Ransomware Intelligence
Active ransomware gang campaigns, victim disclosures from leak sites, RaaS affiliate recruitment, and SIGMA detection rules for every known ransomware family targeting enterprise environments.
Ransomware — Archive & Latest
GLOBAL SECRET GROUP Ransomware: 3 US Victims in 4 Days — Manufacturing, Retail & Healthcare Targeting Analysis with Detection Rules
Global Secret Group posted 3 US victims in 4 days across manufacturing, retail, and healthcare. Detection rules, KQL hunts, and hardening priorities for exposed perimeter and RMM access vectors.
BLACKWATER Ransomware Gang: 2 New Victims Posted on Leak Site — India & Argentina Targeting Analysis with Detection Rules
BLACKWATER posted 2 victims (IN, AR) to its dark web leak site on 2026-08-15. Healthcare & professional services orgs should hunt for VPN exploitation and pre-encryption staging now.
PANZER Ransomware Gang: 3 New Victims Posted — Central European Targeting, Sector Analysis & Detection Rules
PANZER posted 3 victims in 72 hours, hitting manufacturing and technology firms in CZ/DE. European industrials must harden VPN and RDP edges now.
QILIN Ransomware Gang: 28 New Victims Posted in 24 Hours — Cross-Sector Campaign Analysis, Initial Access CVEs & Detection Rules
QILIN posted 15+ victims in a single day spanning manufacturing, financial services, transportation, and education across 8 countries. Enterprise defenders must patch Check Point, ConnectWise, and Exchange CVEs now.
LOCKBIT5 Ransomware Gang: 5 New Victims Posted in 48 Hours — European Campaign Analysis, CVE Exploitation Links & Detection Rules
LOCKBIT5 posted 5 victims in 48 hours across Germany, Italy, and France, hitting technology, energy, agriculture, and professional services. Patch Check Point, ScreenConnect, and Exchange now.
MEDUSALOCKER Ransomware Gang: 5 New Victims Posted — Cross-Sector Campaign Analysis, Pre-Encryption Hunt Logic & Containment Playbook
MEDUSALOCKER posted 5 victims across tech, retail, manufacturing and transport in GB/DE/FR/ZA. Patch edge CVEs, hunt PsExec/WMI staging, isolate backup paths now.
XPL0ITRS Ransomware Gang: 3 New Victims Posted — Retail & Tech Sector Targeting Analysis with Detection Engineering
XPL0ITRS posted 3 new victims to its dark web leak site on 2026-08-15, spanning AU retail and US technology. Enterprises running Check Point, ScreenConnect, or Exchange must act now.
DIREWOLF Ransomware Gang: 6 Victims Posted in 48 Hours — Healthcare & Tech Targeting Analysis with Detection Rules
DIREWOLF posted 6 victims in a single burst across healthcare, tech, and financial services in GB/US/BR/IN. Detection rules and IR priorities for defenders inside.
PAYLOAD Ransomware Gang: 4 New Victims Posted in 5 Days — DACH/Levant Targeting Analysis & Detection Engineering
PAYLOAD posted 4 new victims across Jordan, Germany, and Switzerland, hitting financial services, manufacturing, professional services, and tech. Mid-market orgs in DACH and the Levant should harden VPN/RDP perimeters now.
CISA KEV Flash: 3 CVEs Added — Cisco Firewalls, Windows WinSock & Metabase Under Active Attack
CISA confirms active exploitation of Cisco ASA/FTD heap flaw, Windows WinSock use-after-free, and Metabase unauthenticated SQLi. Patch per CISA deadlines now.
THEGENTLEMEN Ransomware Gang: 15 Victims in a Single-Day Surge — Sector Analysis, CVE Correlation & Detection Rules
THEGENTLEMEN posted 15 victims in 24 hours spanning healthcare, manufacturing, retail and technology across 8 countries. Technology, healthcare and SMB-sector orgs must patch exposed gateways and hunt for pre-encryption staging now.
