Ransomware
Curated coverage and analysis in this editorial area.

US Sanctions First VPN Provider: Anonymity as Criminal Infrastructure
The Treasury Department sanctions First VPN Service and its Ukrainian administrator for supporting ransomware groups. It marks the fir…

The Gentlemen Climbs RaaS Rankings: 90% Payout and 580 Victims in One Year
The Gentlemen, tracked as Storm-2697, has become the second most active RaaS operation of 2026 with over 6x growth and a 90% affiliate…

GodDamn Ransomware Uses Microsoft-Signed Driver to Disable EDR
The GodDamn ransomware, a rebrand of the Hyadina family, leverages the PoisonX driver — signed with a valid Microsoft Windows Hardware…

LVM: Weeks of Blackout After Ransomware Hits System Unpatched for Two Years
Latvia's state-owned forestry company Latvijas valsts meži (LVM) remains paralyzed weeks after a June 22 ransomware attack. Roughly tw…

Hyadina Strikes with GodDamn: Microsoft-Signed Driver Disables EDR in 24 Hours
The Hyadina ransomware-as-a-service group deploys a new locker, GodDamn, using the Microsoft-signed PoisonX kernel driver to neutraliz…

Mount Royal University Confirms Breach With Double Extortion: Data Theft and Deletion
The CMD Organization ransomware group claimed responsibility for the attack on Mount Royal University, demanding a $1.9 million ransom…

Agentic AI: A Lone Attacker Compromises Enterprise AWS in 72 Hours
Sygnia documents the first operational case of a lone threat actor using AI-assisted workflows to compress an enterprise AWS attack fr…

China-Linked Exploit Chain Targets US and Canadian Universities via Roundcube
A suspected Chinese espionage cluster has compromised fewer than ten US and Canadian universities using a two-vulnerability chain in R…

The Gentlemen: Go Backdoor and BYOVD in New RaaS That Spies on EDR
Kaspersky analyzes The Gentlemen, a ransomware-as-a-service group active since early 2026. Custom Go backdoor with persistent C2, five…

FortiBleed Fuels INC and Lynx: One Operator Serving Two Ransomware Clients
SOCRadar has documented the link between FortiBleed and the INC and Lynx ransomware groups. A single operator accessed the negotiation…

A U.S. Local Government Paid $1 Million for an Illusion of Control
A U.S. government entity paid roughly $1 million in bitcoin to the Kairos ransomware group on June 13, 2025, to prevent the release of…

Researcher Documents Real-Time Shared Access Between FortiBleed Operator and INC Ransom, Lynx Panels for First Time
SOCRadar documented that an operator with access to the FortiBleed infrastructure was simultaneously logged into the negotiation panel…