Frequency
4
occurrences
First Seen
April 22, 2026
Last Seen
May 27, 2026
Related Threat Clusters
-
Payload Ransomware Targets Global Organizations with ChaCha20 Encryption
Payload ransomware, first identified in February 2026, has rapidly expanded its operations, targeting logistics, real estate, and manufacturing sectors worldwide. The malware employs ChaCha20 encryption and Curve25519…
2 articles · Updated May 26, 2026 -
Kyber Ransomware Targets Windows and VMware ESXi Systems
The Kyber ransomware group has launched a coordinated attack targeting both Windows file servers and VMware ESXi systems. In March 2026, cybersecurity firm Rapid7 analyzed two variants of the ransomware deployed in the…
3 articles · Updated April 22, 2026 -
Akira Ransomware Attack Exploits Disabled VPN Account
A recent Akira ransomware attack targeted a mid-sized organization by exploiting a disabled local SSL VPN account through brute-force methods. The attackers gained initial access, performed credential discovery, and…
2 articles · Updated May 29, 2026
Recent Intelligence Reports
- Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs, (Wed, May 27th) — Isc.Sans.Edu · May 27, 2026
- Payload Ransomware Uses ChaCha20 and Aggressive Anti-Forensics — Socprime · May 26, 2026
- Tr Kyber Ransomware Double Trouble Windows Esxi Attacks Explained — www.rapid7.com · April 25, 2026
- Kyber Ransomware Targets Windows and ESXi — Socprime · April 22, 2026
Related Entities
Brute Force
Credential Stuffing
Ransomware
Manufacturing
T1021.001 - Remote Desktop Protocol
T1033 - System Owner/User Discovery
T1047 - Windows Management Instrumentation
T1059.001 - PowerShell
T1059.003 - Windows Command Shell
T1070.001 - Clear Windows Event Logs
T1071 - Application Layer Protocol
T1078 - Valid Accounts