Ransomware Intelligence
Active ransomware gang campaigns, victim disclosures from leak sites, RaaS affiliate recruitment, and SIGMA detection rules for every known ransomware family targeting enterprise environments.
Ransomware — Archive & Latest
KRYBIT Ransomware Gang: 5 New Victims Posted — Healthcare and Education Targeting With Perimeter-Edge CVE Pressure
KRYBIT posted 5 new victims across healthcare, professional services, education and agri-food; defenders should prioritize edge-VPN, ScreenConnect, Exchange and pre-encryption staging hunts.
PANZER Ransomware: 4 Victims Posted in 72 Hours — European & Middle East Targeting, Sector Analysis & Detection Rules
PANZER posted 4 victims in 72 hours across Saudi Arabia, Germany, and Indonesia, hitting government, education, and professional services. Detection rules and IR priorities inside.
THEGENTLEMEN Ransomware Gang: 5 Victims in 5 Days — Transportation, Healthcare & Technology Under Active Fire
THEGENTLEMEN posted 5 victims across 4 countries in 5 days, hitting Transportation, Healthcare, Retail, and Tech. Enterprises with exposed VPNs, RDP, or unpatched KEV flaws should hunt now.
DIREWOLF Ransomware: 6 Victims in 5 Days — Cross-Sector Campaign Hits US Tech, Thai Energy, and Global Manufacturing
DIREWOLF posted 6 victims in 5 days spanning tech, energy, transportation, and manufacturing across US, ZA, TH, BR, ID. Edge-VPN and remote access exploitation suspected. Patch and hunt now.
SPACEBEARS Ransomware Gang: 3 Fresh Leak-Site Victims — US/IT Sector Pressure, KEV Edge Exposure & Pre-Encryption Hunt Rules
SPACEBEARS posted 3 US/IT victims across retail, professional services and healthcare; patch KEV edge/RMM flaws and hunt pre-encryption staging now.
VEXY Ransomware Gang: 5 New Victims in 4 Days — India & LATAM Campaign, Sector Analysis & Detection Rules
VEXY Ransomware posted 5 victims in 4 days spanning manufacturing, retail, and hospitality across India, Ecuador, and Brazil. Edge-VPN CVEs flagged as likely entry vectors.
QILIN Ransomware Gang: 7 Victims in 5 Days — Government, Energy & Manufacturing Targeting with Detection Rules
Qilin (Agenda) posted 7 victims in 5 days across CA, US, CL, TR, AR — hitting government, energy co-ops, and manufacturing. KEV-linked edge exploitation suspected; detection rules included.
STORM Ransomware Gang: 8 New Victims in 72 Hours — Energy, Financial & Healthcare Targeting Analysis with Detection Rules
STORM posted 8 victims across CA, US, and AU in 72 hours, hitting energy, financial services, transportation, agriculture, and healthcare. Detection rules and IR priorities inside.
INCRANSOM Ransomware Gang: 11 New Victims in 5 Days — Manufacturing & Healthcare Surge, Detection Rules Inside
INCRANSOM posted 11 victims across 8 countries since Aug 31, hitting manufacturing, healthcare, education and financial services. Detection rules and hunt queries included.
SILENTRANSOMGROUP Ransomware Campaign: 4 Victims Posted in 48 Hours — BigLaw Targeting Analysis, Detection Rules & Hunting Queries
SILENTRANSOMGROUP posted 4 victims in 48 hours, including major US law firms Greenberg Traurig and Holland & Knight. Professional services orgs must act now.
AKIRA Ransomware Gang: 9 New Victims in 72 Hours — Sector Targeting Analysis, CVE Correlation & Detection Rules
AKIRA posted 9 victims in 72 hours spanning manufacturing, financial services, retail and transportation across the US, NL and DE. Detection rules and IR priorities inside.
LOCKBIT5 Ransomware Gang: 6 Victims Posted in 24 Hours — Financial Services & Manufacturing Targeting Analysis with Detection Rules
LOCKBIT5 posted 6 victims across US, JP, and NL on 2026-08-31, hitting financial services, legal, and manufacturing firms. Detection rules and IR priorities inside.
CISA KEV Flash: 11 CVEs Added — PaperCut, Citrix NetScaler & Linux Kernel Under Active Exploitation
CISA confirms active exploitation of 11 CVEs incl. PaperCut NG/MF, Citrix NetScaler, Linux Kernel, JFrog Artifactory & ownCloud. Patch now — federal deadlines apply.
