Home/Blog/Ransomware

Ransomware

Ransomware attacks continue to evolve with double-extortion tactics and targeted enterprise campaigns. This section analyzes ransomware groups, attack patterns, and defensive strategies CISOs must understand.

90 articles

Transport for London Ransomware: Scattered Spider Disrupts Services (August 2024)
ransomware

Transport for London Ransomware: Scattered Spider Disrupts Services (August 2024)

Transport for London suffered a high-severity ransomware attack by the Scattered Spider group in August 2024, causing service disruptions and operational compromise. Two men have pleaded guilty in the UK for their roles in the incident.

Jun 26, 20265 min read
Read More
Woodgnat Ransomware: Mistic RAT Enables Multi-Industry Access (April 2026)
ransomware

Woodgnat Ransomware: Mistic RAT Enables Multi-Industry Access (April 2026)

Woodgnat, an initial access broker, leveraged the new Mistic RAT to compromise organizations globally, enabling ransomware groups to infiltrate networks. The campaign targeted education, insurance, IT, and professional services sectors using advanced social engineering and lateral movement.

Jun 25, 20265 min read
Read More
FFmpeg Ransomware: PixelSmash Flaw Enables Remote Code Execution (June 2024)
ransomware

FFmpeg Ransomware: PixelSmash Flaw Enables Remote Code Execution (June 2024)

FFmpeg and downstream projects suffered a critical ransomware incident exploiting CVE-2026-8461, allowing remote code execution via crafted media files. Attackers leveraged the MagicYUV decoder flaw to compromise major media platforms.

Jun 24, 20265 min read
Read More
The Gentlemen Ransomware Operation Ransomware: GentleKiller Framework Disables Security Software (June 2024)
ransomware

The Gentlemen Ransomware Operation Ransomware: GentleKiller Framework Disables Security Software (June 2024)

The Gentlemen Ransomware-as-a-Service group deployed the GentleKiller framework to disable over 400 security products, including Microsoft Defender and CrowdStrike, prior to ransomware deployment. This allowed their attacks to bypass endpoint protection and increase impact across Southeast Asia, South America, and Western Europe.

Jun 23, 20265 min read
Read More
iRhythm Ransomware: Patient Data Stolen and Ransom Demanded (June 2024)
ransomware

iRhythm Ransomware: Patient Data Stolen and Ransom Demanded (June 2024)

iRhythm suffered a ransomware attack resulting in the theft of patient data and a ransom demand. The incident highlights the ongoing targeting of healthcare organizations in North America.

Jun 22, 20265 min read
Read More
Standard Bank Ransomware: Prinz Eugen Targets Recent Files, No Ransom Note (June 2024)
ransomware

Standard Bank Ransomware: Prinz Eugen Targets Recent Files, No Ransom Note (June 2024)

Standard Bank suffered a ransomware attack by the Prinz Eugen group, resulting in encryption and exfiltration of data. Attackers prioritized recent files and left no ransom note, complicating response.

Jun 21, 20265 min read
Read More
The Gentlemen RaaS Ransomware: GentleKiller EDR Framework Disables 400 Security Processes (March 2025)
ransomware

The Gentlemen RaaS Ransomware: GentleKiller EDR Framework Disables 400 Security Processes (March 2025)

The Gentlemen ransomware-as-a-service operation compromised hundreds of organizations globally by deploying the GentleKiller EDR framework, disabling 400 security processes prior to ransomware deployment.

Jun 20, 20265 min read
Read More
Oltenia Ransomware: Gentlemen Group Deploys EDR Killers to Evade Defenses (June 2024)
ransomware

Oltenia Ransomware: Gentlemen Group Deploys EDR Killers to Evade Defenses (June 2024)

Romanian energy provider Oltenia suffered a ransomware attack by the Gentlemen group, who used multiple EDR killer tools—including the custom GentleKiller utility—to disable security defenses and enable widespread data encryption.

Jun 19, 20265 min read
Read More
Unnamed US Services Firm Ransomware: DragonForce Abuses Microsoft Teams Relay (June 2024)
ransomware

Unnamed US Services Firm Ransomware: DragonForce Abuses Microsoft Teams Relay (June 2024)

An unnamed US services firm suffered a critical ransomware attack by DragonForce, resulting in data encryption and exfiltration. The attackers leveraged Microsoft Teams relay servers for covert command-and-control.

Jun 18, 20265 min read
Read More
Unnamed Major U.S. Services Company Ransomware: DragonForce Abuses Microsoft Teams TURN Relays (June 2024)
ransomware

Unnamed Major U.S. Services Company Ransomware: DragonForce Abuses Microsoft Teams TURN Relays (June 2024)

An unnamed major U.S. services company suffered a critical ransomware attack by DragonForce, who leveraged Microsoft Teams TURN relays to hide command-and-control traffic. Attackers exfiltrated data and encrypted systems using custom malware and BYOVD techniques.

Jun 17, 20265 min read
Read More
Malicious Infrastructure Ransomware: EtherRAT Distributed via Blockchain-Enabled C2 (June 2026)
ransomware

Malicious Infrastructure Ransomware: EtherRAT Distributed via Blockchain-Enabled C2 (June 2026)

A global malicious infrastructure distributed EtherRAT ransomware and phishing pages, leveraging the Ethereum blockchain for resilient C2 communication. Attackers gained full remote access to compromised systems.

Jun 16, 20265 min read
Read More
Conti Ransomware: Ukrainian National Pleads Guilty in Global Attack Scheme (June 2024)
ransomware

Conti Ransomware: Ukrainian National Pleads Guilty in Global Attack Scheme (June 2024)

Conti ransomware operators, including Oleksii Lytvynenko, targeted over 1,000 computers and networks worldwide, leading to system encryption and data theft. The attacks resulted in at least $150 million in ransom payments and widespread operational disruption.

Jun 15, 20265 min read
Read More