Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
    • Breach verification
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
    • Breach verification
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews

How to build a threat actor profile from public sources: MITRE ATT&CK + Mandiant + Malpedia tutorial

Jesse William McGrawMay 7, 20260

A practitioner’s tutorial for assembling a working threat-actor profile from public sources: MITRE ATT&CK for TTPs, Mandiant and CrowdStrike for attribution context, Malpedia for malware lineage, plus a clean note-taking template.

Tracking ransomware affiliates across rebrands with VirusTotal, MalwareBazaar, and YARA

Ransomnews Research TeamMay 7, 20260

A 2026 tutorial for tracking individual ransomware affiliates across operator rebrands using VirusTotal Intelligence, abuse.ch’s MalwareBazaar, and YARA rules. Code reuse, builder fingerprints, and TTP continuity reveal the same crews under new names.

How to check if you’re in a stealer log: tutorial with Hudson Rock, IntelX, and Have I Been Pwned

Jesse William McGrawMay 7, 20260

A practitioner’s tutorial for checking whether your email, your domain, or your employees show up in fresh infostealer logs, using Hudson Rock’s free tools, IntelX, Have I Been Pwned, and a couple of paid options worth the spend.

Defending against infostealers: tutorial with Defender for Endpoint, CrowdStrike, and browser hardening

Ransomnews Research TeamMay 7, 20260

A 2026 tutorial on building a layered defence against infostealers: endpoint EDR settings that catch stealer behaviour, browser hardening that protects cookie stores, and the user-side training that closes the actual gap.

Browser fingerprint markets: how stolen identities get sold in 2026

Ransomnews Research TeamMay 3, 20260

Stolen credentials are only half the package. The other half is the browser fingerprint that lets an attacker impersonate the victim’s session believably. A 2026 look at how fingerprint markets work.

Inside a ‘cloud of logs’ Telegram subscription tier

Jesse William McGrawMay 3, 20260

A practitioner’s look inside the “cloud of logs” subscription model: what attackers pay, what they get, and the operational mechanics that turn raw infostealer output into a productised threat.

How session-cookie theft replaced password theft in 2026

Jesse William McGrawMay 3, 20260

Stealing your password used to be the goal. In 2026 it’s the consolation prize: modern infostealers go for session cookies, which let attackers impersonate authenticated users without needing to defeat MFA. Here’s how the model works.

Lumma vs RedLine vs Vidar in 2026: market share by infections

Ransomnews Research TeamMay 3, 20260

A 2026 comparative profile of the three dominant infostealer families: capabilities, distribution channels, market share by observed infections, and where each is heading after the 2024 takedown actions.

The new mid-tier RaaS contenders: Qilin, Medusa, Embargo

Ransomnews Research TeamMay 3, 20260

Three mid-tier ransomware operators have built sustained victim claim counts in 2025-2026. Profiles of Qilin, Medusa, and Embargo: what’s distinctive about each, and what the rise of the mid-tier means for defenders.

Lapsus$ revival rumors in 2026: what we know and what we don’t

Ransomnews Research TeamMay 3, 20260

Persistent rumors point to a Lapsus$ revival operating under new branding in 2026. Sorting the credible signal from the Telegram noise, and what defenders should make of it.

Previous 1 … 11 12 13 14 15 … 24 Next

The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Free tool

How does your own site score?

Forty passive checks on TLS, security headers, email spoofing and privacy. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,715 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links; when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker
  • Site Check

Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.