Threat Actors

Cybersecurity
Alleged Dream Market Admin Speedstepper Arrested in Germany
US prosecutors charged Owe Martin Andresen as alleged Dream Market operator after German police arrested him for laundering over $2M in dark web proceeds.
Cybersecurity
Gentlemen Ransomware Group’s Internal Data Leaked Publicly
Internal data from the Gentlemen ransomware group — including bitcoin wallets and communications from 300+ victim operations — was posted publicly on MediaFire.
Cybersecurity
Sri Lanka Arrests 628 in Colombo Crypto Fraud Compound Bust
Sri Lankan police arrested 628 foreign nationals running crypto fraud and pig-butchering scam operations from luxury apartments in Colombo in a coordinated sweep.
Cybersecurity
Nitrogen Ransomware Hits Foxconn Wisconsin, Claims 8TB Theft
Nitrogen ransomware claimed responsibility for an attack on Foxconn's Mount Pleasant, Wisconsin campus, asserting 8TB of data stolen across more than 11 million files.
Cybersecurity
InterLock Claims Park Dental Research in 24-Hour Healthcare Blitz
InterLock ransomware posted four new victims in 24 hours on May 11, including Park Dental Research — a US healthcare target flagged in active FBI ...
Cybersecurity
ShinyHunters Sets HMH Extortion Deadline, Student Data at Risk
ShinyHunters posted Houghton Mifflin Harcourt with a May 12 pay-or-leak deadline, threatening to expose student and educator data from one of the largest US edtech ...
Cybersecurity
Operation HookedWing: 4-Year Campaign Compromises 500 Orgs
SOCRadar uncovered Operation HookedWing, a 4-year credential-harvesting campaign that compromised 2,000+ accounts across 500+ organizations in aviation, energy, government, and critical infrastructure using GitHub-hosted phishing ...
Application Security
Checkmarx Jenkins Plugin Backdoored in TeamPCP Supply Chain
TeamPCP backdoored the Checkmarx Jenkins AST scanner plugin in a third supply chain wave, following March Trivy and April KICS attacks. Version 2026.5.09 was compromised; ...
Cybersecurity
ShinyHunters Leaks 50GB After Vishing Breach at Cushman & Wakefield
Cushman & Wakefield confirmed a vishing-enabled breach after ShinyHunters and Qilin ransomware listed the firm separately. ShinyHunters published a 50GB Salesforce dataset after the May ...
Cybersecurity
TrickMo Android Banker Routes C2 Traffic Through TON Blockchain
ThreatFabric identified Trickmo.C, a TrickMo Android banking trojan routing C2 through TON blockchain with SSH tunneling, SOCKS5, and NFC capabilities targeting European banking users.