KRYBIT Ransomware Gang: 14 Victims Posted in Single-Day Surge — Cross-Sector Campaign Analysis & Detection Engineering
KRYBIT posted 14 victims in 24 hours spanning healthcare, education, tech, and transport across 9 countries. Detection rules, KQL hunts, and IR priorities inside.
OROVA Ransomware Gang: 4 New Victims Posted — APAC Technology, Manufacturing & Hospitality Targeting Analysis & Detection Rules
OROVA posted 4 new victims to its leak site this week, concentrated in Taiwan and Hong Kong across Technology, Manufacturing, and Hospitality. VPN-edge exploitation and double extortion remain the gang's primary playbook.
BRAINCIPHER Ransomware Gang: 4 New Victims in 24 Hours — Cross-Sector Campaign Analysis & Detection Rules
BRAINCIPHER posted 4 victims across AE, DE, and US on 2026-08-31, spanning healthcare, technology, and professional services. Edge-VPN patching and pre-encryption staging hunts are urgent.
WALLSTREET Ransomware: US Healthcare and Education Victims Posted — Leak-Site Signals, CVE Access Paths & Detection Rules
WALLSTREET posted Cedar County Memorial Hospital and Andover; US healthcare and education teams should harden VPN, Exchange, RMM and link-following paths now.
CHAOS Ransomware Gang: 3 Victims Posted in 48 Hours — US/GB/AU Targeting, KEV-Linked Access Paths & Detection Rules
CHAOS posted corematerials.com, macallister.com and singleton.com within 48h. Manufacturing and unclassified GB/AU firms should harden VPN/RDP/RMM paths now.
DIREWOLF Ransomware Gang: 3 Healthcare & Tech Victims Posted in 24 Hours — Sector Targeting Analysis & Detection Rules
DIREWOLF posted Hospital Clínico Universidad de Chile, Erdem Hospital, and THQ Nordic to its leak site on 2026-08-30. Healthcare and technology organizations must act now.
MAJINAHANASHI Ransomware Gang: 2 New Victims Posted — Campaign Analysis & Detection Engineering
MAJINAHANASHI posted 2 new victims to its dark web leak site on 2026-08-29. Multi-country targeting observed; enterprise teams should prioritize edge-VPN patching and pre-encryption detection.
THEGENTLEMEN Ransomware Gang: 16 Victims Posted in 48 Hours — Sector Targeting Analysis & Detection Rules
THEGENTLEMEN posted 16 victims in a single burst across 8 countries, hitting transportation, healthcare, energy, and tech. Enterprises with Check Point gateways and ScreenConnect exposure should hunt now.
IAH6477 Ransomware Gang: 4 US Victims Posted in 72 Hours — Manufacturing Surge, Edge-Device Exploitation & Detection Rules
IAH6477 posted 4 US victims in 72 hours, heavily skewed toward manufacturing. Detection rules, KQL hunts, and hardening guidance for the CVEs driving initial access.
EMPERADOR Ransomware Gang: 4 New Victims Posted — Energy Sector Targeting, Edge-Device Exploitation & Detection Rules
EMPERADOR posted 4 victims in 72 hours including a Korean renewables operator. Energy, Tech, and Transportation orgs must patch Check Point & Exchange flaws and hunt pre-encryption staging now.
INCRANSOM Ransomware Gang: 5 New Victims Posted — Manufacturing & Energy Targeting Analysis with Detection Rules
INCRANSOM posted 5 victims in 72 hours across Manufacturing, Energy, and Tech in MX/US/ZA. Industrial-sector orgs must verify VPN patching and deploy pre-encryption detection now.
MEDUSALOCKER Ransomware Gang: 5 New Victims Posted — Cross-Sector Extortion Wave & Detection Rules
MEDUSALOCKER posted 5 victims across healthcare, manufacturing, retail and agriculture in TH/MX/GH/AU; defenders should hunt VPN/RDP access, staging and shadow-copy tampering now.
AKIRA Ransomware Gang: 9 New Victims in 4 Days — Manufacturing Surge, VPN Exploitation & Detection Engineering
AKIRA posted 9 new victims in 96 hours, heavily weighted toward US manufacturing. VPN edge exploitation and ConnectWise abuse remain prime initial vectors — manufacturing and healthcare must act now.
