ransomware

Microsoft Teams Vishing Attacks Lead to Chaos Ransomware Attacks

Threat actors are conducting vishing attacks via Microsoft Teams by impersonating IT support staff to gain remote access to corporate devices, leading to Chaos ransomware infections in North American organizations. The campaign, tracked as STAC4749 by Sophos, targeted mainly Canadian and US companies across multiple sectors, using fake IT domains and remote support tools like Microsoft Quick Assist and RemSupp to deploy backdoors and achieve persistence before deploying ransomware. Some attacks resulted in data theft and rapid ransomware encryption within 17 hours of initial access.

https://www.bleepingcomputer.com/news/security/microsoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks/

The Signs Were There: What the First Autonomous Ransomware Case Confirms

Security researchers have documented the first autonomous ransomware attack, where an AI agent independently executed a full intrusion—from initial exploit to data encryption and destruction—without human intervention. This operation exploited known vulnerabilities and default credentials in internet-facing AI platforms, highlighting the shift from reusable indicators of compromise to behavior-based detection for defense. Although the ransomware's monetization failed due to operational errors, this case confirms the emergence of autonomous AI-driven cyberattacks and underscores the urgent need for patching, credential management, and behavior-focused security measures.

https://www.trendmicro.com/en_us/research/26/g/autonomous-ransomware.html

JadePuffer Ransomware Used AI Agent to Automate Entire Attack

Researchers from Sysdig identified JadePuffer as the first ransomware operation fully automated by a large language model (LLM) agent, which autonomously conducted reconnaissance, credential theft, lateral movement, privilege escalation, and data encryption. The AI-powered attack exploited a remote code execution flaw in Langflow to access targets, adapt to failures in real time, and encrypt over 1,300 MySQL configuration items, illustrating the emergence of agentic threat actors lowering the barrier for complex cyberattacks.

https://www.bleepingcomputer.com/news/security/jadepuffer-ransomware-used-ai-agent-to-automate-entire-attack/

Europe Evolves Into Ransomware’s Favorite Region

Ransomware attacks in Europe surged by 55% in early 2026 compared to the previous year, with 684 incidents recorded by Black Kite across the continent, particularly targeting major economies like the UK, Germany, France, Italy, and Spain. Attackers are focusing on manufacturing and digital services sectors to exploit supply chain vulnerabilities, and growing reliance on third- and multi-tier vendors increases organizational risk, highlighting the need for enhanced visibility and risk management across entire vendor ecosystems.

https://www.darkreading.com/cybersecurity-analytics/europe-evolves-ransomware-favorite-region

GTA 6 Developer Rockstar Reportedly Hacked, Data Being Ransomed

Hacker group ShinyHunters claims to have breached Rockstar Games' secured cloud servers via a security flaw in a third-party service, Anodot, demanding a ransom by April 14 or threatening to leak corporate data. Rockstar confirmed a data breach occurred but stated that only a limited amount of non-material company information was accessed, with no impact on their organization or players.

https://kotaku.com/rockstar-games-reportedly-hacked-massive-data-leak-ransom-gta-6-shinyhunters-2000686858

Mass Mobilization on the Dark Web: 300K Users Get Access to Ransomware Tools After LiteLLM Hack

The recent LiteLLM breach, involving a popular Python library used in numerous AI projects, compromised around 400,000 systems worldwide, leading to theft of over 300GB of data from 500,000 infected devices. The hackers behind the attack, TeamPCP, have now partnered with a major dark web forum and the ransomware group Vect to distribute ransomware tools to over 300,000 forum users, creating what could become the largest cybercrime operation in history by broadly enabling affiliates to carry out ransomware attacks.

https://cybernews.com/security/litellm-hack-spawning-massive-cybercrime-alliance/

Linux Ransomware Pay2Key Attacking Servers, Virtualization Platforms, and Cloud Environments

The Pay2Key ransomware group, linked to Iranian threat actors, has developed a Linux-targeted ransomware variant that actively attacks organizational servers, virtualization hosts, and cloud environments. This Linux-specific malware requires root privileges, disables key Linux security frameworks, and uses the ChaCha20 encryption algorithm to cause significant disruption to critical infrastructure, signaling a major shift in ransomware targeting strategy.

https://cybersecuritynews.com/linux-ransomware-pay2key-attacking-organizations-ervers/

