Ransomware Intelligence
Active ransomware gang campaigns, victim disclosures from leak sites, RaaS affiliate recruitment, and SIGMA detection rules for every known ransomware family targeting enterprise environments.
Ransomware — Archive & Latest
BARRACUDA Ransomware Gang: 3 New Leak-Site Listings — Sector Targeting Analysis, Detection Rules & Response Playbook
BARRACUDA listed 3 organizations on its dark web leak site this week — manufacturing and services firms, with Argentina in scope. Unverified claims; detection rules inside.
CISA KEV Flash: 10 CVEs Added — MikroTik, Microsoft SharePoint, F5 & Check Point Under Active Attack
CISA confirms active exploitation of 10 new CVEs spanning MikroTik, SharePoint, WordPress, F5 BIG-IP, Check Point, Zyxel & more. Federal deadlines binding. Patch now.
THEGENTLEMEN Ransomware Gang: 4 New Leak-Site Claims — Sector Targeting Analysis & Detection Engineering
THEGENTLEMEN has listed 4 new organizations on its dark web leak site spanning Technology, Manufacturing, and Retail across US, SG, and PT. All listings are single-source, unverified claims.
AKIRA Ransomware Gang: 5 New Victim Claims Posted — Manufacturing & Professional Services Listing Analysis With Detection Rules
AKIRA's leak site added 5 new claimed victims in 72 hours, concentrated in US manufacturing and professional services. Unverified claims — but the exposure signals are actionable now.
TERMITE Ransomware Gang: 4 New Leak-Site Listings in 4 Days — US-Only Targeting, Sector Analysis & Detection Rules
TERMITE listed 4 US organizations on its leak site between 2026-09-22 and 2026-09-25 — all single-source claims spanning manufacturing, financial services, and real estate. Unverified; defenders should treat as exposure signal.
EVEREST Ransomware Gang: 6 New Leak-Site Listings Posted — Sector Targeting Analysis & Detection Rules
EVEREST listed six organizations across professional services, healthcare, technology and education; defenders in SE, ZA, JP and BE should hunt pre-encryption staging now.
WALLSTREET Ransomware Gang: 7 New Leak-Site Listings — Sector Targeting Analysis & Detection Rules
WALLSTREET listed 7 organizations across manufacturing, energy, finance, healthcare, legal, and education in GB/US/SV. Unverified claims; defenders should hunt pre-ransom TTPs now.
INCRANSOM: 6 New Leak-Site Listings — Healthcare and Professional Services Claims, Exposure Analysis & Detection Rules
INCRANSOM listed six organizations across healthcare, professional services, and manufacturing; defenders should prioritize access, staging, and exfiltration controls.
N0N Ransomware Gang: 3 Leak-Site Listings Across Technology and Retail — Detection Rules & Sector Exposure
N0N lists 3 orgs across US, ML, and UZ technology and retail; all are single-source claims. Technology, retail, and IT services teams should hunt remote-access and staging indicators.
ENDZONE Ransomware Gang: 3 New Leak-Site Listings — Sector Targeting Analysis & Detection Rules
ENDZONE has listed 3 organizations on its leak site in the past 5 days, concentrated in US professional services and technology. Unverified claims — defenders should hunt now.
DRAGONFORCE Ransomware Gang: 4 New Victims Listed — Cross-Regional Campaign Analysis & Detection Engineering
DRAGONFORCE listed 4 new victims across TW, TH, FR, and US on its leak site, spanning manufacturing, healthcare, and other sectors. Unverified claims — defenders should hunt now.
EMPERADOR Ransomware Gang: 6 New Leak-Site Listings Across Government, Healthcare & Transportation — Analysis & Detection Rules
EMPERADOR has listed 6 organizations on its dark web leak site, spanning government, healthcare, transportation, and manufacturing. Unverified claims — defensive guidance inside.
SILENTRANSOMGROUP: 6 New Leak-Site Listings Claimed — Legal & Professional Services Targeting Analysis and Detection Engineering
SILENTRANSOMGROUP has listed 6 organizations — including several US professional services / legal firms — on its dark web leak site. Claims are unverified; legal and professional services teams should hunt now.
