Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews

Akira: The Retro-Themed Ransomware Operation Quietly Eating Mid-Market Enterprise

Jesse William McGrawApril 26, 20260

Akira launched in March 2023 with a 1980s green-screen aesthetic and rapidly became one of the most active ransomware operations in the world, riding waves of Cisco VPN exploitation and a steady stream of mid-market victims. Here is what makes it distinctive.

Black Basta: Conti’s Most Successful Successor and Its Healthcare Specialism

Jesse William McGrawApril 26, 20260

Black Basta walked out of the Conti collapse in 2022 and rapidly became one of the top RaaS programs in the world, with a particular taste for healthcare and critical infrastructure. Then internal chats leaked again — and the playbook started looking familiar.

Ryuk: The Big-Game Hunter That Made Ransomware a Boardroom Problem

Jesse William McGrawApril 26, 20260

Ryuk was the Russian-speaking operation that proved you could ransom a Fortune 500 company for tens of millions of dollars and get away with it. It is also the operation whose people went on to run Conti — and, by extension, half the modern ransomware ecosystem.

Cl0p: The Mass-Exploitation Specialists Behind Accellion, GoAnywhere, and MOVEit

Jesse William McGrawApril 26, 20260

Cl0p turned ransomware into a zero-day data-extortion business. Three sweeping campaigns against file-transfer software — Accellion, GoAnywhere, and MOVEit — produced thousands of victims and billions in damages, with little encryption and a lot of stolen data.

BlackCat / ALPHV: The Rust-Powered RaaS That Ended in an Exit Scam

Jesse William McGrawApril 26, 20260

BlackCat — also known as ALPHV — was the first major ransomware written in Rust, the operation that filed an SEC complaint against its own victim, and the brand that walked away with $22 million from Change Healthcare and stiffed its own affiliate. A short, eventful career.

REvil / Sodinokibi: The Big-Game Hunters Who Hit Kaseya, JBS, and Then Disappeared Twice

Jesse William McGrawApril 26, 20260

REvil — a.k.a. Sodinokibi — was the swaggering, big-game hunting RaaS responsible for some of the highest-profile attacks in ransomware history, including the Kaseya supply-chain incident. Then it vanished, briefly came back, and got cleaned up by the FSB.

Conti: Anatomy of a Ransomware Corporation — and How It Imploded

Jesse William McGrawApril 26, 20260

Conti was the most corporate ransomware operation of its era — payroll, HR, R&D, the works — until an internal leak in 2022 exposed the entire enterprise and its political alignment. Here is how it grew, how it operated, and how it collapsed into a network of successor brands.

LockBit: The Ransomware Brand That Redefined the Industry — and Got Taken Down

Jesse William McGrawApril 26, 20260

LockBit was the most prolific ransomware operation in history, running an industrialised RaaS program with the world’s fastest encryptor — until Operation Cronos shredded its infrastructure in early 2024.

Ransomware-as-a-Service (RaaS): How Cybercrime Got Its Franchise Model

Jesse William McGrawApril 26, 20260

Ransomware-as-a-Service turned ransomware from a craft into a franchise. Core developers write the malware, affiliates run the intrusions, and revenue is split. Here is how RaaS works, who plays which role, and why it has been so hard to disrupt.

The Different Types of Ransomware: From Crypto-Lockers to Triple Extortion

Jesse William McGrawApril 26, 20260

Not all ransomware is alike. Crypto-ransomware, lockers, scareware, leakware, doxware, wipers — each works differently and demands a different defensive response. A practical taxonomy.

Previous 1 … 18 19 20 21 Next
Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.