|
10 | 10 | | 16 April 2025 | CrazyHunter | https://www.trendmicro.com/en_us/research/25/d/crazyhunter-campaign.html | |
11 | 11 | | 8 April 2025 | RansomEXX | https://www.microsoft.com/en-us/security/blog/2025/04/08/exploitation-of-clfs-zero-day-leads-to-ransomware-activity/ | |
12 | 12 | | 1 April 2025 | Qilin | https://news.sophos.com/en-us/2025/04/01/sophos-mdr-tracks-ongoing-campaign-by-qilin-affiliates-targeting-screenconnect/ | |
13 | | -| 31 March 2025 | BlackSuit | https://thedfirreport.com/2025/03/31/fake-zoom-ends-in-blacksuit-ransomware/ | |
14 | 13 | | 26 March 2025 | RansomHub, BianLian, Medusa, Play | https://www.welivesecurity.com/en/eset-research/shifting-sands-ransomhub-edrkillshifter/ | |
15 | 14 | | 26 March 2025 | QWCrypt | https://www.bitdefender.com/en-us/blog/businessinsights/redcurl-qwcrypt-ransomware-technical-deep-dive | |
16 | 15 | | 25 March 2025 | NightSpire | https://www.s-rminform.com/latest-thinking/ransomware-in-focus-meet-nightspire | |
17 | 16 | | 20 March 2025 | RansomHub | https://www.security.com/threat-intelligence/ransomhub-betruger-backdoor | |
18 | 17 | | 19 March 2025 | Hunters International | https://www.esentire.com/blog/from-access-to-encryption-dissecting-hunters-internationals-latest-ransomware-attack | |
19 | | -| 12 March 2025 | Medusa | https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a | |
20 | 18 | | 10 March 2025 | Qilin | https://www.picussecurity.com/resource/blog/qilin-ransomware | |
21 | 19 | | 6 March 2025 | Medusa | https://www.security.com/threat-intelligence/medusa-ransomware-attacks | |
22 | 20 | | 20 February 2025 | NailaoLocker | https://www.trendmicro.com/en_us/research/25/b/updated-shadowpad-malware-leads-to-ransomware-deployment.html | |
23 | | -| 19 February 2025 | Ghost/Cring | https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-050a | |
24 | 21 | | 18 February 2025 | NailaoLocker | https://www.orangecyberdefense.com/global/blog/cert-news/meet-nailaolocker-a-ransomware-distributed-in-europe-by-shadowpad-and-plugx-backdoors | |
25 | 22 | | 13 February 2025 | RA World | https://www.security.com/threat-intelligence/chinese-espionage-ransomware | |
26 | 23 | | 10 February 2025 | Various Groups | https://connect.cybercx.com.au/dfir-threat-report-au-2025 | |
|
34 | 31 | | 10 September 2024 | CosmicBeetle* (Scarab, ScRansom, NONAME, RansomHub) | https://www.welivesecurity.com/en/eset-research/cosmicbeetle-steps-up-probation-period-ransomhub/ | |
35 | 32 | | 10 September 2024 | Cicada3301 | https://unit42.paloaltonetworks.com/repellent-scorpius-cicada3301-ransomware/ | |
36 | 33 | | 3 September 2024 | Cicada3301 | https://blog.morphisec.com/cicada3301-ransomware-threat-analysis | |
37 | | -| 28 August 2024 | *Br0k3r (NoEscape, Ransomhouse, BlackCat, Pay2Key) | https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-241a | |
38 | 34 | | 28 August 2024 | BlackByte | https://blog.talosintelligence.com/blackbyte-blends-tried-and-true-tradecraft-with-newly-disclosed-vulnerabilities-to-support-ongoing-attacks/ | |
39 | | -| 26 August 2024 | BlackSuit | https://thedfirreport.com/2024/08/26/blacksuit-ransomware/ | |
40 | 35 | | 20 August 2024 | Everest | https://www.aha.org/system/files/media/file/2024/08/hc3-tlp-clear-threat-actor-profile-everest-ransomware-group-august-20-2024.pdf | |
41 | 36 | | 14 August 2024 | RansomHub | https://news.sophos.com/en-us/2024/08/14/edr-kill-shifter/ | |
42 | 37 | | 14 August 2024 | INC Ransom | https://www.guidepointsecurity.com/blog/update-from-the-ransomware-trenches/ | |
|
0 commit comments