PROBABLYPWNED
Home/Ransomware News

Ransomware News

Track the latest ransomware attacks, malware campaigns, and threat actor activity. Analysis of ransomware gangs, decryption tools, and defense strategies.

249Malware Articles
Nx Console VS Code Extension Hijacked for 11 Minutes
Malware4 min read

Nx Console VS Code Extension Hijacked for 11 Minutes

Attackers published malicious Nx Console 18.95.0 to VS Code Marketplace, stealing developer credentials via triple-channel exfiltration and Sigstore-signed npm package poisoning.

James RiveraMay 19, 2026
DAEMON Tools Trojanized Since April—Backdoor Hit 100+ Countries
Malware4 min read

DAEMON Tools Trojanized Since April—Backdoor Hit 100+ Countries

Kaspersky uncovered a supply chain attack on DAEMON Tools official website. Trojanized installers deployed QUIC RAT backdoors to thousands of systems, with a dozen government and manufacturing targets receiving advanced payloads.

James RiveraMay 8, 2026
Needle Stealer Spreads via Fake TradingView AI Tool
Malware4 min read

Needle Stealer Spreads via Fake TradingView AI Tool

Malwarebytes uncovers campaign using fake TradingClaw website to distribute Needle Stealer malware. The infostealer hijacks browsers to harvest credentials, crypto wallets, and financial data from traders.

James RiveraApr 28, 2026
Mirai Variant Targets End-of-Life D-Link Routers
Malware4 min read

Mirai Variant Targets End-of-Life D-Link Routers

Akamai detects active exploitation of CVE-2025-29635 in discontinued D-Link DIR-823X routers. The tuxnokill variant spreads via command injection and launches DDoS attacks from compromised devices.

James RiveraApr 23, 2026
Kyber Ransomware Deploys Post-Quantum Crypto on Windows
Malware4 min read

Kyber Ransomware Deploys Post-Quantum Crypto on Windows

New Kyber ransomware operation uses NIST-standardized Kyber1024 encryption on Windows while targeting VMware ESXi with a separate variant. Rapid7 analysis reveals the ESXi version's claims are false.

James RiveraApr 23, 2026

Related Data Breaches

ShinyHunters Claims 275M Records in Instructure Canvas Breach
Data Breaches4 min read

ShinyHunters Claims 275M Records in Instructure Canvas Breach

Educational tech giant Instructure confirms data breach affecting Canvas LMS users. ShinyHunters claims 275 million student and teacher records stolen from 9,000 schools, with a May 6 leak deadline.

Sarah MitchellMay 4, 2026

Understanding the Ransomware Threat

Ransomware remains one of the most damaging cyber threats facing organizations today. Our coverage tracks active ransomware gangs, new malware variants, attack campaigns, and the evolving tactics used by threat actors.

We analyze ransomware-as-a-service (RaaS) operations, infostealer malware, banking trojans, and nation-state malware campaigns. Each article includes indicators of compromise (IOCs), MITRE ATT&CK mappings, and practical defense recommendations.

New to ransomware? Read our comprehensive guide: What is Ransomware? For broader malware education, see What is Malware?

Notable Ransomware Groups We Track

LockBitActive
ALPHV/BlackCatDisrupted
AkiraActive
PlayActive
Cl0pActive
Black BastaActive
RoyalRebranded
Scattered SpiderActive

All Hacking News

Browse all cybersecurity news including breaches, vulnerabilities, and threat intel.

What is Ransomware?

Complete guide to understanding ransomware attacks and how to prevent them.

Threat Intelligence

APT tracking, nation-state campaigns, and threat actor analysis.