Scworld Ransomware Operators Exploit ISPsystem VMs for Malicious Payloads
Article Content
Browse articles
Ransomware operators are leveraging virtual machines (VMs) provided by ISPsystem to host and distribute malicious payloads. Cybersecurity researchers at Sophos identified this tactic during their investigation of recent 'WantToCry' ransomware incidents, noting the use of Windows VMs with identical hostnames, indicative of default templates from ISPsystem's VMmanager.
Ask AI about this cluster
Answers cite the sources they use
Updated 193d ago How this analysis works
More articles in this cluster (2)
Following this threat?
Track BlackCat/ALPHV and Lummar in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
PAYLOAD Ransomware Exploits Active Directory for Disruption In April 2026, Kaspersky's Global Emergency Response Team responded to a ransomware incident at a manufacturing organization in the Middle East. Attackers gained domain-admin-equivalent control through a compromised account and created a malicious Group Policy Object (GPO) named PAYLOAD at the domain root. This GPO…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…