LOCKBIT5 Ransomware: 5 Victims Posted in 24 Hours — Healthcare & Tech Sector Surge with Detection Rules
LOCKBIT5 posted 5 victims across healthcare, professional services, and technology sectors in TN, NL, BE, CZ, and US. Detection rules and IR priorities inside.
SILENTRANSOMGROUP: 10 Victims Posted in 48 Hours — Multi-Country Extortion Campaign, Initial Access CVEs & Detection Engineering
SILENTRANSOMGROUP posted 10 new victims across multiple countries in a 48-hour burst. Enterprise teams should patch KEV-listed edge/remote-access flaws and hunt for pre-encryption staging now.
CISA KEV Flash: 11 CVEs Added — Citrix NetScaler, Zimbra, Linux Kernel & Microsoft SQL Server Under Active Attack
CISA confirmed active exploitation of 11 CVEs spanning Citrix NetScaler, Zimbra, Oracle WebLogic proxy, Linux Kernel, SQL Server, Gitea, TrueConf and Red Hat. Patch immediately.
KRYBIT Ransomware Gang: 13 Victims in 48 Hours — Cross-Sector Campaign Analysis, CVE Exploitation Ties & Detection Rules
KRYBIT posted 13 victims in 48 hours across finance, healthcare, agriculture, and retail spanning 7 countries. Security teams should review edge-device patching and pre-encryption staging indicators now.
SHADOWBYT3$ Ransomware Gang: 3 New Victims Posted in 24 Hours — Agriculture, Tech & Education Targeting Analysis with Detection Rules
SHADOWBYT3$ posted 3 new victims in 24 hours spanning agriculture, technology, and education across Indonesia and the UK. Defenders should act on KEV-listed edge and RMM vulnerabilities now.
GLOBAL SECRET GROUP Ransomware: 3 US Victims Posted in 24 Hours — Transportation, Retail & Government/Defense Targeting Analysis with Detection Rules
GLOBAL SECRET GROUP posted 3 US victims across transportation, retail, and government/defense sectors on 2026-08-25. Includes Sigma, KQL, and hardening guidance.
CHAOS Ransomware Gang: 3 New Victims Posted in 24 Hours — Cross-Continental Targeting Analysis & Detection Engineering
CHAOS ransomware posted 3 victims across NL, US, and CN on 2026-08-25, spanning professional services and SMB sectors. Edge-VPN patching and lateral movement detection are urgent priorities.
STORM Ransomware Gang: 7 New Victims Posted in 72 Hours — Government, Healthcare & Financial Sector Alert
STORM posted 7 victims in 72 hours to its leak site, hitting US government, healthcare, banking, and manufacturing orgs. Edge device CVEs and RDP exposure are the likely entry points — hunt now.
DRAGONFORCE Ransomware Gang: 4 New Victims Posted in 24 Hours — Cross-Border Campaign Analysis & Detection Engineering
DragonForce posted 4 new victims across AR, BR, AE, and CA in a single day, hitting technology, financial services, and industrial sectors. Perimeter VPN and RMM exploitation likely vectors — patch and hunt now.
DARK PROJECT Ransomware: 4 US Victims Posted in 24 Hours — Professional Services & Manufacturing in the Crosshairs
DARK PROJECT posted 4 US victims in a single day, hitting CPA firms, hospitality, and engineering manufacturers. Professional services and SMB manufacturers should harden VPN edge and RDP access now.
BOOBA PROJECT Ransomware Gang: 2 New Victims Posted — Financial & Professional Services Targeting Analysis with Detection Rules
BOOBA PROJECT posted 2 new victims (US financial services, MX legal) on 2026-08-24. Edge-device CVE exploitation suspected; financial and professional services orgs should hunt now.
BARRACUDA Ransomware Gang: 3 New Victims Posted — Healthcare & Manufacturing Campaign Analysis with Detection Rules
BARRACUDA posted 3 new victims in 24h across healthcare and manufacturing in the US and South Korea. Dental/healthcare providers and industrial firms must verify VPN patch status and hunt for pre-encryption staging now.
