Tag: ransomware gang

Warlock Ransomware Breaches SmarterTools Through Unpatched SmarterMail Server
News

Warlock Ransomware Breaches SmarterTools Through Unpatched SmarterMail Server

Last week, SmarterTools verified that an unpatched SmarterMail instance was used by the Warlock (also known as Storm-2603) ransomware gang to compromise its network. According to Derek Curtis, the company's chief commercial officer, the incident occurred on January 29, 2026, when a mail server that had not been updated to the most recent version was compromised. We had about 30 servers/VMs with SmarterMail installed across our network before the hack, Curtis said. Regretfully, we were not aware of one employee-created virtual machine that was not being updated. The breach resulted from the penetration of that mail server. However, SmarterTools stressed that no business applications or account data were impacted or compromised read more about Warlock Ransomware Breaches SmarterToo...
Ransomware gang uses ISPsystem VMs for stealthy payload delivery
News

Ransomware gang uses ISPsystem VMs for stealthy payload delivery

By abusing virtual machines (VMs) provided by ISPsystem, a reputable virtual infrastructure management provider, ransomware perpetrators are hosting and distributing malware payloads at scale. While looking into recent "WantToCry" ransomware incidents, researchers at cybersecurity firm Sophos noticed the strategy. They discovered that the attackers employed Windows virtual machines (VMs) with the same hostnames, indicating that ISPsystem's VMmanager had produced default templates. Further investigation revealed that the identical hostnames were found in the infrastructure of other ransomware operators, such as LockBit, Qilin, Conti, BlackCat/ALPHV, and Ursnif, as well as several malware operations including RedLine and Lummar info-stealers. ISPsystem is a reputable software firm ...
Royal and BlackSuit ransomware gangs hit over 450 US companies
News

Royal and BlackSuit ransomware gangs hit over 450 US companies

Before being shut down last month, the cybercrime gang responsible for the Royal and BlackSuit ransomware operations reportedly compromised hundreds of American businesses, according to the U.S. Department of Homeland Security (DHS). The cybercriminals also seized more than $370 million from their victims, according to Homeland Security Investigations (HSI), DHS’s primary investigative division, which worked with foreign law enforcement partners to take down the group’s infrastructure. According to a news release issued by the HSI on Thursday, the Royal and BlackSuit ransomware groups have infected more than 450 known victims in the United States since 2022, including organizations in the public safety, healthcare, education, energy, and government sectors. Based on current bitco...
CISA and FBI warn of escalating Interlock ransomware attacks
News

CISA and FBI warn of escalating Interlock ransomware attacks

On Tuesday, CISA and the FBI issued a warning about a surge in Interlock ransomware activity that targets critical infrastructure organizations and businesses through double extortion assaults. The Multi-State Information Sharing and Analysis Center (MS-ISAC) and the Department of Health and Human Services (HHS) collaborated to create today's advisory, which gives network defenders mitigation strategies to shield their networks from attacks by this ransomware gang as well as indicators of compromise (IOCs) gathered during incident investigations as recently as June 2025. Since its emergence in September 2024, the relatively new ransomware operation Interlock has targeted victims globally in a variety of industry sectors, with a particular emphasis on the healthcare sector. The th...
Ransomware gang encrypted network from a webcam to bypass EDR
News

Ransomware gang encrypted network from a webcam to bypass EDR

Endpoint Detection and Response (EDR), which was preventing the encryptor on Windows, was successfully evaded by the Akira ransomware gang when they were observed launching encryption attacks on a victim's network via an unprotected camera. During a recent incident response at one of its clients, the cybersecurity firm S-RM team learned about the novel attack technique. Akira only turned to the webcam after trying to install encryptors on Windows, which the victim's EDR solution prevented. Using either brute-forcing the password or using credentials that were obtained read more about Ransomware gang encrypted network from a webcam to bypass EDR. Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers...
Ransomware gang uses SSH tunnels for stealthy VMware ESXi access
News

Ransomware gang uses SSH tunnels for stealthy VMware ESXi access

SSH tunneling is being used by ransomware actors to stay on the system and avoid detection when they target ESXi bare metal hypervisors. Because VMware ESXi appliances may run on a single physical server and several virtual machines inside an enterprise, they play a crucial role in virtualized settings. Due to their lack of oversight, hackers have targeted them in an attempt to get access to business networks. By encrypting files and stealing data, they can paralyze an entire company by making all virtual machines unavailable read more about Ransomware gang uses SSH tunnels for stealthy VMware ESXi access. Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
NoName ransomware gang deploying RansomHub malware in recent attacks
News

NoName ransomware gang deploying RansomHub malware in recent attacks

The NoName ransomware group may now be affiliated with RansomHub after attempting to establish a reputation for more than three years by using its encryptors to target small and medium-sized enterprises across the globe. The group employs specialized instruments referred to as the Spacecolon malware family, which they introduce into a network by means of brute-force attacks and by taking advantage of more established vulnerabilities such as EternalBlue (CVE-2017-0144) or ZeroLogon (CVE-2020-1472). The ransomware ScRansom, which took the place of the Scarab encryptor in more recent attacks, is used by NoName. The threat actor also made an attempt to gain notoriety by utilizing identical ransom letters, constructing a data leak website, and experimenting with the disclosed LockBit 3.0...
US Marshals Service disputes ransomware gang’s breach claims
News

US Marshals Service disputes ransomware gang’s breach claims

The U.S. Marshals Service (USMS), which was included as a new victim on the cybercrime group's leak site on Monday, disputes that the Hunters International ransomware gang compromised its systems. When contacted to verify the claims made by the cybercrime organization, a representative for USMS told BleepingComputer that the company is aware of the accusations and has reviewed the content that people have uploaded on the dark web. These materials don't seem to be related to any recent or undisclosed occurrence. Although the ransomware organization hasn't yet disclosed any purportedly stolen documents, they have already backed up their claims with thumbnail screenshots of a few of those files in the USMS entry read more about US Marshals Service disputes ransomware gang's breach clai...
Ransomware gang targets IT workers with new SharpRhino malware
News

Ransomware gang targets IT workers with new SharpRhino malware

Using a brand-new C# remote access trojan (RAT) named SharpRhino, the Hunters International ransomware organization is attempting to compromise business networks by targeting IT personnel. Hunters International uses the virus to assist them get access to targeted systems, increase their privileges there, run PowerShell operations, and ultimately release the ransomware payload. The new malware was found by Quorum Cyber researchers, who also report that it is being spread by a typosquatting website that mimics the official website for Angry IP Scanner, a networking utility that is used legitimately by IT experts. Due to code similarities, Hunters International, a ransomware operation that was started in late 2023, has been suggested as a potential Hive rebrand read more about Ranso...
ARRL finally confirms ransomware gang stole data in cyberattack
News

ARRL finally confirms ransomware gang stole data in cyberattack

Ultimately, the American Radio Relay League (ARRL) acknowledged that a ransomware attack in May had taken some of its employees' data, which had been initially referred to as a "serious incident." The National Association for Amateur Radio, or ARRL, announced the data breach to those who were affected lately. They stated that they discovered the "sophisticated ransomware incident" following their computer systems being compromised and encrypted on May 14. Following the breach's discovery, ARRL employed outside forensic specialists to assist in determining the attack's impact and pulled the affected systems offline to limit the situation. It also disclosed at the beginning of June that a malevolent multinational cyber gang had breached its networks through a sophisticated network ...