Interlock breaks the ransomware playbook, entering through compromised websites and fake CAPTCHAs. A joint CISA-FBI advisory mapped its TTPs. Here is the profile.
SafePay went from unknown to one of the busiest ransomware crews in under a year by ditching affiliates and hammering RDP and VPN gateways. Here is how it works.
INC Ransom has claimed 800-plus victims since 2023 using stolen credentials, edge-device flaws and double extortion. Here is how the RaaS operates in 2026.
wp2shell chains a REST batch-route bypass and a SQL injection into pre-auth RCE on WordPress core. WordPress shipped forced auto-updates in 7.0.2, 6.9.5 and 6.8.6.
Deadlock ransomware uses Polygon smart contracts for takedown-resistant command and control and a vulnerable driver to kill EDR. A profile of 2026’s most technically novel new group.
Clover Health disclosed in a July 17 SEC filing that three employee accounts were compromised via social engineering, risking protected health data.
Symantec detailed GodDamn ransomware using PoisonX, a kernel driver with a valid Microsoft signature, to terminate EDR before it encrypts.
DragonForce rebranded as a ransomware cartel offering white-label infrastructure, absorbed RansomHub affiliates, and hit UK retail. A profile of its model, decline, and tactics.
ShinyHunters listed Fluke (21M Salesforce records claimed) and Ingram Content on its leak site, extending a 2026 Salesforce extortion campaign now drawing class-action lawyers.
LockBit relaunched as version 5.0 in September 2025 and surged to 7% of June 2026 attacks. A profile of the disrupted brand’s resurgence, new encryptor, and affiliate model.