METAENCRYPTOR Ransomware Gang: 7 Victims in 24 Hours — Cross-Sector Blitz Targeting Transportation, Energy & Healthcare with VPN & Supply Chain Intrusion Vectors
METAENCRYPTOR posted 7 victims across CA, US, DE, JP in a single day, hitting transportation, energy, healthcare, and manufacturing. Likely exploiting Check Point CVE-2026-50751 and ScreenConnect CVE-2024-1708 for initial access.
KAZU Ransomware Gang: 9 Healthcare & Professional Services Victims Posted in Single-Day Surge — Targeting Analysis & Detection Rules
KAZU posted 9 victims in one day, 7 of them healthcare orgs across 6 countries. Healthcare and SaaS providers must hunt for VPN exploitation and pre-encryption staging now.
SHINYHUNTERS Extortion Campaign: 4 New Victims Posted — Tech, Healthcare & Financial Sector Analysis with Detection Rules
SHINYHUNTERS posted 4 new victims in 72 hours spanning Technology, Healthcare, and Financial Services in the US and Israel. Detection rules and IR priorities inside.
COINBASECARTEL Ransomware Gang: 13 Victims Posted in 24 Hours — Financial Services Blitz, Sector Analysis & Detection Rules
COINBASECARTEL posted 13 victims on 2026-08-22, with financial services taking the heaviest hit (5 of 13). US, NZ, AR, PH, and ID organizations should harden VPN/RDP perimeters and hunt for pre-encryption staging now.
QILIN Ransomware Gang: 15 New Victims Posted in 72 Hours — Cross-Sector Campaign Targeting Energy, Hospitality & Manufacturing
QILIN posted 15 victims across 8 countries in 3 days, hitting energy, hospitality, and manufacturing. Orgs running Check Point, ConnectWise, or Exchange should verify patch posture now.
RHYSIDA Ransomware Gang: 3 New US Victims in 48 Hours — Energy, Healthcare & Education Targeting Analysis with Detection Rules
RHYSIDA posted 3 US victims in 48 hours spanning energy, healthcare, and education. Detection rules, hunt queries, and IR priorities for defenders inside.
DEADLOCK Ransomware Gang: 3 New Victims Posted to Dark Web Leak Site — Cross-Continental Campaign Hits UK, Taiwan, and Turkey
DEADLOCK ransomware posted 3 new victims across GB, TW, and TR in 48 hours, hitting transportation and professional services. Edge VPN and RMM exploitation likely involved — patch and hunt now.
DIREWOLF Ransomware Gang: 13 Victims Posted in Single-Day Leak Site Surge — Sector Analysis & Detection Rules
DIREWOLF posted 13 victims to its dark web leak site on 2026-08-21, hitting Education, Financial Services, Technology and Transportation orgs across US, MX, DK, AE, NL and CA. Patch perimeter CVEs and hunt for pre-encryption staging now.
CISA KEV Flash: 8 CVEs Added — TrueConf, VMware vCenter & Microsoft SharePoint Under Active Attack
CISA confirms 8 CVEs under active exploitation (Aug 17–20): TrueConf RCE, VMware vCenter path traversal, SharePoint auth bypass, Microsoft IKE double-free, MLflow SSRF, Ray RCE, macOS Screen Sharing auth flaw. Patch now.
IAH6477 Ransomware Gang: 3 US Victims Posted in 24 Hours — Retail, Finance & Tech Targeting with Detection Rules
IAH6477 posted 3 US victims in 24 hours across retail, financial services, and technology. Edge VPN and MSP tooling CVEs in play — patch and hunt now.
SILENTRANSOMGROUP: 3 New Victim Postings on Dark Web Leak Site — US Professional Services Targeting Analysis & Detection Engineering
SILENTRANSOMGROUP posted 3 victims to its leak site this week, including US law firm Troutman Pepper Locke. Professional services and legal orgs should hunt for VPN-edge exploitation and pre-encryption staging now.
TITAN Ransomware Gang: 9 Italian Victims Posted in Single-Day Blitz — Sector Analysis, CVE Correlation & Detection Rules
TITAN ransomware posted 9 Italian victims in 24 hours across manufacturing, energy, and professional services. Detection rules and IR priorities inside.
Showing 50 of 420 reports. Archive expands automatically as new intel is generated.
Every RansomwareReport Includes SIGMA & KQL Detection Rules
Every intelligence briefing on this page includes at least one Sigma rule, a Microsoft Sentinel KQL hunt query, and an IOC check script — ready to drop into your SIEM. No paywall. No registration.