REvil is a ransomware_group tracked across 15 threat clusters and 29 intelligence report mentions on ThreatCluster. First observed October 23, 2025; most recent activity July 23, 2026.
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
On May 19-20, 2026, an international law enforcement operation, dubbed Operation Saffron, successfully dismantled First VPN, a virtual private network service heavily utilized by cybercriminals for ransomware, fraud,…
Adversaries are employing data destruction and disk wiping techniques to disrupt organizational operations. Techniques include overwriting files and disk data, with malware exhibiting worm-like propagation capabilities.…
Veeam has disclosed a critical vulnerability (CVE-2026-44963) affecting its Backup & Replication software, allowing authenticated domain users to execute remote code on domain-joined backup servers. This flaw impacts…
Qilin and Warlock ransomware variants have been identified exploiting vulnerable drivers to disable over 300 endpoint detection and response (EDR) tools. This exploitation allows the ransomware to evade detection and…
The article discusses the fifth volume of AttackIQ’s Ransom Tales series, which simulates the tactics of ransomware families REvil, DarkSide, and BlackMatter. These emulations are designed to help organizations validate…
Ransomware attacks are increasingly targeting mid-market firms, with two-thirds reporting breaches in the past year. The rise of Ransomware-as-a-Service (RaaS) has made these attacks more accessible to less…
German Federal Criminal Police (BKA) have identified Daniil Maksimovich Shchukin, 31, and Anatoly Sergeevitsch Kravchuk, 43, as the leaders of the notorious REvil and GandCrab ransomware gangs. Shchukin, known by the…
In 2024, ransomware attacks saw a decline, yet $734 million was paid in ransoms. The ongoing threat is being addressed through international cooperation and advancements in cybersecurity solutions. CTERA's Ransom…
The FBI has seized the RAMP cybercrime forum, a key platform for ransomware operations and other digital crimes. Both the forum's dark web and clearnet domains now display a seizure notice attributed to the FBI,…