Dark Side Intelligence Category

Ransomware Intelligence

Active ransomware gang campaigns, victim disclosures from leak sites, RaaS affiliate recruitment, and SIGMA detection rules for every known ransomware family targeting enterprise environments.

365 reports availableRefreshed every 5 minutes

Ransomware — Archive & Latest

50 reports loaded
Ransomware

GLOBAL SECRET GROUP Ransomware: 3 US Victims in 4 Days — Manufacturing, Retail & Healthcare Targeting Analysis with Detection Rules

Global Secret Group posted 3 US victims in 4 days across manufacturing, retail, and healthcare. Detection rules, KQL hunts, and hardening priorities for exposed perimeter and RMM access vectors.

Aug 17, 2026
Read →
Ransomware

BLACKWATER Ransomware Gang: 2 New Victims Posted on Leak Site — India & Argentina Targeting Analysis with Detection Rules

BLACKWATER posted 2 victims (IN, AR) to its dark web leak site on 2026-08-15. Healthcare & professional services orgs should hunt for VPN exploitation and pre-encryption staging now.

Aug 17, 2026
Read →
Ransomware

PANZER Ransomware Gang: 3 New Victims Posted — Central European Targeting, Sector Analysis & Detection Rules

PANZER posted 3 victims in 72 hours, hitting manufacturing and technology firms in CZ/DE. European industrials must harden VPN and RDP edges now.

Aug 17, 2026
Read →
Ransomware

QILIN Ransomware Gang: 28 New Victims Posted in 24 Hours — Cross-Sector Campaign Analysis, Initial Access CVEs & Detection Rules

QILIN posted 15+ victims in a single day spanning manufacturing, financial services, transportation, and education across 8 countries. Enterprise defenders must patch Check Point, ConnectWise, and Exchange CVEs now.

Aug 17, 2026
Read →
Ransomware

LOCKBIT5 Ransomware Gang: 5 New Victims Posted in 48 Hours — European Campaign Analysis, CVE Exploitation Links & Detection Rules

LOCKBIT5 posted 5 victims in 48 hours across Germany, Italy, and France, hitting technology, energy, agriculture, and professional services. Patch Check Point, ScreenConnect, and Exchange now.

Aug 16, 2026
Read →
Ransomware

MEDUSALOCKER Ransomware Gang: 5 New Victims Posted — Cross-Sector Campaign Analysis, Pre-Encryption Hunt Logic & Containment Playbook

MEDUSALOCKER posted 5 victims across tech, retail, manufacturing and transport in GB/DE/FR/ZA. Patch edge CVEs, hunt PsExec/WMI staging, isolate backup paths now.

Aug 16, 2026
Read →
Ransomware

XPL0ITRS Ransomware Gang: 3 New Victims Posted — Retail & Tech Sector Targeting Analysis with Detection Engineering

XPL0ITRS posted 3 new victims to its dark web leak site on 2026-08-15, spanning AU retail and US technology. Enterprises running Check Point, ScreenConnect, or Exchange must act now.

Aug 16, 2026
Read →
Ransomware

DIREWOLF Ransomware Gang: 6 Victims Posted in 48 Hours — Healthcare & Tech Targeting Analysis with Detection Rules

DIREWOLF posted 6 victims in a single burst across healthcare, tech, and financial services in GB/US/BR/IN. Detection rules and IR priorities for defenders inside.

Aug 16, 2026
Read →
Ransomware

PAYLOAD Ransomware Gang: 4 New Victims Posted in 5 Days — DACH/Levant Targeting Analysis & Detection Engineering

PAYLOAD posted 4 new victims across Jordan, Germany, and Switzerland, hitting financial services, manufacturing, professional services, and tech. Mid-market orgs in DACH and the Levant should harden VPN/RDP perimeters now.

Aug 15, 2026
Read →
Ransomware

CISA KEV Flash: 3 CVEs Added — Cisco Firewalls, Windows WinSock & Metabase Under Active Attack

CISA confirms active exploitation of Cisco ASA/FTD heap flaw, Windows WinSock use-after-free, and Metabase unauthenticated SQLi. Patch per CISA deadlines now.

Aug 15, 2026
Read →
Ransomware

THEGENTLEMEN Ransomware Gang: 15 Victims in a Single-Day Surge — Sector Analysis, CVE Correlation & Detection Rules

THEGENTLEMEN posted 15 victims in 24 hours spanning healthcare, manufacturing, retail and technology across 8 countries. Technology, healthcare and SMB-sector orgs must patch exposed gateways and hunt for pre-encryption staging now.

