Ransomware Intelligence
Active ransomware gang campaigns, victim disclosures from leak sites, RaaS affiliate recruitment, and SIGMA detection rules for every known ransomware family targeting enterprise environments.
Ransomware — Archive & Latest
M3RX Ransomware Gang: 3 New Victims Posted — Manufacturing & Professional Services Under Siege
M3RX targets Manufacturing and Professional Services in DE, PT, and US. Immediate patching for Check Point and ScreenConnect required.
SAFEPAY Ransomware: DACH Region Blitz — Retail & Education Sectors Under Siege via Critical VPN Flaws
SAFEPAY targets German Retail/Edu sectors using ScreenConnect & VPN exploits. Immediate patching and detection required.
CISA KEV Flash: 8 Critical CVEs Under Active Attack — Fortinet, Check Point & Microsoft Targeted
CISA adds 8 actively exploited CVEs. Critical flaws in Fortinet, Arista, and Microsoft SharePoint allow RCE & auth bypass. Patch immediately.
GENESIS Ransomware Gang: 6 New Victims Posted — Critical Infrastructure & Manufacturing Targeted via Firewall Exploits
GENESIS ransomware claims 6 new US/CA victims. Immediate action required on Check Point & Cisco firewall flaws.
CRPXO Ransomware: Cross-Sector Surge & Firewall Exploitation — Detection Engineering Brief
CRPXO aggressively targets US Healthcare & Tech sectors via firewall and RMM flaws. Immediate patching of CVE-2026-50751 required.
SECTION9 Ransomware: Surge in LATAM & Global Attacks — Check Point & ScreenConnect Exploitation
SECTION9 claims 15+ new victims targeting Tech, Ag, and Retail. Active exploitation of Check Point and ScreenConnect vulnerabilities observed.
GLOBAL SECRET GROUP: 2026-07-26 Mass Victim Posting — Tech & Finance Sector Targeting via Critical VPN & RMM Exploits
Global Secret Group posts 15 new victims targeting Tech & Finance. Active exploitation of Check Point (CVE-2026-50751) and ScreenConnect (CVE-2024-1708) observed.
QILIN Ransomware: 16 New Victims in Global Surge — Education & Healthcare Sectors in Crosshairs as Critical CVEs Exploited
Qilin posts 16 new victims targeting Education, Healthcare, and Gov sectors. Active exploitation of ScreenConnect and Check Point CVEs detected.
EXFILSQUAD Ransomware: Surge in Critical Infrastructure Targeting — 14 New Victims & CVE Exploitation Analysis
EXFILSQUAD targets US/UK Gov & Tech sectors. 14 victims posted via ScreenConnect and Firewall exploits. Patch immediately.
INCRANSOM Ransomware: Cross-Border Healthcare & Legal Sector Targeting — Critical CVE Exploitation
INCRANSOM targets US/CH healthcare and legal firms via VPN/Remote Mgmt exploits. Immediate patching for Check Point & ScreenConnect required.
DEADLOCK Ransomware: Global Manufacturing & Gov Sector Assault — IOCs & Detection Engineering
DEADLOCK gang targets manufacturing & gov sectors via VPN/fw exploits. Immediate defensive actions required.
MONEYMESSAGE Gang: US Transportation & Energy Under Siege — Critical Firewall & Remote Access Exploitation
MONEYMESSAGE targets US Transportation and Energy sectors using active exploits for Check Point and Cisco vulnerabilities. Immediate patching required.
KILLSEC Gang: 3 New US/IN Victims — Financial & Healthcare Targeting & Detection Rules
KILLSEC claims 3 new US/IN victims in Finance & Healthcare. Detect specific CVEs and lateral movement TTPs now.
PLAY Ransomware Campaign: US & Spain Hospitality/Retail Hit — Detection Rules for ScreenConnect & Check Point Exploits
PLAY targets Hospitality/Retail in US/ES exploiting Check Point & ScreenConnect CVEs. Includes IOCs and Sigma detection logic.
AKIRA Ransomware: Critical VPN & RMM Exploitation Alert — 4 New Victims
AKIRA targets Manufacturing and Retail via VPN and RMM exploits. Immediate patching of ScreenConnect and Check Point CVEs required.
NOVA Ransomware: Global Tech Sector Surge & Critical Infrastructure Exploitation
NOVA aggressively targets Technology and Finance sectors via Check Point and Cisco exploits. Immediate patching and IOC hunting required.
