Ransomware

Cybersecurity
TheGentlemen and Genesis Ransomware Hit Two US Clinics
TheGentlemen ransomware claimed Michigan Surgical Center while Genesis targeted Family Medical Associates of Raleigh, exposing PHI to double-extortion pressure.
Cybersecurity
DragonForce and Nitrogen Ransomware Hit Three Continents
DragonForce claimed Lebanon IT firm SETS Solutions and Mexican manufacturer Copamex, while Nitrogen posted U.S. real estate developer Pyramid in parallel.
Cybersecurity
KillSec Ransomware Hits Indian Teaching Hospital and Mexican Insurer
KillSec ransomware posted an Indian teaching hospital and a Mexican insurance firm as victims, exposing patient data under India's DPDPA and Mexico's CNBV.
Cybersecurity
Nova Ransomware Apologizes for CIS Rule Violation, Bans Affiliate
Nova ransomware publicly apologized and banned an affiliate for attacking Eriell Group, an Uzbekistan oilfield firm, violating the CIS safe harbor rule.
Cybersecurity
Qilin Ransomware Claims Six Victims Across Five Countries in Two Days
Qilin ransomware posted six victims across five countries over two days, including Nova Medical Products and MEISA Sines at Portugal's Sines energy port.
Cybersecurity
APT73 Bashe Ransomware Claims Armenia’s Ministry of Internal Affairs
APT73 (Bashe), a LockBit-linked RaaS, posted Armenia's elections.mia.gov.am as a victim, threatening voter registration and electoral administration data.
Cybersecurity
Sophos: AI Ransomware Toolkit Uses Claude Opus 4.5 for EDR Evasion
Sophos discovered a criminal ransomware framework using Claude Opus 4.5 and multi-agent AI pipelines to build and test 80 evasion-optimized malware modules.
Cybersecurity
TheGentlemen Ransomware Lists US Water Utility Suburban Water
TheGentlemen ransomware posted Suburban Water, a US critical infrastructure water utility, among 14 victims across five sectors in a 46-minute window.
Cybersecurity
ShadowByt3$ Ransomware Hits Syngenta’s Cropwise Platform
ShadowByt3$ ransomware claims unauthorized access to Cropwise, Syngenta's precision agriculture platform, stealing GIS data, yield models, and API keys.
Cybersecurity
PureLogs Infostealer Uses MSBuild.exe for Fileless Deployment
FortiGuard Labs documents PureLogs infostealer delivered via fake purchase order emails, using MSBuild.exe process hollowing to execute entirely in memory.

Threat actors