Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews

REvil / Sodinokibi: The Big-Game Hunters Who Hit Kaseya, JBS, and Then Disappeared Twice

Jesse William McGrawApril 26, 20260

REvil — a.k.a. Sodinokibi — was the swaggering, big-game hunting RaaS responsible for some of the highest-profile attacks in ransomware history, including the Kaseya supply-chain incident. Then it vanished, briefly came back, and got cleaned up by the FSB.

Conti: Anatomy of a Ransomware Corporation — and How It Imploded

Jesse William McGrawApril 26, 20260

Conti was the most corporate ransomware operation of its era — payroll, HR, R&D, the works — until an internal leak in 2022 exposed the entire enterprise and its political alignment. Here is how it grew, how it operated, and how it collapsed into a network of successor brands.

LockBit: The Ransomware Brand That Redefined the Industry — and Got Taken Down

Jesse William McGrawApril 26, 20260

LockBit was the most prolific ransomware operation in history, running an industrialised RaaS program with the world’s fastest encryptor — until Operation Cronos shredded its infrastructure in early 2024.

Ransomware-as-a-Service (RaaS): How Cybercrime Got Its Franchise Model

Jesse William McGrawApril 26, 20260

Ransomware-as-a-Service turned ransomware from a craft into a franchise. Core developers write the malware, affiliates run the intrusions, and revenue is split. Here is how RaaS works, who plays which role, and why it has been so hard to disrupt.

The Different Types of Ransomware: From Crypto-Lockers to Triple Extortion

Jesse William McGrawApril 26, 20260

Not all ransomware is alike. Crypto-ransomware, lockers, scareware, leakware, doxware, wipers — each works differently and demands a different defensive response. A practical taxonomy.

How Ransomware Works: The Full Attack Lifecycle, Step by Step

Jesse William McGrawApril 26, 20260

Modern ransomware attacks are not single events; they are weeks-long intrusions that end in encryption. Here is the full lifecycle, from initial access to extortion, and what defenders can do at each stage.

A Brief History of Ransomware: From the AIDS Trojan to the RaaS Empires

Jesse William McGrawApril 26, 20260

Ransomware did not start with Bitcoin. It started in 1989, on floppy disks mailed to AIDS researchers, and spent thirty years evolving into the multibillion-dollar criminal industry we know today.

What Is Ransomware? A Plain-English Guide to the Defining Cybercrime of Our Era

Jesse William McGrawApril 26, 20260

Ransomware is malware that holds data, devices, or entire enterprises hostage until a payment is made. Here is what it is, why it works, and why it has become the single most disruptive category of cybercrime.

Previous 1 … 20 21 22

// The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

// Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

// Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,459 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.