KRYBIT Ransomware Gang: 4 New Victims Posted — Sector Targeting Analysis & Detection Rules
KRYBIT targets Indian Tech & Bulgarian Finance sectors using perimeter exploits. Immediate detection rules included.
THEGENTLEMEN Ransomware Gang: Critical Infrastructure Targeted — Active Exploitation of Check Point & Cisco Vulnerabilities
THEGENTLEMEN active targeting of Energy, Healthcare, and Logistics sectors. Urgent patching required for CVE-2026-50751 and CVE-2026-20131.
SPACEBEARS Ransomware: Global Surge in Tech & Business Services — CVE-Driven Attacks & Detection Engineering
SPACEBEARS posts 3 new victims across KR, CO, and IT. Tech and Business Services sectors face immediate risk from active CVE exploitation.
DRAGONFORCE Gang: 4 Victims Across Telecom & Finance — KEV-Driven Attacks & Detection Rules
DRAGONFORCE targets Telecom and Finance using CVE-2026-50751. Detection rules inside.
SAFEPAY Ransomware: German Manufacturing & Services Sector Targeted — Detection Rules for Active Exploits
SAFEPAY posts 9 new victims, primarily German manufacturers and business services, exploiting Check Point and ScreenConnect vulnerabilities.
CISA KEV Flash: 10 CVEs Added — Microsoft, Fortinet & SonicWall Under Active Attack
CISA adds 10 actively exploited CVEs. Critical RCE flaws in Microsoft SharePoint and Fortinet FortiSandbox require immediate remediation.
BLACKOUT Ransomware: Global Tech Sector Assault & Critical Infrastructure CVEs
BLACKOUT exploits ScreenConnect & Check Point flaws targeting Tech firms in JP, US, GB. Patch immediately.
AKIRA Ransomware Gang: US Infrastructure Under Siege — CVE Exploitation & Detection Engineering
AKIRA targets US critical infrastructure with 4 new victims in Telecom, Logistics, and Manufacturing. Detection rules inside.
NOVA Ransomware Gang: Global Tech Sector Surge & Critical CVE Exploitation
NOVA targets Tech/Biz Services globally via Check Point & ScreenConnect CVEs. Immediate patching and log review critical.
INCRANSOM Gang: Surge in Agriculture & Manufacturing Targets — Detection Engineering & IOCs
INCRANSOM posts 10 new victims targeting Agriculture & Manufacturing in US, Asia, & Africa. Immediate patching of Check Point & Cisco CVEs advised.
KRYBIT Ransomware: Global Surge Exploiting Perimeter Appliances and RMM Tools
KRYBIT claims 4 new victims across IL, MX, MY, and CZ, heavily targeting healthcare and business sectors. Immediate patching of Check Point and ScreenConnect vulnerabilities is critical.
INTERLOCK Ransomware Gang: Critical Infrastructure Surge — CVE-2026-50751 Analysis & Detection
INTERLOCK targets CA/US public sector & manufacturing. Patch Check Point VPN & ScreenConnect immediately to prevent encryption.
QILIN Ransomware: Global Surge Targets Healthcare, Agriculture, and Tech — CVE-2026-50751 Exploitation Confirmed
Qilin Gang claims 12 new victims across US, EU, and LATAM; exploits Check Point and Cisco vulnerabilities to breach critical sectors.
PLAY Ransomware: Critical Infrastructure Targeting via Edge Device Exploits
PLAY ransomware posted 5 victims targeting Telecom and Healthcare sectors in US/Europe. Immediate patching of Check Point and ScreenConnect CVEs required.
THEGENTLEMEN Ransomware: High-Volume Campaign Targeting Manufacturing & Financials — Detection Rules
THEGENTLEMEN group posts 15 new victims targeting Manufacturing and Financials across US/EU; urgent patching of ConnectWise and Check Point CVEs required.
DEADLOCK Ransomware: Global Surge In Business Services & Public Sector Targets
DEADLOCK gang posts 14 new victims across 8 countries. Critical patching for ConnectWise and Check Point CVEs required immediately.
DRAGONFORCE Ransomware: Global Campaign Targets Manufacturing & Business Services — Detection & Mitigation Guide
DRAGONFORCE posts 15 victims across manufacturing, business services, and telecom. Critical detection rules and IR guidance included.
AILOCK Ransomware: Critical Infrastructure Targeted in Japan & Spain — Check Point & Cisco Exploitation Active
AILOCK posts 4 new victims in JP/ES construction/logistics. Active exploitation of Check Point and Cisco CVEs detected.
