Wednesday, September 16, 2026
Follow on LinkedIn

Ransomware

Hackers Using New Blackhat AI Tool MessiahGPT to Generate Ransomware and Phishing Kits

A newly surfaced criminal AI service called MessiahGPT is being openly marketed on BreachForums as a purpose-built offensive model that writes ransomware, phishing kits, stealers, crypters, and rootkits on demand, according to findings published by the Trellix Advanced Research...

New GenieLocker Ransomware Attacks Windows, ESXi, and Linux Instances

GenieLocker, a newly identified ransomware linked to the financially motivated Toy Ghouls group, targets Windows, Linux, and VMware ESXi systems and has primarily attacked Russia's manufacturing sector since March 2026. The Toy Ghouls group, also known as Bearlyfy, Labubu, and...

New Spirals Ransomware Uses IIS Web Shell and PsExec to Encrypt IT Firm in Under 24 Hours

A previously unseen ransomware family dubbed "Spirals" struck an IT services company in South Asia in June 2026. Symantec's Threat Hunter Team reports that the attackers moved from the initial breach to full network encryption in under 24 hours....

Ransomware Attack on Coca-Cola-Owned Fairlife Halts Production Across the United States

Coca-Cola has reported a ransomware attack affecting its dairy subsidiary, Fairlife, resulting in a temporary shutdown of production operations across the United States. This incident was disclosed in a Form 8-K filing submitted to the U.S. Securities and Exchange Commission...

Ransomware Negotiator Sentenced for BlackCat Ransomware Operators to Attack Victims

A former Florida ransomware negotiator has been sentenced to 70 months in federal prison after conspiring with BlackCat/ALPHV ransomware operators and helping attack multiple U.S. victims. Angelo Martino, of Land O’Lakes, Florida, worked for a U.S.-based cyber incident response company....

The Gentlemen Ransomware With Custom EDR/AV Killers Scaling Faster to Attack Industries Worldwide

The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026. Emerging in mid-2025 from a payment dispute within the Qilin RaaS program, the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation that Microsoft...

Grafana GitHub Breach Linked to TanStack npm Supply Chain Ransomware

Grafana Labs has disclosed a targeted ransomware-linked breach of its GitHub environment, traced to a broader TanStack npm supply chain compromise associated with the “Mini Shai-Hulud” campaign. The incident, detected on May 11, 2026, involved unauthorized access to internal repositories...

Member of Prolific Russian Ransomware Group Sentenced to 102 Months in Prison

A Latvian national operating out of Moscow was sentenced to 102 months in federal prison for his central role in a sprawling Russian ransomware syndicate. Deniss Zolotarjovs, 35, served as a primary extortionist and negotiator for a highly organized cybercriminal...

Ransomware Gangs Expand Use of EDR Killers Beyond Vulnerable Drivers, ESET Warns

In recent years, Endpoint Detection and Response (EDR) killers have become a standard, highly effective weapon in modern ransomware intrusions. Before launching their file-encrypting malware, cybercriminals routinely deploy specialized tools to bypass security software. According to a comprehensive new...

Russian Initial Access Broker Sentenced to Prison for Enabling Ransomware Attacks on U.S. Firms

Aleksei Volkov, a 26-year-old Russian national, has been sentenced to 81 months in federal prison for operating as an Initial Access Broker (IAB). His illicit activities directly enabled major cybercrime syndicates, including the notorious Yanluowang ransomware group, to compromise numerous...

Latest News

Latest News