickFix via Hacked Sites Deploys Deno In-Memory Loader
News

LeakNet Ransomware Uses ClickFix via Hacked Sites Deploys Deno In-Memory Loader

The ClickFix social engineering technique, which is distributed via hacked websites, has been used as an initial entry method by the ransomware operation known as LeakNet. According to a technical report released today by ReliaQuest, the use of ClickFix, which deceives users into manually executing malicious commands to fix nonexistent errors, is different from depending on conventional methods for gaining initial access, like using credentials that were stolen from initial access brokers (IABs). The employment of a staged command-and-control (C2) loader based on the Deno JavaScript runtime to run malicious payloads directly in memory is the second crucial component of these assaults. According to the cybersecurity firm, the most important lesson here is that both entry routes re...
Stryker attack wiped tens of thousands of devices, no malware needed
News

Stryker attack wiped tens of thousands of devices, no malware needed

Tens of thousands of employee devices were remotely erased by last week's cyberattack on medical technology major Stryker, which was restricted to its internal Microsoft environment. All of the company's medical devices are safe to use, according to an update released on Sunday. However, consumers must still place orders manually through sales reps because computerized purchasing systems are still out. Stryker stresses that the threat actor did not install any malware on its systems and that the event was not a ransomware attack. The Handala hacktivist organization, which is thought to be connected to Iran, said that Stryker was the victim of a cyberattack last week. The attacker claimed to have stolen 50 gigabytes of data and erased over 200,000 computers, servers, and mobile devic...
Qilin Ransomware Turns South Korean MSP Breach Into 28-Victim ‘Korean Leaks’ Data Heist
News

Qilin Ransomware Turns South Korean MSP Breach Into 28-Victim ‘Korean Leaks’ Data Heist

What has been described as a sophisticated supply chain operation that resulted in the deployment of Qilin ransomware targeted South Korea's financial industry. According to a report shared with The Hacker News by Bitdefender, this operation used Managed Service Provider (MSP) compromise as the initial access vector, combining the capabilities of a significant Ransomware-as-a-Service (RaaS) group, Qilin, with possible involvement from North Korean state-affiliated actors (Moonstone Sleet). The RaaS team demonstrated "explosive growth" in October 2025, claiming over 180 victims, making Qilin one of the most active ransomware operations this year. According to data from NCC Group, the group is accountable for 29% of all ransomware outbreaks. In September 2025, South Korea became th...
Microsoft Links Storm-1175 to GoAnywhere Exploit Deploying Medusa Ransomware
News

Microsoft Links Storm-1175 to GoAnywhere Exploit Deploying Medusa Ransomware

Microsoft said Monday that a threat actor it monitors as Storm-1175 exploited a serious security hole in Fortra GoAnywhere software to make it easier for the Medusa ransomware to spread. The major deserialization flaw, CVE-2025-10035 (CVSS score: 10.0), has the potential to allow command injection without authentication. The Sustain Release 7.6.3, or version 7.8.4, addressed it. According to the Microsoft Threat Intelligence team, the vulnerability can enable a threat actor to deserialize an arbitrary actor-controlled object using a legitimately faked license response signature, potentially resulting in command injection and remote code execution (RCE). The tech firm claims that since September 11, 2025, the cybercriminal gang Storm-1175 has been using Medusa ransomware and gaini...
Pennsylvania AG Office says ransomware attack behind recent outage
News

Pennsylvania AG Office says ransomware attack behind recent outage

The two-week service disruption is being caused by a ransomware attack, according to the Office of the Pennsylvania Attorney General. Attorney General David W. Sunday Jr. stated in a formal statement that the office declined to compensate the assailants. An outsider encrypting files in an attempt to compel the office to pay to resume operations was the reason of the disruption. AG Sunday explains why no payment has been paid. We are unable to comment further on the investigation or our response to the incident since other agencies are still conducting an active investigation. On August 11, the AG's Office revealed that several of its systems and services, including the public website, email accounts, and landline phones, were unavailable due to a cybersecurity attack. The AG O...
Experimental PromptLock ransomware uses AI to encrypt, steal data
News

