Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Ransomware

20 articles

Security Affairs Ransomware 1d ago

Why pure extortion is replacing traditional ransomware

Ransomware gangs are shifting from encryption to pure extortion, focusing on stolen data, reputational pressure, and stealthier attacks. Ransomware groups ar...

Security Affairs →

The Hacker News Ransomware 2d ago

First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups

Authorities in Europe and North America have announced the dismantling of a criminal virtual private network (VPN) service used by criminal actors to obscure...

T1041

The Hacker News →

CSO Online Ransomware 2d ago

Police take down VPN service (this time with a good reason)

European authorities have cracked down on a VPN that has been used for various criminal activities. The operation, led by investigators in France and the Net...

T1041

CSO Online →

SecurityWeek Ransomware 2d ago

‘First VPN’ Cybercrime Service Disrupted, Administrator Arrested

The FBI says First VPN has been used by dozens of ransomware groups for network reconnaissance and intrusions. The post ‘First VPN’ Cybercrime Service Disrup...

T1046 T1592

SecurityWeek →

GBHackers Ransomware 2d ago

Authorities Take Down “First VPN” Service Used in Ransomware Attacks

Authorities in Europe have dismantled a major criminal VPN service known as “First VPN,” which was widely used by ransomware operators and cybercriminal grou...

GBHackers →

Security Affairs Ransomware 3d ago

Global law enforcement operation takes First VPN offline

Police seized First VPN in a global crackdown, exposed its cybercrime users, and shut down infrastructure tied to ransomware and data theft. A major internat...

T1041 T1598

Security Affairs →

Infosecurity Magazine Ransomware 3d ago

Cybercriminal VPN Dismantled in Europol Crackdown

First VPN, a service used by ransomware actors and fraudsters, was dismantled by Europol

Infosecurity Magazine →

Help Net Security Ransomware 3d ago

Authorities dismantle First VPN, used by ransomware actors

First VPN, a virtual private network service marketed to cybercriminals, promising anonymity for its users, was taken offline on May 19 and 20 as part of Ope...

Help Net Security →

BleepingComputer Ransomware 3d ago

Police seize “First VPN” service used in ransomware, data theft attacks

A virtual private network service called 'First VPN,' used in ransomware and data theft attacks, has been taken offline in a joint international law enforcem...

T1041

BleepingComputer →

Rapid7 Blog Ransomware 3d ago

Q1 2026 Threat Landscape Report: Zero-clicks, geopolitical tensions, and some wins for law enforcement

The first quarter of 2026 reinforced that attackers are moving faster, operating with greater coordination, and exploiting weaknesses before most organizatio...

T1204 T1598

Rapid7 Blog →

HackRead Ransomware 3d ago

Europol Seizes First VPN Used by Ransomware Gangs, Arrests Administrator

Europol has seized First VPN, a service used by ransomware gangs, arrested its administrator and gained access to data linked to thousands of users.

HackRead →

GBHackers Ransomware 3d ago

WantToCry Ransomware Exploits SMB to Encrypt Remote Files

A new ransomware campaign named “WantToCry” that leverages exposed Server Message Block (SMB) services to gain access and encrypt victim data without deployi...

GBHackers →

The Record Ransomware 3d ago

Europe dismantles VPN service used by cybercriminals to hide ransomware attacks

The international operation targeted a service known as First VPN, which had been marketed for years on Russian-speaking cybercrime forums as a secure way fo...

The Record →

SC Media Ransomware 4d ago

WantToCry ransomware evades detection through SMB abuse, remote encryption

More than 1.5 million exposed SMB ports may be susceptible to brute force attacks.

T1110

SC Media →

BleepingComputer Ransomware SonicWall 4d ago

Hackers bypass SonicWall VPN MFA due to incomplete patching

Threat actors brute-forced VPN credentials and bypassed multi-factor authentication (MFA) on SonicWall Gen6 SSL-VPN appliances to deploy tools used in ransom...

BleepingComputer →

The Hacker News Ransomware Microsoft 4d ago

Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks

Microsoft on Tuesday said it disrupted a malware-signing-as-a-service (MSaaS) operation that weaponized the company's Artifact Signing system to deliver mali...

The Hacker News →

SC Media Ransomware 4d ago

Verizon DBIR 2026: Vulnerability exploits top initial access as patching coverage falls

The report also highlighted ransomware trends and the evolving role of AI in breaches.

SC Media →

GBHackers Ransomware Microsoft Intel 4d ago

Fox Tempest Linked to Malware-Signing Service Abusing Microsoft Artifact Signing

Fox Tempest, a financially motivated threat actor, has been linked to a large-scale malware-signing-as-a-service (MSaaS) operation that abused Microsoft’s Ar...

GBHackers →

CSO Online Ransomware Microsoft 4d ago

Microsoft disrupts malware code-signing service used by ransomware gangs

Microsoft has disrupted the infrastructure powering the largest malware code-signing service used to help ransomware groups and other cybercriminals make mal...

CSO Online →

BleepingComputer Ransomware Microsoft 5d ago

Cybercrime service disrupted for abusing Microsoft platform to sign malware

Microsoft says it has disrupted a malware-signing-as-a-service (MSaaS) operation that abused the company's Artifact Signing service to generate fraudulent co...

BleepingComputer →

1 2 3 ... 6 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA