Tag: ransomware

Washington Hotel in Japan discloses ransomware infection incident
News

Washington Hotel in Japan discloses ransomware infection incident

The Japanese company Washington Hotel has revealed that a ransomware attack infiltrated its servers, exposing a variety of company information. In order to evaluate the consequences of the intrusion, ascertain whether customer data was exposed, and organize recovery operations, the hotel business has formed an internal task force and hired outside cybersecurity specialists. The Washington Hotel, a business-oriented accommodation chain with 30 sites around Japan, is a brand owned by Fujita Kanko Inc. (WHG Hotels). With 11,000 rooms spread among several locations, WHG welcomes around 5 million visitors annually. The corporation disclosed that at 22:00 (local time) on Friday, February 13, 2026, hackers gained access to its network. To stop the network attack from spreading read more...
Multi-Stage Phishing Campaign Targets Russia with Amnesia RAT and Ransomware
News

Multi-Stage Phishing Campaign Targets Russia with Amnesia RAT and Ransomware

Amnesia RAT is a new multi-stage phishing campaign that uses ransomware and a remote access virus to target users in Russia. In a technical analysis released this week, Fortinet FortiGuard Labs analyst Cara Lin stated, "The attack starts with social engineering lures delivered via business-themed documents crafted to appear routine and benign." While malicious activity operates in the background in silence, these papers and the scripts that go with them work as visual distractions, leading victims to fictitious chores or status updates. There are two distinctive aspects to the campaign. First, it distributes various types of payloads via several public cloud services. Dropbox is utilized to stage binary payloads, whereas GitHub is mostly used for script distribution. This division e...
Ransomware gangs turn to Shanya EXE packer to hide EDR killers
News

Ransomware gangs turn to Shanya EXE packer to hide EDR killers

A packer-as-a-service platform called Shanya is being used by several ransomware gangs to assist in the deployment of payloads that deactivate endpoint detection and response solutions on victim systems. Cybercriminals can use specialized tools from packer providers to package their payloads in a way that obfuscates harmful code and avoids detection by the majority of security products and antivirus engines. According to telemetry data from Sophos Security, malware samples utilizing the Shanya packer operation have been observed in Tunisia, the United Arab Emirates, Costa Rica, Nigeria, and Pakistan since it first appeared in late 2024. Medusa, Qilin, Crytox, and Akira are among the ransomware groups that have been found to have used it; the latter is the most frequent user of th...
Qilin Ransomware Turns South Korean MSP Breach Into 28-Victim ‘Korean Leaks’ Data Heist
News

Qilin Ransomware Turns South Korean MSP Breach Into 28-Victim ‘Korean Leaks’ Data Heist

What has been described as a sophisticated supply chain operation that resulted in the deployment of Qilin ransomware targeted South Korea's financial industry. According to a report shared with The Hacker News by Bitdefender, this operation used Managed Service Provider (MSP) compromise as the initial access vector, combining the capabilities of a significant Ransomware-as-a-Service (RaaS) group, Qilin, with possible involvement from North Korean state-affiliated actors (Moonstone Sleet). The RaaS team demonstrated "explosive growth" in October 2025, claiming over 180 victims, making Qilin one of the most active ransomware operations this year. According to data from NCC Group, the group is accountable for 29% of all ransomware outbreaks. In September 2025, South Korea became th...
DOJ investigates ex-ransomware negotiator over extortion kickbacks
News

DOJ investigates ex-ransomware negotiator over extortion kickbacks

The Department of Justice is conducting a criminal investigation into a former ransomware negotiator who reportedly collaborated with ransomware gangs to make money off of extortion payment agreements. The suspect was previously employed by DigitalMint, an incident response and digital asset services firm based in Chicago that specialized in ransomware negotiation and enabling cryptocurrency payments to obtain a decryptor or stop the public publication of stolen data. Since 2017, the business says it has negotiated more than 2,000 ransomware agreements. As initially reported by Bloomberg, the DOJ is looking into whether the suspect reportedly received a portion of the ransom that was charged to the client after negotiating payments with ransomware groups. DigitalMint told Bleepin...
DragonForce Exploits SimpleHelp Flaws to Deploy Ransomware Across Customer Endpoints
News

DragonForce Exploits SimpleHelp Flaws to Deploy Ransomware Across Customer Endpoints

Using the SimpleHelp remote monitoring and management (RMM) service from an unidentified Managed Service Provider (MSP), the threat actors behind the DragonForce ransomware were able to exfiltrate data and drop the locker on numerous endpoints. According to a Sophos study, the attackers used three security holes in SimpleHelp (CVE-2024-57727, CVE-2024-57728, and CVE-2024-57726) that were made public in January 2025 to gain access to the MSP's SimpleHelp deployment. A suspicious installation of a SimpleHelp installer file, pushed via a genuine SimpleHelp RMM instance that is hosted and run by the MSP for their clients, prompted the cybersecurity firm to report the incident. It has also been discovered that the threat actors exploit their access to the MSP's RMM instance to gather ...
Rubrik rotates authentication keys after log server breach
Business

Rubrik rotates authentication keys after log server breach

Last month, Rubrik revealed that a breach had occurred on one of its servers that housed log files, leading the company to rotate possibly compromised login keys. The business has assured BleepingComputer that it did not receive any correspondence from the threat actor and that the breach was not a ransomware event. With more than 3,000 workers spread over more than 22 locations worldwide, Rubrik is a cybersecurity company that specializes in data protection, backup, and recovery. High-profile businesses like AMD, Adobe, Pepsico, Home Depot, Allstate, Sephora, GSK, Honda, Harvard University, and TrelliX are among the company's more than 6,000 clients globally. Rubrik claims to have found strange behavior on a server holding its log files read more about Rubrik rotates authenticat...
China-Linked Attackers Exploit Check Point Flaw to Deploy ShadowPad and Ransomware
News

China-Linked Attackers Exploit Check Point Flaw to Deploy ShadowPad and Ransomware

PlugX and its replacement, ShadowPad, were deployed by a previously unidentified threat activity cluster that targeted European enterprises, especially those in the healthcare industry. In certain cases, the intrusions resulted in the transmission of a ransomware known as NailaoLocker. Orange Cyberdefense CERT dubbed the campaign Green Nailao, which exploited a recently patched security hole in Check Point network gateway security devices (CVE-2024-24919, CVSS score: 7.5). The attacks took place in 2024 between June and October. According to a technical analysis provided to The Hacker News, the campaign used DLL search-order hijacking to install ShadowPad and PlugX read more about China-Linked Attackers Exploit Check Point Flaw to Deploy ShadowPad and Ransomware. Get up to date o...
TRIPLESTRENGTH Targets Cloud Platforms with Cryptojacking and Ransomware
News

TRIPLESTRENGTH Targets Cloud Platforms with Cryptojacking and Ransomware

Google revealed on Wednesday that TRIPLESTRENGTH, a financially driven threat actor, targets cloud systems opportunistically for on-premise ransomware and cryptojacking attacks. According to the tech giant's cloud division's 11th Threat Horizons Report, this actor engaged in a range of threat activities, such as ransomware activity and cryptocurrency mining operations on cloud resources that were stolen. Malicious assaults by TRIPLESTRENGTH include ransomware, extortion, illegal cryptocurrency mining, and promoting to other threat actors access to cloud platforms such as Google Cloud, Amazon Web Services, Microsoft Azure, Linode, OVHCloud, and Digital Ocean. Cookies and credentials that have been taken, some of which come from Raccoon information stealer infection logs read more ...
Free Decryptor Released for BitLocker-Based ShrinkLocker Ransomware Victims
News

Free Decryptor Released for BitLocker-Based ShrinkLocker Ransomware Victims

A free decryptor has been made available by the Romanian cybersecurity firm Bitdefender to assist victims in recovering data that has been encrypted by the ShrinkLocker ransomware. The researchers were able to identify a particular window of opportunity for data recovery right after the removal of protectors from BitLocker-encrypted disks since the decryptor is the outcome of a thorough examination of ShrinkLocker's internal operations. The malware's exploitation of Microsoft's built-in BitLocker tool to encrypt files as part of extortion campaigns against Mexico, Indonesia, and Jordan was initially discovered by Kaspersky in May 2024 read more about Free Decryptor Released for BitLocker-Based ShrinkLocker Ransomware Victims. Get up to date on the latest cybersecurity news and en...