CHAOS Ransomware Gang: Critical Infrastructure Surge in North America & Perimeter Bypass Analysis
CHAOS gang posts 3 new victims in CA/US targeting Pharma, Food, and Mfg. Prioritize patching ScreenConnect & Check Point CVEs.
ARCUSMEDIA Ransomware Gang: Global Campaign Intensifies — Critical Infrastructure CVEs & Detection Logic
ARCUSMEDIA adds 6 victims across 3 continents. Urgent detection needed for Check Point & ScreenConnect exploits.
D1R Ransomware Gang: Critical Tech & Manufacturing Breaches — CISA KEV Exploitation Analysis
D1R targets high-value Tech/Mfg giants (Synopsys, Bosch) using CISA KEVs. Immediate patching for Check Point & Cisco required.
D1R Ransomware Gang: Triple-Tap on Global Tech Giants — Critical CVE Exploitation Analysis
D1R targets Synopsys, Bosch, and ARM via Check Point and Cisco vulnerabilities. Immediate patching mandated.
D1R Ransomware Gang: High-Value Tech & Manufacturing Targets Hit — ConnectWise & Cisco Exploits Active
D1R claims Synopsys, Bosch, and ARM. Active exploitation of ConnectWise ScreenConnect and Cisco FMC vulnerabilities observed.
D1R Ransomware Campaign: Global Tech & Manufacturing Targets Spike — Critical CVE Exploitation & Detection Strategy
D1R targets Synopsys, Bosch, and ARM. Active exploitation of Check Point and Cisco CVEs requires immediate network isolation and patching.
ANUBIS Ransomware: Critical Infrastructure Exploits Target Healthcare and Business Services
ANUBIS ransomware claims 3 new victims targeting healthcare and business sectors via Check Point and ConnectWise exploits.
TITAN Ransomware: Perimeter Breach Campaigns Targeting Business Services & Construction
TITAN ransomware targets CZ/US Business Services and Construction. Active exploitation of Check Point and Cisco FMC vulnerabilities observed.
M3RX Ransomware Gang: 3 New Victims Posted — Business Services Targeted & Critical CVE Exploitation
M3RX posts 3 new victims targeting Business Services in US/IE. Immediate patching of ConnectWise ScreenConnect and Check Point Gateway CVEs required.
DOOMMAGEDDON Ransomware: Healthcare Sector Under Siege — Critical Firewall & Remote Access Exploitation
DOOMMAGEDDON targets Healthcare via Check Point & ScreenConnect flaws. Immediate patching and detection rules required.
PAYLOAD Ransomware Gang: Low-Volume Construction Targeting & Critical Firewall Vulnerability Exploitation
PAYLOAD gang targets construction sector (Roofinox) leveraging Check Point and Cisco firewall flaws. Detection rules inside.
BLACKWATER Ransomware: CN Targeting Confirmed & Critical Edge Firewall Exploitation Campaign
Blackwater targets CN entities. Active exploitation of Check Point, Cisco, and ConnectWise edge vulnerabilities confirmed.
CMDORGANIZATION Ransomware: Energy Sector Alert — Check Point & Cisco Exploits Active
CMDORGANIZATION claims Golden Star Resources (GH). Energy defenders must patch CVE-2026-50751 (Check Point) immediately.
INTERLOCK Ransomware Gang: Education Sector Targeting — Perimeter Exploit Analysis & IOCs
INTERLOCK claims Borger ISD, exploiting Check Point and ScreenConnect flaws. US Education entities must patch CVE-2026-50751 and CVE-2024-1708 immediately.
BRAINCIPHER Ransomware: US Manufacturing & Services Under Siege — Critical Firewall Exploitation Detected
BRAIN CIPHER targets US Manufacturing and Services sectors via Check Point and Cisco firewall vulnerabilities. Immediate patching required.
DEADLOCK Ransomware: Global Surge in Critical Infrastructure Attacks — IOCs & Detection Engineering
DEADLOCK posts 15 new victims targeting Construction, Healthcare, and Manufacturing. Immediate patching for Check Point and ScreenConnect required.
Showing 50 of 308 reports. Archive expands automatically as new intel is generated.
Every RansomwareReport Includes SIGMA & KQL Detection Rules
Every intelligence briefing on this page includes at least one Sigma rule, a Microsoft Sentinel KQL hunt query, and an IOC check script — ready to drop into your SIEM. No paywall. No registration.