Experimental PromptLock ransomware uses AI to encrypt, steal data

PromptLock, the first AI-powered ransomware, was found by threat researchers. It encrypts and steals data from Windows, macOS, and Linux systems using Lua scripts. The malware dynamically creates the harmful Lua scripts from hard-coded prompts using OpenAI's gpt-oss:20b model via the Ollama API. ESET researchers claim that PromptLock is written in Golang and accesses the gpt-oss:20b big language model via the Ollama API. The threat actor uses a proxy tunnel to connect to the distant server hosting the LLM. The malware employs hard-coded prompts to tell the model to create malicious Lua scripts on the fly, such as those for data exfiltration, file encryption, target file inspection, and local filesystem enumeration. Although it hasn't been used, the researchers also discuss dat...
Microsoft Windows Vulnerability Exploited to Deploy PipeMagic RansomExx Malware
News

Microsoft Windows Vulnerability Exploited to Deploy PipeMagic RansomExx Malware

Researchers studying cybersecurity have shown how threat actors used a now-patched security hole in Microsoft Windows to spread the PipeMagic malware during RansomExx ransomware assaults. According to a joint analysis released today by Kaspersky and BI.ZONE, the attacks entail the exploitation of CVE-2025-29824, a privilege escalation vulnerability affecting the Windows Common Log File System (CLFS) that Microsoft fixed in April 2025. PipeMagic, which can function as a full-fledged backdoor that grants remote access and can carry out a variety of commands on compromised hosts, was initially reported in 2022 as a component of RansomExx ransomware attacks that targeted industrial companies in Southeast Asia. The threat actors were able to access the target infrastructure by taking ...
Royal and BlackSuit ransomware gangs hit over 450 US companies
News

Royal and BlackSuit ransomware gangs hit over 450 US companies

Before being shut down last month, the cybercrime gang responsible for the Royal and BlackSuit ransomware operations reportedly compromised hundreds of American businesses, according to the U.S. Department of Homeland Security (DHS). The cybercriminals also seized more than $370 million from their victims, according to Homeland Security Investigations (HSI), DHS’s primary investigative division, which worked with foreign law enforcement partners to take down the group’s infrastructure. According to a news release issued by the HSI on Thursday, the Royal and BlackSuit ransomware groups have infected more than 450 known victims in the United States since 2022, including organizations in the public safety, healthcare, education, energy, and government sectors. Based on current bitco...
AWS EKS Security Best PracticesScattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. Infrastructure
News

AWS EKS Security Best PracticesScattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. Infrastructure

VMware ESXi hypervisors are the subject of attacks by the well-known cybercrime gang Scattered Spider that target the North American retail, airline, and transportation industries. The fundamental strategies employed by the gang have not changed and do not depend on software exploits. According to a thorough examination by Google's Mandiant team, they instead employ a tried-and-true strategy that revolves upon phone calls to an IT help desk. The actors are aggressive, resourceful, and especially adept at circumventing even well-established security measures through social engineering. They target an organization's most important systems and data using targeted, campaign-driven attacks rather than opportunistic ones. The threat actors, also known as 0ktapus, Muddled Libra, Octo Te...
IdeaLab confirms data stolen in ransomware attack last year
News

IdeaLab confirms data stolen in ransomware attack last year

People affected by the data breach that occurred in October, when hackers gained access to private data, are being notified by IdeaLab. The Hunters International ransomware group has claimed the hack and posted the stolen data on the dark web, despite the organization's failure to specify the nature of the attack. Since 1996, IdeaLab, a California-based incubator for digital startups, has helped create more than 150 businesses, such as GoTo.com, CitySeach, eToys, Authy, Pet.net, Heliogen, and Energy Vault. As one of the most established and significant venture capital businesses in the United States, the organization has created a significant amount of investment value, jobs, and economic effect. IdeaLab discovered questionable activities on its network on October 7, 2024. Aft...