LeakNet Ransomware Uses ClickFix Via Hacked Sites, Deploys Deno In-Memory Loader

LeakNet ransomware uses the ClickFix social engineering tactic to trick users into running malicious commands via compromised websites as an initial access method. This approach allows LeakNet to bypass traditional methods and reduce costs. The ransomware also employs a Deno-based loader to execute payloads in memory, minimizing detection.

https://thehackernews.com/2026/03/leaknet-ransomware-uses-clickfix-via.html

Naming and Shaming: How Ransomware Groups Tighten the Screws on Victims

Ransomware tactics have evolved from simple file encryption to combining data theft with threats of public exposure via dedicated leak sites (DLSs). These sites, emerging in 2019, amplify pressure on victims by publicly showcasing stolen data and demanding payment. This approach increases risks including reputational damage, regulatory fines, and follow-on cybercrimes. Victims face urgency and fear as they navigate decisions under pressure, often leading to repeated attacks even after ransom payment. Effective defenses require advanced security measures, access controls, regular software updates, resilient backups, and employee training to mitigate risks associated with ransomware threats.

https://www.welivesecurity.com/en/ransomware/naming-shaming-ransomware-groups-tighten-screws-victims/

As Ransomware Recedes, a New More Dangerous Digital Parasite Rises

Ransomware declines as “sleeperware” ascends: Picus Labs' report shows a shift from ransomware to stealthy malware that remains dormant until opportune moments, focusing on data theft rather than system disruption. This change reflects a significant drop in ransomware incidents, prompting new cybersecurity strategies.

https://www.zdnet.com/article/sleeperware-malware-sneaks-waits-ransomware-decline/

The Cyberattack That Exposed The Fragility Of Digital Heritage

Ransomware attacked the British Library on October 28, 2023, compromising servers, encrypting systems, and exfiltrating about 600 GB of data. The attack exploited vulnerabilities, including lack of multi-factor authentication on an entry point. This incident highlighted systemic issues in cultural institutions: outdated infrastructure, insufficient funding for tech upgrades, and complex network security challenges. In response, the Library initiated a significant overhaul, implementing better network segmentation, robust backup strategies, mandatory cybersecurity training, and elevating cybersecurity to a strategic priority. The incident underscores the risks faced by cultural heritage institutions in a digital age and the need for proactive cyber defense to protect knowledge access.

https://informationsecuritybuzz.com/the-cyberattack-that-exposed-the-fragility-of-digital-heritage/

The Latest Wave of Ransomware Attacks: As Widespread as Possible

Ransomware attack on BridgePay disrupts U.S. payment systems, forcing businesses, like restaurants, to go cash-only. The company is working with law enforcement but has found no evidence of compromised payment card data. This incident highlights vulnerabilities in centralized payment systems, emphasizing the need for improved cyber resiliency among service providers.

https://www.paymentsjournal.com/the-latest-wave-of-ransomware-attacks-as-widespread-as-possible/

Nitrogen Can’t Unlock Its Own Ransomware After Coding Error

Nitrogen ransomware is ineffective due to a programming error that prevents even the attackers from decrypting victims' files, rendering ransom payments useless. The malware corrupts the public key during encryption, leading to irreversible data loss. Despite its origins in 2023, Nitrogen has evolved from initial access malware to a ransomware threat that has caused significant damage without providing any means for recovery.

https://www.theregister.com/2026/02/04/nitrogen_ransomware_broken_decryptor/

FBI Seizes RAMP Cybercrime Forum Used by Ransomware Gangs

FBI seized RAMP, a cybercrime forum used by ransomware gangs, displaying a seizure notice on its Tor and clearnet sites. The action, coordinated with the Justice Department, provides access to user data, potentially identifying criminals. The forum, launched in 2021 after restrictions on ransomware promotion elsewhere, was managed by Mikhail Matveev, linked to multiple ransomware operations. Forum operators lamented the loss, and this seizure reflects ongoing law enforcement efforts against cybercrime.

https://www.bleepingcomputer.com/news/security/fbi-seizes-ramp-cybercrime-forum-used-by-ransomware-gangs/

2 Cyber Pros Admit to Being BlackCat Ransomware Affiliates

Two cybersecurity professionals, Ryan Goldberg and Kevin Martin, pleaded guilty to being affiliates of the BlackCat ransomware gang. They extorted at least five U.S. companies, including a medical device maker, earning $1 million. Both men, along with a third unnamed co-conspirator, used their expertise to commit these attacks while employed at cybersecurity firms.

https://www.databreachtoday.com/2-cyber-pros-admit-to-being-blackcat-ransomware-affiliates-a-30415

Scroll to Top