Related Threat Clusters
-
Akira Ransomware Group Targets Critical Infrastructure, Extracts $42 Million
The Akira ransomware group has been identified as a significant threat to critical infrastructure, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the FBI warning of its active ransomware…
9 articles · Updated November 14, 2025 -
China-linked Bronze Butler Exploits Motex Lanscope Zero-Day Vulnerability
China-linked cyber-espionage group Bronze Butler, also known as Tick, exploited a zero-day vulnerability in Motex Lanscope Endpoint Manager, identified as CVE-2025-61932. This critical request origin verification flaw…
2 articles · Updated November 3, 2025 -
China-linked Hackers Exploit Lanscope Zero-Day to Deploy Gokcpdoor Malware
Cyber-espionage group Bronze Butler, also known as Tick, has exploited a zero-day vulnerability in Motex Lanscope Endpoint Manager, identified as CVE-2025-61932. This critical request origin verification flaw was used…
2 articles · Updated November 3, 2025 -
Makop Ransomware Enhancements Target Indian Organizations
The Makop ransomware, a variant of the Phobos family, has been updated to include GuLoader malware for enhanced payload delivery. Recent attacks have primarily targeted Indian businesses, utilizing Remote Desktop…
4 articles · Updated December 11, 2025 -
Shift in Ransomware Tactics Targeting Cloud Assets
Ransomware actors are increasingly focusing on cloud-based assets, particularly in AWS environments. This shift involves utilizing various tactics to compromise critical business data, moving away from traditional…
56 articles · Updated November 19, 2025 -
Kraken Ransomware Targets Multiple Systems with Advanced Encryption Techniques
The Kraken ransomware, which targets Windows and Linux/VMware ESXi systems, emerged in February 2025 as a continuation of the HelloKitty operation. It employs a double extortion technique, testing systems to optimize…
2 articles · Updated November 13, 2025 -
Kraken Ransomware Emerges from HelloKitty with Advanced Techniques
The Kraken ransomware, identified in February 2025, is a sophisticated Russian-speaking threat that evolved from the HelloKitty ransomware cartel. It employs double extortion tactics, targeting various sectors across…
4 articles · Updated November 17, 2025
Recent Intelligence Reports
- Updated Makop ransomware emerges — Scworld · December 11, 2025
- Kraken Uses Benchmarking to Enhance Ransomware Attacks — Infosecurity-Magazine · November 17, 2025
- Unleashing the Kraken ransomware group — Blog.Talosintelligence · November 13, 2025
- Akira Ransomware — Filestore.Fortinet · November 13, 2025
- Crowdstrike cybersecurity report highlights a spike in physical attacks on privileged users — Csoonline · November 5, 2025
- China-linked hackers exploited Lanscope flaw as a zero — Bleepingcomputer · November 1, 2025