COINBASECARTEL Ransomware Gang: 4 New Victims Posted in 48 Hours — Professional Services, Agriculture & Manufacturing Targeting Analysis with Detection Rules
COINBASECARTEL posted 4 victims across GB, US, and JP in 48 hours, hitting professional services, agriculture, and manufacturing. Edge VPN and remote access exploitation likely vectors — patch and hunt now.
SILENTRANSOMGROUP: 5 Victims Posted in 72 Hours — Legal & Professional Services Targeting Analysis with Detection Rules
SILENTRANSOMGROUP posted 5 victims in 72 hours, concentrated on law firms and professional services in the US and Germany. Legal and professional services orgs must act now.
KRYBIT Ransomware: 5 Victims Posted in 48 Hours — Cross-Regional Campaign Hits Healthcare & Professional Services, Detection Rules Inside
KRYBIT posted 5 victims across TW, IN, SG, FI, and AR in 48 hours, including a healthcare org. Edge-device and RMM exploitation are the likely access vectors — hunt and patch now.
INCRANSOM Ransomware Gang: 5 Victims Posted in 24 Hours — Energy, Healthcare & Professional Services Targeting Analysis with Detection Rules
INCRANSOM posted 5 victims on Aug 12 spanning Technology, Energy, Healthcare and Professional Services across US/AU. Detection rules and IR priorities inside.
BLACKNEVAS Ransomware: MSP Supply-Chain Intrusion Yields 5 Victims in 48 Hours — Sector Analysis & Detection Engineering
BLACKNEVAS posted 5 victims in 48 hours, all downstream clients of compromised MSP 'Computer Country and Networks.' Technology, healthcare, and agri-food orgs in US/CA must act now.
MAJINAHANASHI Ransomware Gang: 5 Victims in 48 Hours — Cross-Sector Leak Activity, Likely Edge-CVE Access Paths & Detection Rules
MAJINAHANASHI posted 5 victims in ~48h across tech, healthcare and energy in US/LT/CL/CH; edge-VPN, RMM and Exchange/FMC CVE exploitation should be hunted now.
CLOP Ransomware Gang: 44 Victims Posted in Latest Leak Site Dump — Exploit-Driven Campaign Analysis & Detection Rules
CLOP posted 44 victims in its latest leak site wave, spanning tech, manufacturing, government & defense, and transportation across 8+ countries. Patch edge CVEs and hunt staging TTPs now.
GENESIS Ransomware Gang: 4 Victims Posted in 48 Hours — US Healthcare Under Active Targeting, Detection Rules Inside
GENESIS posted 4 victims to its dark web leak site in 48 hours, with 3 of 4 hitting US healthcare providers. Healthcare and mid-market US orgs should review edge device exposure and pre-encryption staging indicators now.
QILIN Ransomware Gang: 26 New Victims Posted in 100-Posting Window — APAC Expansion, Government Targeting & Detection Rules
QILIN posted 15 new victims in 72 hours spanning government, energy, and manufacturing across 8 countries — with heavy APAC expansion. Detection rules and hunt queries inside.
UNSAFE Ransomware Gang: 3 New Victims in 72 Hours — Tech & Manufacturing Targeting Analysis with Detection Rules
UNSAFE posted 3 victims in 72 hours across Technology and Manufacturing (US/IN). KEV-linked perimeter CVEs in play — detection rules, hunt queries, and hardening guidance inside.
DIREWOLF Ransomware Gang: 10 Victims Posted in 24 Hours — Cross-Sector Campaign Analysis, Initial Access CVEs & Detection Rules
DIREWOLF posted 10 victims in a single day across healthcare, finance, and tech in the US, BR, PH, ES, and DE. Enterprises running Check Point, Cisco FMC, Exchange, or ScreenConnect must patch and hunt now.
GLOBAL SECRET GROUP Ransomware: 3 New Victims in 24 Hours — Financial Services Under Fire, VPN Edge Exploitation Suspected
GLOBAL SECRET GROUP posted 3 new victims on 2026-08-10, hitting financial services firms in the US and Greece. Detection rules, KQL hunts, and hardening steps inside.