BOOBA PROJECT Ransomware Group: 6 New Leak-Site Listings Across Government, Healthcare & Education — Sector Analysis & Detection Rules
BOOBA PROJECT listed 6 organizations on its dark web leak site across government, healthcare, and education sectors. All listings are unverified single-source claims — review detection rules now.
N0N Ransomware Gang: 7 New Leak-Site Listings Across Tech, Retail, Finance & Government — Sourcing, Sectors & Detection Rules
N0N listed 7 organizations on its dark web leak site this week spanning technology, retail, finance, and government sectors. All listings are single-source, unverified criminal claims — detection content inside.
N0N Ransomware Gang: 13 New Leak-Site Listings in 6 Days — Sector Targeting Analysis & Detection Rules
Dark web leak-site monitoring shows the N0N ransomware gang has listed 13 organizations across 8 countries since Sept 18, spanning tech, finance, retail, healthcare, government, and education. All listings are unverified single-source claims; defenders in affected sectors should review N0N-aligned TTP detection content now.
N0N Ransomware Gang: 13 New Leak-Site Listings — Cross-Sector Targeting Analysis, Verification Caveats & Detection Rules
N0N claims 13 new victims across 8 countries spanning technology, financial services, government, and healthcare. All listings are single-source claims — detection and hardening guidance included.
QILIN Ransomware Gang: 14 New Leak-Site Listings — Sector Targeting Analysis & Detection Rules
QILIN listed 14 organizations on its dark web leak site in five days, spanning manufacturing, technology, retail, transportation, agriculture, and energy across 8+ countries. Claims remain unverified — defensive guidance inside.
N0N Ransomware Gang: 12 Victims Posted in 5-Day Surge — Cross-Sector Campaign Analysis, CVE Correlation & Detection Engineering
N0N posted 12 victims in 5 days spanning retail, fintech, government, healthcare and education across 8 countries. Edge-device CVE exploitation suspected; retail, financial services and education orgs must act now.
N0N Ransomware Gang: 11 New Victims in 72 Hours — Financial Services, Government & Telecom Targeting Analysis With Detection Rules
Dark web monitoring confirms N0N posted 11 victims in 72 hours, hitting financial services, telecom, government, and healthcare across 8 countries. Detection rules and IR priorities inside.
METAENCRYPTOR Ransomware Gang: 7 Organizations Listed in 5 Days — Healthcare & Manufacturing Focus With Edge-Device Exploitation
METAENCRYPTOR listed 7 organizations in 5 days — unverified leak-site claims. Detection rules, KQL hunts, and IR priorities inside.
N0N Ransomware Gang: 11 Victims in 4 Days — Cross-Sector Campaign Analysis, KEV Correlation & Detection Engineering
Dark web monitoring of the N0N leak site shows 11 victims posted across 8 countries in 4 days, spanning retail, finance, healthcare, and government. Detection rules and hunt queries inside.
AKIRA Ransomware Gang: 4 New Victims Posted — US/Brazil Targeting, CVE Correlation & Detection Rules
Akira posted 4 new victims across Manufacturing, Professional Services, Tech, and Retail in the US and Brazil. Edge-device CVEs in active exploitation demand immediate patching and hunt operations.
N0N Ransomware Gang: 11 Victims in 4 Days — Cross-Sector Extortion Campaign Targeting FinServ, Education & Critical Telecom
N0N posted 11 victims across 8 countries in a 4-day burst, hitting financial services, education, healthcare and a national ISP. FinServ and EDU defenders should hunt for edge-device exploitation and pre-encryption staging now.
KRYBIT Ransomware Gang: 3 New Victims Posted to Leak Site — Turkey/Germany Targeting, Healthcare Exposure & Detection Rules
KRYBIT posted 3 victims (Technology, Healthcare, TR/DE) to its dark web leak site in 4 days. Edge device CVEs in active ransomware use demand immediate patching and hunting.
