A hands-on 2026 guide to Maltego for OSINT: entities, transforms, machines and how to build a corroborated link chart from a single selector using the free Community Edition.
Jesse William McGraw
A hands-on 2026 guide to GraphSense, the open-source cryptoasset forensics platform: address clustering, TagPacks and how to trace ransom funds without a paid licence.
How to pivot from a single ransomware forum handle to a corroborated actor profile using usernames, PGP keys, emails and crypto selectors. A 2026 OSINT walkthrough.
A practical 2026 walkthrough for following a ransom payment across the blockchain using open tools, wallet clustering and off-ramp attribution.
Deadlock ransomware uses Polygon smart contracts for takedown-resistant command and control and a vulnerable driver to kill EDR. A profile of 2026’s most technically novel new group.
Symantec detailed GodDamn ransomware using PoisonX, a kernel driver with a valid Microsoft signature, to terminate EDR before it encrypts.
DragonForce rebranded as a ransomware cartel offering white-label infrastructure, absorbed RansomHub affiliates, and hit UK retail. A profile of its model, decline, and tactics.
World Leaks published 19,000 files (14.3GB) tied to India’s Kudankulam nuclear plant after Reliance Infrastructure refused to pay. The data leaked via a third-party server.
Akira has stayed a top-tier ransomware operation into 2026 by hammering SonicWall SSL-VPNs via CVE-2024-40766, deploying within an hour and using BYOVD to bypass EDR.
Microsoft’s July 2026 Patch Tuesday fixed a record 570 flaws and three zero-days, two already exploited in AD FS and SharePoint identity infrastructure.