Aug 15, 2026
Read →
Ransomware

COINBASECARTEL Ransomware Gang: 4 New Victims Posted in 48 Hours — Professional Services, Agriculture & Manufacturing Targeting Analysis with Detection Rules

COINBASECARTEL posted 4 victims across GB, US, and JP in 48 hours, hitting professional services, agriculture, and manufacturing. Edge VPN and remote access exploitation likely vectors — patch and hunt now.

Aug 14, 2026
Read →
Ransomware

SILENTRANSOMGROUP: 5 Victims Posted in 72 Hours — Legal & Professional Services Targeting Analysis with Detection Rules

SILENTRANSOMGROUP posted 5 victims in 72 hours, concentrated on law firms and professional services in the US and Germany. Legal and professional services orgs must act now.

Aug 14, 2026
Read →
Ransomware

KRYBIT Ransomware: 5 Victims Posted in 48 Hours — Cross-Regional Campaign Hits Healthcare & Professional Services, Detection Rules Inside

KRYBIT posted 5 victims across TW, IN, SG, FI, and AR in 48 hours, including a healthcare org. Edge-device and RMM exploitation are the likely access vectors — hunt and patch now.

Aug 13, 2026
Read →
Ransomware

INCRANSOM Ransomware Gang: 5 Victims Posted in 24 Hours — Energy, Healthcare & Professional Services Targeting Analysis with Detection Rules

INCRANSOM posted 5 victims on Aug 12 spanning Technology, Energy, Healthcare and Professional Services across US/AU. Detection rules and IR priorities inside.

Aug 13, 2026
Read →
Ransomware

BLACKNEVAS Ransomware: MSP Supply-Chain Intrusion Yields 5 Victims in 48 Hours — Sector Analysis & Detection Engineering

BLACKNEVAS posted 5 victims in 48 hours, all downstream clients of compromised MSP 'Computer Country and Networks.' Technology, healthcare, and agri-food orgs in US/CA must act now.

Aug 13, 2026
Read →
Ransomware

MAJINAHANASHI Ransomware Gang: 5 Victims in 48 Hours — Cross-Sector Leak Activity, Likely Edge-CVE Access Paths & Detection Rules

MAJINAHANASHI posted 5 victims in ~48h across tech, healthcare and energy in US/LT/CL/CH; edge-VPN, RMM and Exchange/FMC CVE exploitation should be hunted now.

Aug 12, 2026
Read →
Ransomware

CLOP Ransomware Gang: 44 Victims Posted in Latest Leak Site Dump — Exploit-Driven Campaign Analysis & Detection Rules

CLOP posted 44 victims in its latest leak site wave, spanning tech, manufacturing, government & defense, and transportation across 8+ countries. Patch edge CVEs and hunt staging TTPs now.

Aug 12, 2026
Read →
Ransomware

GENESIS Ransomware Gang: 4 Victims Posted in 48 Hours — US Healthcare Under Active Targeting, Detection Rules Inside

GENESIS posted 4 victims to its dark web leak site in 48 hours, with 3 of 4 hitting US healthcare providers. Healthcare and mid-market US orgs should review edge device exposure and pre-encryption staging indicators now.

Aug 12, 2026
Read →
Ransomware

QILIN Ransomware Gang: 26 New Victims Posted in 100-Posting Window — APAC Expansion, Government Targeting & Detection Rules

QILIN posted 15 new victims in 72 hours spanning government, energy, and manufacturing across 8 countries — with heavy APAC expansion. Detection rules and hunt queries inside.

Aug 11, 2026
Read →
Ransomware

UNSAFE Ransomware Gang: 3 New Victims in 72 Hours — Tech & Manufacturing Targeting Analysis with Detection Rules

UNSAFE posted 3 victims in 72 hours across Technology and Manufacturing (US/IN). KEV-linked perimeter CVEs in play — detection rules, hunt queries, and hardening guidance inside.

Aug 10, 2026
Read →
Ransomware

DIREWOLF Ransomware Gang: 10 Victims Posted in 24 Hours — Cross-Sector Campaign Analysis, Initial Access CVEs & Detection Rules

DIREWOLF posted 10 victims in a single day across healthcare, finance, and tech in the US, BR, PH, ES, and DE. Enterprises running Check Point, Cisco FMC, Exchange, or ScreenConnect must patch and hunt now.

Aug 10, 2026
Read →
Ransomware

GLOBAL SECRET GROUP Ransomware: 3 New Victims in 24 Hours — Financial Services Under Fire, VPN Edge Exploitation Suspected

GLOBAL SECRET GROUP posted 3 new victims on 2026-08-10, hitting financial services firms in the US and Greece. Detection rules, KQL hunts, and hardening steps inside.

Aug 10, 2026
Read →
Ransomware

WALLSTREET Ransomware Gang: 2 New US Victims Posted — Manufacturing & Technology Sector Targeting Analysis with Detection Rules

WALLSTREET ransomware posted two US victims (manufacturing, technology) to its leak site on 2026-08-10. Security teams in industrial and tech sectors should review VPN/edge device exposure and lateral movement detections now.