N0N Ransomware Gang: 11 Victims in 48 Hours — Cross-Sector Campaign Analysis, Leak-Site Intelligence & Detection Rules
N0N posted 11 victims in 48 hours spanning retail, finance, healthcare, government and education across 8 countries. Enterprise SOC and IR teams in these sectors should activate pre-ransomware hunt playbooks now.
ARCUSMEDIA Ransomware Gang: 3 Victims in 4 Days — BR/CA Tech and Government-Defense Targeting With Edge-CVE Access Signals
ArcusMedia posted 3 victims in 4 days across BR/CA tech and government-defense; edge/VPN CVE exposure and pre-encryption staging demand immediate hunting.
N0N Ransomware Gang: 11 New Victims Posted — Sector Targeting Analysis & Detection Rules
N0N posted 11 victims across retail, finance, healthcare, government and education; edge/VPN CVEs and pre-encryption staging demand immediate hunting.
INCRANSOM Ransomware Gang: 4 New Victims Posted — Hospitality, Education, Retail and Manufacturing Alert
INCRANSOM posted 4 victims across NL, US and AR. Hospitality, education, retail/e-commerce and manufacturing teams should hunt for edge-device intrusion, staging and pre-encryption extortion signals now.
N0N Ransomware Gang: 11 Victims Posted in 72 Hours — Multi-Sector Campaign Analysis, Detection Rules & IR Playbook
N0N posted 11 victims across 8 countries and 8 sectors in a 72-hour burst. Retail, financial services, healthcare, and government orgs must review VPN edge exposure and pre-encryption staging indicators now.
CISA KEV Flash: 7 CVEs Added — Cisco Edge, Linux Kernel, Acronis & Pixel Under Active Attack
CISA added 7 actively exploited CVEs: Cisco SEG/ISE, Acronis plugins, three Linux kernel flaws and Pixel modem. Patch edge identity/email first.
SAFEPAY Ransomware Gang: 8 New Leak-Site Victims — Sector/Geo Targeting Analysis, CVE Access Paths & Detection Rules
SAFEPAY posted 8 victims across manufacturing, healthcare, retail, technology and services in US/DE/MX/CH/JP; edge-VPN, RMM and hypervisor CVE exposure should be treated as urgent.
N0N Ransomware Gang: 10 Victims Posted in Single-Day Surge — Sector Targeting Analysis & Detection Engineering
N0N posted 10 victims on 2026-09-18 spanning telecom, finance, government, healthcare and education across 8 countries. Detection rules and IR priorities inside.
N0N Ransomware Gang: 10 Victims Posted in 24 Hours — Cross-Sector Campaign Analysis & Detection Engineering
N0N posted 10 victims in a single day spanning tech, finance, government, healthcare, and education across 8 countries. Enterprises running VMware vCenter, Cisco FMC, and Check Point gateways must act now.
N0N Ransomware: 10 Victims Posted in 24 Hours — Telecom, Fintech & Government Targeting Analysis with Detection Rules
N0N posted 10 victims in a single day spanning telecom, fintech, government, and education across 8 countries. Detection rules, hunt queries, and IR playbook inside.
N0N Ransomware: 10 Victims Posted in Single-Day Surge — Cross-Sector Campaign Hits Telecom, Finance, Government & Education
N0N ransomware posted 10 victims in one day spanning telecom, financial services, government, healthcare, and education across 8 countries. Detection rules and hunt queries inside.
STORM Ransomware Gang: 8 Victims Posted in 4 Days — US Financial Services Blitz, Detection Rules & IR Playbook
STORM posted 8 US victims in 4 days, with 6 of 8 in financial services. Banks, credit unions, and healthcare orgs must hunt perimeter CVEs and pre-encryption staging now.
PANZER Ransomware Gang: 5 Victims in 4 Days — Technology & Manufacturing Sector Surge, Perimeter CVE Exploitation & Detection Rules
PANZER posted 5 victims in 4 days across FR, PY, DE, and PE, hitting Technology, Education, and Manufacturing. Likely exploiting KEV-listed perimeter flaws — patch and hunt now.