WALLSTREET Ransomware Gang: 2 New US Victims Posted — Manufacturing & Technology Sector Targeting Analysis with Detection Rules
WALLSTREET ransomware posted two US victims (manufacturing, technology) to its leak site on 2026-08-10. Security teams in industrial and tech sectors should review VPN/edge device exposure and lateral movement detections now.
CISA KEV Flash: 6 CVEs Added — Progress LoadMaster, JetBrains TeamCity & N-able N-central Under Active Attack
CISA confirms active exploitation of 6 new CVEs hitting LoadMaster, TeamCity, N-central, Tomcat, and Langflow. Unauthenticated RCE across CI/CD, MSP, and edge infrastructure. Patch now.
THEGENTLEMEN Ransomware Gang: 25 New Victims Posted — Sector Targeting Analysis & Detection Rules
THEGENTLEMEN posted 25 victims to its .onion leak site, hitting manufacturing, professional services, and technology firms across DE, US, and EU. Detection rules and IR priorities inside.
PANZER Ransomware Gang: 2 New Victims Posted — Energy & Media Targeting Analysis, Detection Rules & IR Playbook
PANZER ransomware posted 2 new victims on its dark web leak site, hitting Energy & Utilities in Thailand and media in Nigeria. Edge-device CVE exploitation signals demand immediate action.
BRAVOX Ransomware Gang: 2 New Victims Posted — European Healthcare & Industrial Targeting Analysis with Detection Rules
BRAVOX posted 2 new victims on its leak site (FR healthcare, CH industrial). European healthcare and mid-market orgs should audit VPN/edge device exposure and deploy the included detection content now.
KRYBIT Ransomware Gang: 5 New Victims Posted in 24 Hours — French SMB Surge, Cross-Continent Reach & Detection Rules
KRYBIT posted 5 victims to its dark web leak site on 2026-08-07, concentrated in France with reach into South Africa and Peru. Technology and professional services firms should audit VPN and remote access exposure now.
LYNX Ransomware Gang: 2 New Victims Posted on Leak Site — Campaign Analysis, KEV Exploitation Links & Detection Rules
LYNX ransomware posted 2 new victims (GB, US) to its dark web leak site on 2026-08-06. Edge-device and MSP-tool CVE exploitation is the suspected access vector — patch and hunt now.
HELIX Ransomware Gang: 5 New Victims Posted in 24 Hours — Transportation & Financial Services Surge, Detection Rules Included
HELIX posted 5 victims to its dark web leak site on 2026-08-07, hitting Transportation and Financial Services across US/CA. Detection rules and IR playbook inside.
DARK PROJECT Ransomware Gang: 3 New Victims Posted — Energy, Transportation & Automotive Targeting Analysis With Detection Rules
DARK PROJECT posted 3 victims to its .onion leak site on 2026-08-04, hitting US energy and automotive firms plus a Philippine logistics operator. Energy, transportation, and mid-market enterprises should review perimeter CVEs and lateral movement detections now.
DRAGONFORCE Ransomware Gang: 4 US Victims in Single-Day Leak Batch — SMB Targeting Analysis & Detection Rules
DragonForce posted 4 US victims in one day across healthcare, manufacturing, and hospitality. SMB-focused campaign analysis, Sigma rules, KQL hunts, and IR guidance.
QILIN Ransomware Gang: 11 New Victims in 72 Hours — Manufacturing Surge, Edge-Device CVE Exploitation & Detection Rules
QILIN posted 11 victims across 7 countries in 72 hours, heavily targeting manufacturing and professional services. Energy, financial, and industrial orgs must patch edge CVEs and hunt for staging indicators now.
BARRACUDA Ransomware Gang: 4 New Victims Posted in 48 Hours — Manufacturing & Healthcare Targeting Analysis with Detection Rules
BARRACUDA posted 4 new victims across CN, US, and KR in 48 hours, hitting manufacturing, healthcare, and technology firms. Security teams must verify perimeter patching and hunt pre-encryption staging now.
CL0P Ransomware Gang: 40 New Victims Posted — Sector Targeting Analysis & Detection Rules
CL0P posted 40 victims on 2026-08-05, mostly sector-unattributed with Technology and Financial Services confirmed; edge, finance and tech teams should patch KEVs and hunt pre-encryption staging.