Aug 10, 2026
Read →
Ransomware

CISA KEV Flash: 6 CVEs Added — Progress LoadMaster, JetBrains TeamCity & N-able N-central Under Active Attack

CISA confirms active exploitation of 6 new CVEs hitting LoadMaster, TeamCity, N-central, Tomcat, and Langflow. Unauthenticated RCE across CI/CD, MSP, and edge infrastructure. Patch now.

Aug 9, 2026
Read →
Ransomware

THEGENTLEMEN Ransomware Gang: 25 New Victims Posted — Sector Targeting Analysis & Detection Rules

THEGENTLEMEN posted 25 victims to its .onion leak site, hitting manufacturing, professional services, and technology firms across DE, US, and EU. Detection rules and IR priorities inside.

Aug 9, 2026
Read →
Ransomware

PANZER Ransomware Gang: 2 New Victims Posted — Energy & Media Targeting Analysis, Detection Rules & IR Playbook

PANZER ransomware posted 2 new victims on its dark web leak site, hitting Energy & Utilities in Thailand and media in Nigeria. Edge-device CVE exploitation signals demand immediate action.

Aug 9, 2026
Read →
Ransomware

BRAVOX Ransomware Gang: 2 New Victims Posted — European Healthcare & Industrial Targeting Analysis with Detection Rules

BRAVOX posted 2 new victims on its leak site (FR healthcare, CH industrial). European healthcare and mid-market orgs should audit VPN/edge device exposure and deploy the included detection content now.

Aug 7, 2026
Read →
Ransomware

KRYBIT Ransomware Gang: 5 New Victims Posted in 24 Hours — French SMB Surge, Cross-Continent Reach & Detection Rules

KRYBIT posted 5 victims to its dark web leak site on 2026-08-07, concentrated in France with reach into South Africa and Peru. Technology and professional services firms should audit VPN and remote access exposure now.

Aug 7, 2026
Read →
Ransomware

LYNX Ransomware Gang: 2 New Victims Posted on Leak Site — Campaign Analysis, KEV Exploitation Links & Detection Rules

LYNX ransomware posted 2 new victims (GB, US) to its dark web leak site on 2026-08-06. Edge-device and MSP-tool CVE exploitation is the suspected access vector — patch and hunt now.

Aug 7, 2026
Read →
Ransomware

HELIX Ransomware Gang: 5 New Victims Posted in 24 Hours — Transportation & Financial Services Surge, Detection Rules Included

HELIX posted 5 victims to its dark web leak site on 2026-08-07, hitting Transportation and Financial Services across US/CA. Detection rules and IR playbook inside.

Aug 7, 2026
Read →
Ransomware

DARK PROJECT Ransomware Gang: 3 New Victims Posted — Energy, Transportation & Automotive Targeting Analysis With Detection Rules

DARK PROJECT posted 3 victims to its .onion leak site on 2026-08-04, hitting US energy and automotive firms plus a Philippine logistics operator. Energy, transportation, and mid-market enterprises should review perimeter CVEs and lateral movement detections now.

Aug 6, 2026
Read →
Ransomware

DRAGONFORCE Ransomware Gang: 4 US Victims in Single-Day Leak Batch — SMB Targeting Analysis & Detection Rules

DragonForce posted 4 US victims in one day across healthcare, manufacturing, and hospitality. SMB-focused campaign analysis, Sigma rules, KQL hunts, and IR guidance.

Aug 6, 2026
Read →
Ransomware

QILIN Ransomware Gang: 11 New Victims in 72 Hours — Manufacturing Surge, Edge-Device CVE Exploitation & Detection Rules

QILIN posted 11 victims across 7 countries in 72 hours, heavily targeting manufacturing and professional services. Energy, financial, and industrial orgs must patch edge CVEs and hunt for staging indicators now.

Aug 6, 2026
Read →
Ransomware

BARRACUDA Ransomware Gang: 4 New Victims Posted in 48 Hours — Manufacturing & Healthcare Targeting Analysis with Detection Rules

BARRACUDA posted 4 new victims across CN, US, and KR in 48 hours, hitting manufacturing, healthcare, and technology firms. Security teams must verify perimeter patching and hunt pre-encryption staging now.

Aug 6, 2026
Read →
Ransomware

CL0P Ransomware Gang: 40 New Victims Posted — Sector Targeting Analysis & Detection Rules

CL0P posted 40 victims on 2026-08-05, mostly sector-unattributed with Technology and Financial Services confirmed; edge, finance and tech teams should patch KEVs and hunt pre-encryption staging.

