The Attack: Stealth Through Complexity Point Wild’s analysis of BotHelper RAT reveals a sophisticated multi-stage infection chain designed specifically to evade detection. A native x64 stager profiles the host, disables TLS certificate validation, downloads an encrypted payload from a remote URL, and decrypts it entirely in memory to avoid disk-based detection tools. Once decrypted, the […]
The Attack: Remote Access Disguised as Legitimate Software Attackers created fake desktop applications impersonating three major US payroll platforms that have never released desktop software. The lure pages, built with an AI app builder and hosted on Vercel behind bot-challenge screens, offered downloads that appeared to be official payroll management tools. The payload was a […]
The Problem: Healthcare Is the Most Targeted Sector A new analysis reveals that 77% of active ransomware groups are now targeting the healthcare sector. This isn’t random — it’s a calculated business decision by the scumbags running these operations. Healthcare organizations hold critical patient data, operate under extreme time pressure, and often run infrastructure that’s […]
The Attack: Backup Destruction Before Encryption The n0n ransomware gang introduced a particularly brutal tactic: systematically destroying all accessible backups — local shadow copies, network shares, cloud snapshots — before encrypting victim files. Their ransom notes explicitly claim this capability, and the threat is real. They use VSSAdmin commands to delete Windows shadow copies, unmount […]
The Gap Between Initial Access and Encryption Ransomware reports document initial access in detail. They document the encryptor in detail. The minute in between — where the endpoint agent quietly stops reporting — gets a single line in the timeline. That minute is where the intrusion is won. Modern ransomware operations follow a predictable sequence. […]
What Happened RIED is a ransomware variant from the Makop family discovered in September 2026. Like other Makop strains, it encrypts files on infected Windows systems, appends a distinctive extension (in this case, the victim’s unique ID, the attacker’s email address, and “.RIED”), and drops a ransom note demanding payment. On test systems, a file […]
1,067 Victims, One Common Vulnerability ThreatMon tracked 1,067 ransomware victims worldwide in August 2026. The report digs into 11 major incidents: a US federal law enforcement agency, a $10 billion wealth management firm, a Turkish hospital, a Japanese manufacturer, and a Brazilian government intranet among them. Nine different ransomware groups were involved — Qilin, Play, […]
Three Years Hidden, One File Operation Away From Prevention Lumen’s Black Lotus Labs disclosed BambooToken malware on September 18-19, 2026, revealing a campaign that had been running undetected since at least February 2023. The malware compromised roughly a dozen organizations across Asia and South America — hotels, biomedical firms, law firms, financial institutions, and a […]
August 2026 set a record: 997 ransomware attacks worldwide in a single month, the highest count ever tracked by Comparitech. Inside that spike, a new ransomware-as-a-service operation called Panzer went from nonexistent on August 4 to claiming 16 victims across 11 countries by early September. The group launched with a fully operational affiliate platform, cross-platform […]
GuidePoint Security recently documented a sophisticated malware campaign that uses smart contracts on the Polygon blockchain to maintain command-and-control infrastructure. The technique, called EtherHiding, stores the attacker’s current C2 server address inside a blockchain smart contract instead of hardcoding it into the malware. When defenders block one C2 domain, the attacker updates the smart contract […]