How to pivot from a single ransomware forum handle to a corroborated actor profile using usernames, PGP keys, emails and crypto selectors. A 2026 OSINT walkthrough.
A practical 2026 walkthrough for following a ransom payment across the blockchain using open tools, wallet clustering and off-ramp attribution.
Interlock breaks the ransomware playbook, entering through compromised websites and fake CAPTCHAs. A joint CISA-FBI advisory mapped its TTPs. Here is the profile.
SafePay went from unknown to one of the busiest ransomware crews in under a year by ditching affiliates and hammering RDP and VPN gateways. Here is how it works.
INC Ransom has claimed 800-plus victims since 2023 using stolen credentials, edge-device flaws and double extortion. Here is how the RaaS operates in 2026.
wp2shell chains a REST batch-route bypass and a SQL injection into pre-auth RCE on WordPress core. WordPress shipped forced auto-updates in 7.0.2, 6.9.5 and 6.8.6.
Deadlock ransomware uses Polygon smart contracts for takedown-resistant command and control and a vulnerable driver to kill EDR. A profile of 2026’s most technically novel new group.
Clover Health disclosed in a July 17 SEC filing that three employee accounts were compromised via social engineering, risking protected health data.
Symantec detailed GodDamn ransomware using PoisonX, a kernel driver with a valid Microsoft signature, to terminate EDR before it encrypts.
DragonForce rebranded as a ransomware cartel offering white-label infrastructure, absorbed RansomHub affiliates, and hit UK retail. A profile of its model, decline, and tactics.