Aug 5, 2026
Read →
Ransomware

INCRANSOM Ransomware Gang: 10 Victims in 5 Days — Cross-Sector Campaign Hits Healthcare, Energy & Quantum Tech

INCRANSOM posted 10 victims across 7 sectors and 6 countries in 5 days, including healthcare, energy, and technology firms. Patch Check Point, Cisco FMC, and ScreenConnect now.

Aug 5, 2026
Read →
Ransomware

OROVA Ransomware Gang: Active Campaign Targeting US/HK Manufacturing & Finance — Critical CVE Alert

OROVA targeting US/HK Manufacturing & Finance. Patch Check Point, ScreenConnect, and Cisco CVEs immediately.

Aug 4, 2026
Read →
Ransomware

THEGENTLEMEN Ransomware: Aggressive Multi-Vector Campaign Exploiting Perimeter & RMM Flaws

THEGENTLEMEN claims 16 new victims, exploiting Check Point & ScreenConnect CVEs. Finance and Tech sectors must patch immediately.

Aug 4, 2026
Read →
Ransomware

ANUBIS Ransomware: US Healthcare & Retail Targeted — Critical CVE Exploitation Analysis

ANUBIS gang posts 3 US healthcare & retail victims. Immediate patching of Check Point and Cisco vulnerabilities required.

Aug 3, 2026
Read →
Ransomware

SAFEPAY Ransomware: Global Manufacturing & Tech Targeted — Critical Vulnerability Exploitation Alert

SAFEPAY claims 9 new victims, heavily targeting US Manufacturing. Immediate patching of Check Point and ScreenConnect CVEs is required.

Aug 3, 2026
Read →
Ransomware

GAMMAX Ransomware Gang: Critical Infrastructure Targeted via Check Point & Cisco Firewall Exploits

GAMMAX targets Energy & Professional Services in SA/CO. Exploiting Check Point & Cisco CVEs. Immediate patching of perimeter devices required.

Aug 2, 2026
Read →
Ransomware

KRYBIT Ransomware Gang: 5 New Victims Posted — Multi-Region Targeting Analysis & Detection Rules

KRYBIT posts 5 new victims across ZA, NG, FR, and MX targeting Professional Services, Government, and Finance. Immediate detection for Check Point and ConnectWise exploits required.

Aug 2, 2026
Read →
Ransomware

GENESIS Ransomware: 3 New Victims Posted — US/DK Tech & Manufacturing Sector Attack

Genesis ransomware posts 3 new victims including Boyum IT. Active exploitation of Check Point VPN & ScreenConnect CVEs confirmed.

Aug 2, 2026
Read →
Ransomware

PLAY Ransomware Gang: US Sector Blitz — 3 New Victims & Critical Firewall/VPN Exploits

PLAY targets US Retail, Mfg, and Professional Services. Urgent action required for Check Point and Cisco vulnerabilities.

Aug 1, 2026
Read →
Ransomware

COINBASECARTEL: Critical Perimeter Exploitation Campaign Targets Healthcare & Industrial Sectors

COINBASECARTEL exploits Check Point and Cisco vulnerabilities to target healthcare and manufacturing. Patch KEVs and hunt for indicators.

Aug 1, 2026
Read →
Ransomware

CRPXO Ransomware: Critical Infrastructure Assault on Turkey & US Healthcare — Active Exploit Analysis

CRPXO exploits CVE-2024-1708 and firewall flaws to target TR finance and US healthcare. Immediate patching required.

Aug 1, 2026
Read →
Ransomware

QILIN Ransomware: Aggressive Multi-Vector Campaign Targeting US & Europe

Qilin claims 15 new victims, heavily targeting US Professional Services and Tech. Detect CVEs and lateral movement with provided IOCs.

Aug 1, 2026
Read →
Ransomware

AURORA Ransomware Gang: Surge in DACH/US Sector Targeting — Critical CVE Exploitation & Detection Logic

AURORA posts 4 new victims across NL, DE, and US. Manufacturing and Tech sectors face immediate threat from active CVE exploitation.

Jul 31, 2026
Read →
Ransomware

DRAGONFORCE Ransomware: Global Surge in Cross-Sector Extortion & Critical Infrastructure CVE Exploitation

DRAGONFORCE posts 4 new victims targeting UK/US/TH hospitality and manufacturing. Immediate patching for ConnectWise & Check Point CVEs required.

Jul 31, 2026
Read →

Showing 50 of 365 reports. Archive expands automatically as new intel is generated.

Free Detection Rules Included

Every RansomwareReport Includes SIGMA & KQL Detection Rules

Every intelligence briefing on this page includes at least one Sigma rule, a Microsoft Sentinel KQL hunt query, and an IOC check script — ready to drop into your SIEM. No paywall. No registration.