Ransomware
Curated coverage and analysis in this editorial area.

Ransom Busters: The Double-Cross Undermining the RaaS Model From Within
A ransomware affiliate operates as a fake recovery firm, contacting victims before attacks are published. GuidePoint Security GRIT doc…

Akira in Safe Mode: Blind EDR and the Ransomware That Collapsed From Memory Starvation
An Akira affiliate disabled EDR by forcing a reboot into Safe Mode with Networking, but the ransomware payload crashed with "Out of Vi…

Ransomware Q2 2026: 2,139 Victims and Payment Rate Crashes to 23%
Ransomware isn't slowing down — it's fragmenting. Q2 2026 saw 93 active groups, up from 71 at the start of the year. The top-10 share…

DeadLock: The Ransomware Using Polygon to Evade Infrastructure Seizures
DeadLock leverages Polygon smart contracts to rotate proxy servers and host its data leak site, rendering the infrastructure-seizure s…

Clop Claims Theft of Technical Data from 43 Organizations; Shell Investigates
The Clop group stole technical data from 43 organizations by exploiting CVE-2026-12569 in PTC Windchill. Shell is investigating a pote…

Ransomware Q2: 1,140 Industrial Attacks, the New Perimeter Lies in IT Systems
Dragos' Q2 2026 report records 1,140 ransomware incidents against industrial organizations. The key finding: production halts without…

Gunra Hits Critical Infrastructure with Dual Fortinet Exploit
CISA, FBI, NSA, and South Korean police issued joint advisory AA26-222A on Gunra: 51 confirmed victims, MFA bypass, and persistence th…

CISA Confirms SharePoint Ransomware Exploitation; Microsoft Stays Silent
The U.S. cybersecurity agency confirmed on August 11, 2026, that ransomware groups are actively exploiting CVE-2026-45659 in on-premis…

Microsoft Analyzes DeadLock: Rust Ransomware with Decentralized Infrastructure
Microsoft Threat Intelligence published a full technical analysis of DeadLock on August 11, 2026. The Rust-based ransomware has been a…

Lazarus Shares Zero-Day and C2 With Gunra: South Korea Raises Alarm
Four South Korean agencies confirm the Lazarus Group shared tools, infrastructure, and a zero-day vulnerability with the Gunra ransomw…

ExfilSquad Exfiltrates Data on 100,000 UK Police Officers: Debut Without Encryption
The emerging ransomware group ExfilSquad has exfiltrated contact data for over 100,000 officers from the UK Police National Legal Data…

Kodak Confirms 'Limited' Breach, but ShinyHunters Claims 2.2 Million Records
Kodak acknowledged unauthorized access to a 'limited amount' of corporate data on June 18, 2026, but did not verify the 2.2 million re…