Related Threat Clusters
-
Microsoft Disrupts Fox Tempest Malware-Signing Service for Ransomware Gangs
On May 19, 2026, Microsoft disrupted Fox Tempest, a malware-signing-as-a-service (MSaaS) operation that provided over 1,000 fraudulent code-signing certificates to cybercriminals, enabling them to disguise malware as…
33 articles · Updated May 19, 2026 -
Gootloader Malware Resurfaces, Compromises Domain Controllers
Gootloader malware, known for delivering ransomware, has re-emerged after reduced activity, with Huntress reporting three infections since October 27, 2025. Two of these incidents resulted in hands-on-keyboard…
2 articles · Updated November 7, 2025 -
Gootloader Malware Resurfaces, Compromises Domain Controllers
Gootloader malware has re-emerged after a period of reduced activity, with Huntress reporting three infections since October 27, 2025. Two of these incidents resulted in hands-on-keyboard intrusions, leading to domain…
4 articles · Updated November 7, 2025 -
Rhysida Ransomware Gang Uses Fake Microsoft Teams Ads for Malware Distribution
The Rhysida ransomware group is exploiting fake advertisements for Microsoft Teams to distribute malware, specifically targeting users searching for the software. This campaign employs malvertising techniques,…
8 articles · Updated November 4, 2025 -
Rhysida Ransomware Gang Uses Fake Microsoft Teams Ads to Infect Users
The Rhysida ransomware gang is exploiting fake ads for Microsoft Teams to distribute malware. Users searching for Microsoft Teams may encounter these deceptive links, which lead to data exfiltration or encryption…
3 articles · Updated November 2, 2025
Recent Intelligence Reports
- Microsoft shuts down illegal code — Theregister · May 19, 2026
- Gootloader malware back for the attack, serves up ransomware — Theregister · November 7, 2025
- Ransomware gang runs ads for Microsoft Teams to pwn victims — Theregister · October 31, 2025