INCRANSOM Ransomware Gang: 10 Victims in 5 Days — Cross-Sector Campaign Hits Healthcare, Energy & Quantum Tech
INCRANSOM posted 10 victims across 7 sectors and 6 countries in 5 days, including healthcare, energy, and technology firms. Patch Check Point, Cisco FMC, and ScreenConnect now.
OROVA Ransomware Gang: Active Campaign Targeting US/HK Manufacturing & Finance — Critical CVE Alert
OROVA targeting US/HK Manufacturing & Finance. Patch Check Point, ScreenConnect, and Cisco CVEs immediately.
THEGENTLEMEN Ransomware: Aggressive Multi-Vector Campaign Exploiting Perimeter & RMM Flaws
THEGENTLEMEN claims 16 new victims, exploiting Check Point & ScreenConnect CVEs. Finance and Tech sectors must patch immediately.
ANUBIS Ransomware: US Healthcare & Retail Targeted — Critical CVE Exploitation Analysis
ANUBIS gang posts 3 US healthcare & retail victims. Immediate patching of Check Point and Cisco vulnerabilities required.
SAFEPAY Ransomware: Global Manufacturing & Tech Targeted — Critical Vulnerability Exploitation Alert
SAFEPAY claims 9 new victims, heavily targeting US Manufacturing. Immediate patching of Check Point and ScreenConnect CVEs is required.
GAMMAX Ransomware Gang: Critical Infrastructure Targeted via Check Point & Cisco Firewall Exploits
GAMMAX targets Energy & Professional Services in SA/CO. Exploiting Check Point & Cisco CVEs. Immediate patching of perimeter devices required.
KRYBIT Ransomware Gang: 5 New Victims Posted — Multi-Region Targeting Analysis & Detection Rules
KRYBIT posts 5 new victims across ZA, NG, FR, and MX targeting Professional Services, Government, and Finance. Immediate detection for Check Point and ConnectWise exploits required.
GENESIS Ransomware: 3 New Victims Posted — US/DK Tech & Manufacturing Sector Attack
Genesis ransomware posts 3 new victims including Boyum IT. Active exploitation of Check Point VPN & ScreenConnect CVEs confirmed.
PLAY Ransomware Gang: US Sector Blitz — 3 New Victims & Critical Firewall/VPN Exploits
PLAY targets US Retail, Mfg, and Professional Services. Urgent action required for Check Point and Cisco vulnerabilities.
COINBASECARTEL: Critical Perimeter Exploitation Campaign Targets Healthcare & Industrial Sectors
COINBASECARTEL exploits Check Point and Cisco vulnerabilities to target healthcare and manufacturing. Patch KEVs and hunt for indicators.
CRPXO Ransomware: Critical Infrastructure Assault on Turkey & US Healthcare — Active Exploit Analysis
CRPXO exploits CVE-2024-1708 and firewall flaws to target TR finance and US healthcare. Immediate patching required.
QILIN Ransomware: Aggressive Multi-Vector Campaign Targeting US & Europe
Qilin claims 15 new victims, heavily targeting US Professional Services and Tech. Detect CVEs and lateral movement with provided IOCs.
AURORA Ransomware Gang: Surge in DACH/US Sector Targeting — Critical CVE Exploitation & Detection Logic
AURORA posts 4 new victims across NL, DE, and US. Manufacturing and Tech sectors face immediate threat from active CVE exploitation.
DRAGONFORCE Ransomware: Global Surge in Cross-Sector Extortion & Critical Infrastructure CVE Exploitation
DRAGONFORCE posts 4 new victims targeting UK/US/TH hospitality and manufacturing. Immediate patching for ConnectWise & Check Point CVEs required.
Showing 50 of 365 reports. Archive expands automatically as new intel is generated.
Every RansomwareReport Includes SIGMA & KQL Detection Rules
Every intelligence briefing on this page includes at least one Sigma rule, a Microsoft Sentinel KQL hunt query, and an IOC check script — ready to drop into your SIEM. No paywall. No registration.