Home/Blog/Ransomware

Ransomware

Ransomware attacks continue to evolve with double-extortion tactics and targeted enterprise campaigns. This section analyzes ransomware groups, attack patterns, and defensive strategies CISOs must understand.

62 articles

iRhythm Ransomware: Patient Data Stolen and Ransom Demanded (June 2024)
ransomware

iRhythm Ransomware: Patient Data Stolen and Ransom Demanded (June 2024)

iRhythm suffered a ransomware attack resulting in the theft of patient data and a ransom demand. The incident highlights the ongoing targeting of healthcare organizations in North America.

Jun 22, 20265 min read
Read More
Standard Bank Ransomware: Prinz Eugen Targets Recent Files, No Ransom Note (June 2024)
ransomware

Standard Bank Ransomware: Prinz Eugen Targets Recent Files, No Ransom Note (June 2024)

Standard Bank suffered a ransomware attack by the Prinz Eugen group, resulting in encryption and exfiltration of data. Attackers prioritized recent files and left no ransom note, complicating response.

Jun 21, 20265 min read
Read More
The Gentlemen RaaS Ransomware: GentleKiller EDR Framework Disables 400 Security Processes (March 2025)
ransomware

The Gentlemen RaaS Ransomware: GentleKiller EDR Framework Disables 400 Security Processes (March 2025)

The Gentlemen ransomware-as-a-service operation compromised hundreds of organizations globally by deploying the GentleKiller EDR framework, disabling 400 security processes prior to ransomware deployment.

Jun 20, 20265 min read
Read More
Oltenia Ransomware: Gentlemen Group Deploys EDR Killers to Evade Defenses (June 2024)
ransomware

Oltenia Ransomware: Gentlemen Group Deploys EDR Killers to Evade Defenses (June 2024)

Romanian energy provider Oltenia suffered a ransomware attack by the Gentlemen group, who used multiple EDR killer tools—including the custom GentleKiller utility—to disable security defenses and enable widespread data encryption.

Jun 19, 20265 min read
Read More
Unnamed US Services Firm Ransomware: DragonForce Abuses Microsoft Teams Relay (June 2024)
ransomware

Unnamed US Services Firm Ransomware: DragonForce Abuses Microsoft Teams Relay (June 2024)

An unnamed US services firm suffered a critical ransomware attack by DragonForce, resulting in data encryption and exfiltration. The attackers leveraged Microsoft Teams relay servers for covert command-and-control.

Jun 18, 20265 min read
Read More
Unnamed Major U.S. Services Company Ransomware: DragonForce Abuses Microsoft Teams TURN Relays (June 2024)
ransomware

Unnamed Major U.S. Services Company Ransomware: DragonForce Abuses Microsoft Teams TURN Relays (June 2024)

An unnamed major U.S. services company suffered a critical ransomware attack by DragonForce, who leveraged Microsoft Teams TURN relays to hide command-and-control traffic. Attackers exfiltrated data and encrypted systems using custom malware and BYOVD techniques.

Jun 17, 20265 min read
Read More
Malicious Infrastructure Ransomware: EtherRAT Distributed via Blockchain-Enabled C2 (June 2026)
ransomware

Malicious Infrastructure Ransomware: EtherRAT Distributed via Blockchain-Enabled C2 (June 2026)

A global malicious infrastructure distributed EtherRAT ransomware and phishing pages, leveraging the Ethereum blockchain for resilient C2 communication. Attackers gained full remote access to compromised systems.

Jun 16, 20265 min read
Read More
Conti Ransomware: Ukrainian National Pleads Guilty in Global Attack Scheme (June 2024)
ransomware

Conti Ransomware: Ukrainian National Pleads Guilty in Global Attack Scheme (June 2024)

Conti ransomware operators, including Oleksii Lytvynenko, targeted over 1,000 computers and networks worldwide, leading to system encryption and data theft. The attacks resulted in at least $150 million in ransom payments and widespread operational disruption.

Jun 15, 20265 min read
Read More
California Water Service Ransomware: Handala Claims 5GB Data Leak (June 2024)
ransomware

California Water Service Ransomware: Handala Claims 5GB Data Leak (June 2024)

California Water Service suffered a ransomware attack by the Iran-linked Handala group, exposing 5GB of sensitive customer data and administrative credentials. The breach included compromise of the RTKBase GNSS platform and lateral movement to billing systems.

Jun 14, 20265 min read
Read More
Conti Ransomware: Ukrainian National Pleads Guilty in Global Attack Disrupting Critical Sectors (June 2024)
ransomware

Conti Ransomware: Ukrainian National Pleads Guilty in Global Attack Disrupting Critical Sectors (June 2024)

Conti ransomware operations, led in part by Oleksii Oleksiyovych Lytvynenko, compromised data from over 1,000 organizations worldwide, including healthcare, government, and enterprises. The group extorted over $150 million in ransoms and caused significant operational disruption.

Jun 13, 20265 min read
Read More
The Gentlemen Ransomware: 478 Victims Hit by Worm-Like Propagation (April 2026)
ransomware

The Gentlemen Ransomware: 478 Victims Hit by Worm-Like Propagation (April 2026)

The Gentlemen ransomware group, led by LARVA-368, compromised 478 organizations globally using worm-like propagation and double extortion tactics. Enterprise environments, especially in Thailand, the UK, Brazil, Germany, and India, were heavily impacted.

Jun 12, 20265 min read
Read More
SilabRAT Trojan Ransomware: Session Hijacking Enables Cryptocurrency Theft (June 2025)
ransomware

SilabRAT Trojan Ransomware: Session Hijacking Enables Cryptocurrency Theft (June 2025)

SilabRAT ransomware campaigns have enabled threat actors to hijack user sessions and steal cryptocurrency by bypassing multi-factor authentication. The malware’s use of browser profile cloning and hidden remote desktop access has resulted in high-severity financial theft globally.

Jun 11, 20265 min read
Read More