Skip to content
feed: live
>_ 0dayNews
Vendor

Ransomware

Ransomware campaigns, extortion economics, and the tradecraft that drives them — from LOLBin-heavy intrusions to bespoke encryptors. Coverage of individual crews (Anubis, BlueHammer, Kairos, Lynx, Avalon/CrownX, JadePuffer, Inc/Lynx) sits alongside the class-level tactics that outlive any one brand.

Articles
~/articles/2026-07-20-jadepuffer-encforge-ai-asset-ransomware-model-weights-vector-dbs
Sysdig: JADEPUFFER now ships EncForge, targets model weights
● Breaking
ransomware

Sysdig: JADEPUFFER now ships EncForge, targets model weights

Sysdig's Threat Research Team says the agentic operator it named JADEPUFFER has upgraded from generic database encryption to a custom Go ransomware, EncForge, that specifically targets AI model checkpoints, vector databases, and training data.

read →
~/articles/2026-07-18-abbott-shinyhunters-vishing-exact-sciences-labcentral-disputed
Abbott confirms Exact Sciences hit; LabCentral disputed
ransomware

Abbott confirms Exact Sciences hit; LabCentral disputed

ShinyHunters used vishing to hit legacy Exact Sciences systems in Abbott's Cancer Diagnostics business; a separate LabCentral extortion claim by ShadowByt3$ is disputed.

read →
~/articles/2026-07-16-coca-cola-fairlife-ransomware-sec-8k-us-production-halt
Coca-Cola halts Fairlife US production after ransomware
ransomware

Coca-Cola halts Fairlife US production after ransomware

Coca-Cola disclosed a Fairlife ransomware attack via SEC 8-K on July 16. US dairy production suspended, Canada unaffected. No group has claimed it.

read →
~/articles/2026-07-16-symantec-spirals-ransomware-iis-webshell-24h-south-asia
Spirals ransomware: full network encrypted in under 24h
ransomware

Spirals ransomware: full network encrypted in under 24h

Symantec documents Spirals, a new ransomware family: IIS web-shell entry to a fully encrypted network in under 24 hours — one confirmed victim so far, an IT services firm in South Asia.

read →
~/articles/2026-07-15-doj-media-land-yalishanda-lockbit-blacksuit-play-bulletproof-hosting-indictment
DOJ indicts Media Land trio: LockBit, BlackSuit, Play host
ransomware

DOJ indicts Media Land trio: LockBit, BlackSuit, Play host

USAO-NDOH unsealed a Dec 2024 indictment against Volosovik ('Yalishanda'), Pankova, and Zatolokin — Media Land and ML.Cloud hosted LockBit, BlackSuit, Play. $62M losses, 21 states.

read →
~/articles/2026-07-14-ofac-1vpns-rashevskyi-silayev-sb0559-cryptor-designation
OFAC sanctions 1VPNS admin plus Belarusian cryptor seller
ransomware

OFAC sanctions 1VPNS admin plus Belarusian cryptor seller

OFAC designated 1VPNS, its Ukrainian admin Rashevskyi, and Belarusian cryptor seller Silayev on July 14 — the follow-on to May's Operation Saffron seizure.

read →
~/articles/2026-07-10-vardanyan-ryuk-guilty-plea-portland-six-year-pipeline
A Ryuk operator pleads guilty, six years after wind-down
Analysis
ransomware

A Ryuk operator pleads guilty, six years after wind-down

Karen Vardanyan pleaded guilty in Portland to Ryuk-era conspiracy charges from 2019-2020. Sentencing is set for September. A note on how long the pipeline actually takes.

read →
~/articles/2026-07-10-digitalmint-martino-70-months-blackcat-insider-negotiation
Ex-DigitalMint negotiator gets 70 months for BlackCat scheme
Analysis
ransomware

Ex-DigitalMint negotiator gets 70 months for BlackCat scheme

Angelo Martino, ex-DigitalMint IR employee, sentenced to 70 months for feeding BlackCat victims' insurance limits and negotiation floors. An old failure mode.

read →
~/articles/2026-07-09-goddamn-ransomware-poisonx-driver-beast-rebrand
GodDamn ransomware: Beast rebrand, signed EDR-killer driver
ransomware

GodDamn ransomware: Beast rebrand, signed EDR-killer driver

Symantec attributes a new family, GodDamn, as a Beast rebrand shipping the PoisonX driver (g11.sys) — a Microsoft-signed kernel BYOVD used to neutralize endpoint defenses.

read →
~/articles/2026-07-08-mount-royal-university-cmd-organization-30-btc-breach
Mount Royal University confirms June breach, 30 BTC demand
ransomware

Mount Royal University confirms June breach, 30 BTC demand

Mount Royal University confirms a June 17 intrusion exfiltrated H drive data. A group calling itself CMD demands 30 BTC before the stated leak deadline.

read →
~/articles/2026-07-04-kairos-1m-extortion-payment-us-government-ransom-isac
Kairos Took $1M — and Never Encrypted a File
ransomware

Kairos Took $1M — and Never Encrypted a File

Ransom-ISAC's new case study confirms a ~$1M payment (9.44 BTC) to the Kairos crew on June 13, 2025. Krishnan's review found no encryption at any point — data-theft extortion only, tracked in ransomware feeds anyway.

read →
~/articles/2026-07-04-avalon-crownx-modular-malware-framework
Avalon Framework Bundles Theft, Wiper, CrownX
ransomware

Avalon Framework Bundles Theft, Wiper, CrownX

Blackpoint Cyber says the previously undocumented Avalon framework combines credential theft, EDR-aware defense evasion, shadow-copy destruction, and the CrownX ransomware payload in one multi-stage phishing chain.

read →
~/articles/2026-07-03-fortibleed-inc-lynx-ransomware-attribution
FortiBleed Tied to INC and Lynx Ransomware Crews
ransomware

FortiBleed Tied to INC and Lynx Ransomware Crews

The Hacker News reports an operator behind FortiBleed's credential-theft infrastructure was seen running ransomware negotiation panels for both INC and Lynx. Not a resale ring — a pipeline.

read →
~/articles/2026-07-03-sysdig-jadepuffer-ai-agent-langflow-ransomware
Sysdig: JADEPUFFER ran a full ransomware chain from one LLM
ransomware

Sysdig: JADEPUFFER ran a full ransomware chain from one LLM

Sysdig's Threat Research Team says JADEPUFFER is the first ransomware incident it has observed where an AI agent handled entry, credential theft, lateral movement, and destruction end-to-end. Initial access was a Langflow code-execution flaw.

read →
~/articles/2026-07-03-avalon-crownx-modular-malware-framework
Blackpoint: Avalon Bundles Theft, Wiper, CrownX
ransomware

Blackpoint: Avalon Bundles Theft, Wiper, CrownX

Blackpoint Cyber documents Avalon, a previously undocumented modular framework whose ransomware payload — CrownX — arrives at the end of a legal-lure phishing chain that stages through Proton Drive, ISO, LNK, and MSBuild.

read →
~/articles/2026-07-03-anubis-ransomware-citrix-bleed-2-cve-2025-5777
Anubis Ransomware Exploits Citrix Bleed 2
ransomware

Anubis Ransomware Exploits Citrix Bleed 2

The Hacker News reports Anubis-ransomware affiliates using Citrix Bleed 2 (CVE-2025-5777) to breach NetScaler-fronted environments, then pivoting with legit RMM, BYOVD, and stolen supply-chain credentials.

read →