BRAINCIPHER Ransomware: 3 New Victims in 24 Hours — Professional Services & Tech Sector Targeting With Detection Rules
BRAINCIPHER posted 3 victims in one day across GB, US, and CA, hitting professional services and technology firms. Engineering, SOC, and IR teams should review detections now.
EMPERADOR Ransomware Gang: 3 New Victims Posted — Education & Manufacturing Targeting, KEV-Linked Access Paths
EMPERADOR posted 3 new victims across Education and Manufacturing in IT/CZ. Patch edge CVEs, hunt pre-encryption staging, and lock down VPN/RDP now.
SHADOWBYT3$ Ransomware: 2 US Property-Management Victims Posted — Edge Access, Staging & Detection Rules
SHADOWBYT3$ posted two US property-management victims tied to HandyTrac/Greystar in AZ; edge-VPN and KEV exposure should be hunted now.
QILIN Ransomware Gang: 19 Victims Posted in 72 Hours — Manufacturing & Agri-Food Surge, Detection Rules Inside
QILIN posted 19 victims in 72 hours, heavily concentrated in manufacturing, agriculture/food, and professional services across the US, AU, and EU. Engineering, food production, and legal-sector orgs should assume active targeting and hunt now.
THEGENTLEMEN Ransomware Gang: 15 Victims Posted in 48 Hours — Multi-Sector Campaign Analysis, CVE Correlation & Detection Engineering
THEGENTLEMEN posted 15+ victims in a single 48-hour burst spanning healthcare, manufacturing, and energy across 13 countries. Detection rules, hunt queries, and IR priorities inside.
DRAGONFORCE Ransomware: 2 New Victims Posted to Leak Site — Healthcare & SMB Targeting Analysis with Detection Engineering
DRAGONFORCE posted 2 new victims (GB healthcare, US property management) on 2026-09-16. Healthcare and SMB orgs should patch edge devices and hunt for pre-encryption staging now.
INTERLOCK Ransomware Gang: Education & Municipal Government Hits Posted — Campaign Analysis & Detection Rules
INTERLOCK posted 2 new US victims on 2026-09-15 — a school district and a municipal government. K-12 and local government defenders should prioritize the CVE and detection guidance below.
AKIRA Ransomware Gang: 3 New Victims in 24 Hours — US Manufacturing & Energy Targeting With Edge-Device Exploitation Analysis
AKIRA posted 3 US victims on 2026-09-15 spanning Manufacturing and Energy & Utilities. Detection rules, hunt queries, and hardening priorities inside.
METAENCRYPTOR Ransomware Gang: 2 East Asian Manufacturing Giants Posted in 24h — Sector Targeting Analysis & Detection Rules
METAENCRYPTOR posted SFA Engineering (KR) and Nippon Steel (JP) to its leak site on 2026-09-15. Manufacturing and heavy industrial orgs in East Asia must act now.
CHAOS Ransomware Gang: 4 New US Victims Posted — Manufacturing & Healthcare Targeting Analysis With Detection Rules
CHAOS ransomware posted 4 US victims in 5 days, concentrated in Manufacturing and Healthcare. Detection rules, KQL hunts, and hardening guidance for edge-device and RMM exploitation below.
VEXY Ransomware Gang: 3 Technology Sector Victims in 5 Days — MSP Targeting Analysis & Detection Rules
VEXY RANSOMWARE posted 3 technology sector victims (GB, IN, BR) to its leak site in 5 days. Technology providers and MSPs must harden edge infrastructure and hunt for pre-encryption staging now.
AUDITTEAM Ransomware Gang: 8 Victims in 6 Days — RU/DE/IN/JP Targeting Analysis & Detection Rules
AUDITTEAM posted 8 victims in 6 days across RU, DE, IN, and JP, hitting Technology and Transportation. Edge-device CVE exploitation is a likely access vector — patch and hunt now.
Showing 50 of 491 reports. Archive expands automatically as new intel is generated.
Every Ransomware Report Includes SIGMA & KQL Detection Rules
Every intelligence briefing on this page includes at least one Sigma rule, a Microsoft Sentinel KQL hunt query, and an IOC check script — ready to drop into your SIEM. No paywall. No registration.