Ransomware
Ransomware campaigns, extortion economics, and the tradecraft that drives them — from LOLBin-heavy intrusions to bespoke encryptors. Coverage of individual crews (Anubis, BlueHammer, Kairos, Lynx, Avalon/CrownX, JadePuffer, Inc/Lynx) sits alongside the class-level tactics that outlive any one brand.

Sysdig: JADEPUFFER now ships EncForge, targets model weights
Sysdig's Threat Research Team says the agentic operator it named JADEPUFFER has upgraded from generic database encryption to a custom Go ransomware, EncForge, that specifically targets AI model checkpoints, vector databases, and training data.

Abbott confirms Exact Sciences hit; LabCentral disputed
ShinyHunters used vishing to hit legacy Exact Sciences systems in Abbott's Cancer Diagnostics business; a separate LabCentral extortion claim by ShadowByt3$ is disputed.

Coca-Cola halts Fairlife US production after ransomware
Coca-Cola disclosed a Fairlife ransomware attack via SEC 8-K on July 16. US dairy production suspended, Canada unaffected. No group has claimed it.

Spirals ransomware: full network encrypted in under 24h
Symantec documents Spirals, a new ransomware family: IIS web-shell entry to a fully encrypted network in under 24 hours — one confirmed victim so far, an IT services firm in South Asia.

DOJ indicts Media Land trio: LockBit, BlackSuit, Play host
USAO-NDOH unsealed a Dec 2024 indictment against Volosovik ('Yalishanda'), Pankova, and Zatolokin — Media Land and ML.Cloud hosted LockBit, BlackSuit, Play. $62M losses, 21 states.

OFAC sanctions 1VPNS admin plus Belarusian cryptor seller
OFAC designated 1VPNS, its Ukrainian admin Rashevskyi, and Belarusian cryptor seller Silayev on July 14 — the follow-on to May's Operation Saffron seizure.

A Ryuk operator pleads guilty, six years after wind-down
Karen Vardanyan pleaded guilty in Portland to Ryuk-era conspiracy charges from 2019-2020. Sentencing is set for September. A note on how long the pipeline actually takes.

Ex-DigitalMint negotiator gets 70 months for BlackCat scheme
Angelo Martino, ex-DigitalMint IR employee, sentenced to 70 months for feeding BlackCat victims' insurance limits and negotiation floors. An old failure mode.

GodDamn ransomware: Beast rebrand, signed EDR-killer driver
Symantec attributes a new family, GodDamn, as a Beast rebrand shipping the PoisonX driver (g11.sys) — a Microsoft-signed kernel BYOVD used to neutralize endpoint defenses.

Mount Royal University confirms June breach, 30 BTC demand
Mount Royal University confirms a June 17 intrusion exfiltrated H drive data. A group calling itself CMD demands 30 BTC before the stated leak deadline.

Kairos Took $1M — and Never Encrypted a File
Ransom-ISAC's new case study confirms a ~$1M payment (9.44 BTC) to the Kairos crew on June 13, 2025. Krishnan's review found no encryption at any point — data-theft extortion only, tracked in ransomware feeds anyway.

Avalon Framework Bundles Theft, Wiper, CrownX
Blackpoint Cyber says the previously undocumented Avalon framework combines credential theft, EDR-aware defense evasion, shadow-copy destruction, and the CrownX ransomware payload in one multi-stage phishing chain.

FortiBleed Tied to INC and Lynx Ransomware Crews
The Hacker News reports an operator behind FortiBleed's credential-theft infrastructure was seen running ransomware negotiation panels for both INC and Lynx. Not a resale ring — a pipeline.

Sysdig: JADEPUFFER ran a full ransomware chain from one LLM
Sysdig's Threat Research Team says JADEPUFFER is the first ransomware incident it has observed where an AI agent handled entry, credential theft, lateral movement, and destruction end-to-end. Initial access was a Langflow code-execution flaw.

Blackpoint: Avalon Bundles Theft, Wiper, CrownX
Blackpoint Cyber documents Avalon, a previously undocumented modular framework whose ransomware payload — CrownX — arrives at the end of a legal-lure phishing chain that stages through Proton Drive, ISO, LNK, and MSBuild.

Anubis Ransomware Exploits Citrix Bleed 2
The Hacker News reports Anubis-ransomware affiliates using Citrix Bleed 2 (CVE-2025-5777) to breach NetScaler-fronted environments, then pivoting with legit RMM, BYOVD, and stolen supply-chain credentials.