RANSOMNEWS // 2026
Tracking the criminal infrastructure of the internet.
Ransomware operators, breach economics, threat-actor profiles, and the open-source investigation toolkit that makes it all visible. Updated daily.
Latest stories
- Codename Morgan: inside Morocco’s Pegasus machineForbidden Stories names Morocco as NSO’s client “Morgan”: a 2017 Rabat demo, an Emirati broker, roughly 12,000 targets, and Pegasus traces on seven French ministers’ phones.
- Inside Pegasus: NSO’s own files reveal the machineUnsealed NSO Group court files, analysed by Amnesty’s Security Lab and Forbidden Stories, expose how Pegasus really works: a vendor-run spyware service, not a weapon sold and forgotten.
- Maltego tutorial: OSINT link analysis in 2026A hands-on 2026 guide to Maltego for OSINT: entities, transforms, machines and how to build a corroborated link chart from a single selector using the free Community Edition.
- GraphSense tutorial: open-source crypto tracing in 2026A hands-on 2026 guide to GraphSense, the open-source cryptoasset forensics platform: address clustering, TagPacks and how to trace ransom funds without a paid licence.
// FOCUS
Ransomware
The defining cybercrime of the decade. How it works, who runs it, and where the money goes.
- Ransomware statistics 2026: confirmed attacks by monthConfirmed ransomware attack statistics, updated monthly: attacks per year, month, country, industry and group, from a human-verified dataset going back to 2018.
- ESXi ransomware in 2026: one host, the whole datacenterESXi ransomware encrypts every VM on a hypervisor at once. Here is why VMware ESXi became ransomware’s highest-value target in 2026, and how to defend it.
- MSPs: ransomware’s #1 target of 2026 [Field Report]Managed service providers entered 2026 as the single highest-leverage target class in the ransomware economy. Why the channel is now the front line, which TTPs operators are running against MSPs specifically, and what the better-run shops have already changed.
// PROFILES
Threat Groups
From LockBit and Conti to Akira and Cl0p, anatomies of the operations behind the headlines.
- Interlock: the drive-by ransomware crew CISA flaggedInterlock breaks the ransomware playbook, entering through compromised websites and fake CAPTCHAs. A joint CISA-FBI advisory mapped its TTPs. Here is the profile.
- SafePay: the centralised crew that skipped affiliatesSafePay went from unknown to one of the busiest ransomware crews in under a year by ditching affiliates and hammering RDP and VPN gateways. Here is how it works.
- INC Ransom: the RaaS that wins by mastering the basicsINC Ransom has claimed 800-plus victims since 2023 using stolen credentials, edge-device flaws and double extortion. Here is how the RaaS operates in 2026.
// DEFENCE
Security
EDR, Zero Trust, MFA, patching, IR, what actually works against modern threats.
- wp2shell: pre-auth RCE in WordPress core (CVE-2026-63030)wp2shell chains a REST batch-route bypass and a SQL injection into pre-auth RCE on WordPress core. WordPress shipped forced auto-updates in 7.0.2, 6.9.5 and 6.8.6.
- GodDamn ransomware blinds EDR with a Microsoft-signed driverSymantec detailed GodDamn ransomware using PoisonX, a kernel driver with a valid Microsoft signature, to terminate EDR before it encrypts.
- macOS.Gaslight: malware that prompt-injects your SOCSentinelLABS found macOS.Gaslight, a DPRK-linked Rust backdoor that embeds 38 fake system messages to make AI malware-triage agents abort. It is the first implant built to attack the analyst’s LLM, not the sandbox.
// SURVEILLANCE
Privacy
GDPR, data brokers, encryption, fingerprinting, VPNs, the surveillance economy and its limits.
- Codename Morgan: inside Morocco’s Pegasus machineForbidden Stories names Morocco as NSO’s client “Morgan”: a 2017 Rabat demo, an Emirati broker, roughly 12,000 targets, and Pegasus traces on seven French ministers’ phones.
- Inside Pegasus: NSO’s own files reveal the machineUnsealed NSO Group court files, analysed by Amnesty’s Security Lab and Forbidden Stories, expose how Pegasus really works: a vendor-run spyware service, not a weapon sold and forgotten.
- Stealer logs bypassing MFA in 2026 [Field Guide]Multi-factor authentication was supposed to end the credential-theft era. In 2026, it hasn’t — because adversaries skip the credential entirely and steal the session cookie that the authentication produced. Here’s how the attack works, why MFA doesn’t stop it, and the four controls that do.
// MACHINE LEARNING
AI
Prompt injection, deepfakes, model theft, the EU AI Act, security and policy at the frontier.
- Vibe coding is shipping vulnerabilities at scale in 2026AI-generated code is fast and insecure. Veracode found 45% of samples carry OWASP Top 10 flaws, roughly a fifth of AI-suggested packages are hallucinated, and vibe-coded apps are already leaking real data.
- Prompt injection left the lab in 2026. It is in the wild nowPrompt injection stopped being a lab demo in 2026. A one-click Claude Desktop flaw, AI browsers leaking credentials, and agents tricked into crypto payments show the attack is now operational, not theoretical.
- Shadow AI is the new stealer-log jackpot in 2026Shadow AI is now a top insider threat: 45% of staff use AI on corporate devices, most via personal accounts. When those sessions land in stealer logs, attackers inherit the AI and everything typed into it.
// INVESTIGATIONS
OSINT
Tools, methods, and case studies from the open-source investigation discipline.
- Maltego tutorial: OSINT link analysis in 2026A hands-on 2026 guide to Maltego for OSINT: entities, transforms, machines and how to build a corroborated link chart from a single selector using the free Community Edition.
- GraphSense tutorial: open-source crypto tracing in 2026A hands-on 2026 guide to GraphSense, the open-source cryptoasset forensics platform: address clustering, TagPacks and how to trace ransom funds without a paid licence.
- Pivoting on threat-actor handles: a 2026 OSINT methodHow to pivot from a single ransomware forum handle to a corroborated actor profile using usernames, PGP keys, emails and crypto selectors. A 2026 OSINT walkthrough.
// PRIMERS
Explainers
Long-form primers on the underlying concepts. Built to be referenced, not skimmed.
- What is intermittent encryption? A 2026 guideIntermittent encryption locks only parts of each file so ransomware runs faster and hides from detection. Here is how partial encryption works and how to catch it.
- What is RaaS? Ransomware-as-a-service, explainedRansomware-as-a-service splits ransomware into a rented product and an affiliate workforce. Here is how the RaaS model works and why it made attacks scale in 2026.
- What is BYOVD? Bring your own vulnerable driver, explainedBYOVD lets attackers load a legitimate but vulnerable signed driver to kill EDR from the kernel. Here is how it works and why ransomware crews rely on it in 2026.




















