Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews

What is RaaS? Ransomware-as-a-service, explained

Ransomnews Research TeamJuly 20, 20260

Ransomware-as-a-service splits ransomware into a rented product and an affiliate workforce. Here is how the RaaS model works and why it made attacks scale in 2026.

What is BYOVD? Bring your own vulnerable driver, explained

Ransomnews Research TeamJuly 20, 20260

BYOVD lets attackers load a legitimate but vulnerable signed driver to kill EDR from the kernel. Here is how it works and why ransomware crews rely on it in 2026.

Pivoting on threat-actor handles: a 2026 OSINT method

Jesse William McGrawJuly 20, 20260

How to pivot from a single ransomware forum handle to a corroborated actor profile using usernames, PGP keys, emails and crypto selectors. A 2026 OSINT walkthrough.

Tracing ransom payments on-chain: a 2026 OSINT walkthrough

Jesse William McGrawJuly 20, 20260

A practical 2026 walkthrough for following a ransom payment across the blockchain using open tools, wallet clustering and off-ramp attribution.

Interlock: the drive-by ransomware crew CISA flagged

Martynas VareikisJuly 20, 20260

Interlock breaks the ransomware playbook, entering through compromised websites and fake CAPTCHAs. A joint CISA-FBI advisory mapped its TTPs. Here is the profile.

SafePay: the centralised crew that skipped affiliates

Martynas VareikisJuly 20, 20260

SafePay went from unknown to one of the busiest ransomware crews in under a year by ditching affiliates and hammering RDP and VPN gateways. Here is how it works.

INC Ransom: the RaaS that wins by mastering the basics

Martynas VareikisJuly 20, 20260

INC Ransom has claimed 800-plus victims since 2023 using stolen credentials, edge-device flaws and double extortion. Here is how the RaaS operates in 2026.

wp2shell: pre-auth RCE in WordPress core (CVE-2026-63030)

Ransomnews Research TeamJuly 18, 20260

wp2shell chains a REST batch-route bypass and a SQL injection into pre-auth RCE on WordPress core. WordPress shipped forced auto-updates in 7.0.2, 6.9.5 and 6.8.6.

Deadlock: ransomware that hides its C2 on the blockchain

Jesse William McGrawJuly 18, 20260

Deadlock ransomware uses Polygon smart contracts for takedown-resistant command and control and a vulnerable driver to kill EDR. A profile of 2026’s most technically novel new group.

Clover Health discloses social-engineering breach in 8-K

Ransomnews Research TeamJuly 18, 20260

Clover Health disclosed in a July 17 SEC filing that three employee accounts were compromised via social engineering, risking protected health data.

Previous 1 2 3 4 5 … 22 Next

// The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

// Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

// Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,459 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.