ransomNews's Avatar

ransomNews

@ransomnews.online

Decoding #ransomware groups since before Bitcoin existed. Deep threat intel for defenders who actually read the tech writeups. ๐Ÿ”— ransomNews.online ๐Ÿ’ผ linkedin.com/company/ransomnews

811
Followers
111
Following
1,337
Posts
19.02.2025
Joined
Posts Following

Latest posts by ransomNews @ransomnews.online

Post image

โš ๏ธ Fake CleanMyMac download spreads Shub stealer malware

A counterfeit CleanMyMac site distributes the #Shub Stealer, which harvests browser credentials, Telegram data, and cryptocurrency wallets from macOS systems before exfiltrating them to attacker-controlled servers.

#ransomNews #macOS

11.03.2026 08:37 ๐Ÿ‘ 5 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1

*all data arise checked, verified and validated by human beings, no Molts.

Weโ€™ve always been on the hard-work side of the page and automations are not a replacement. Paid platforms not able to localize a claim, and free platforms unable to catch the latest claims.

The rest is #fuffa.

10.03.2026 14:37 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
ransomNews โ€ข your go-to source for ransomware news, insights, and analysis, also home of RedACT monthly threat report ransomNews, your go-to source for ransomware news, insights, and analysis, also home of RedACT monthly threat report

This is verified data. Not estimates. Not noise.
And this is just the beginning, more features and insights are coming soon ๐Ÿ‘€

If you work in cybersecurity, risk management, or just want to understand the real threat landscape affecting businesses today, this is your bookmark.

#ransomNews

10.03.2026 14:37 ๐Ÿ‘ 3 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Post image

๐Ÿ‡ฎ๐Ÿ‡น Italy is not immune:
โ†’ February alone recorded 26 confirmed incidents
โ†’ Lombardia, Emilia-Romagna, Liguria leading the regional impact
โ†’ over 3.600 GB of data already exfiltrated and published in early 2026

10.03.2026 14:37 ๐Ÿ‘ 3 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Post image Post image

in the ransomware ecosystem:

๐ŸŒ Global snapshot (2026 so far*):
โ†’ 1.504 ransomware victims worldwide
โ†’ 62 active threat groups
โ†’ 26 countries impacted
โ†’ 13 new threat actors already emerged

10.03.2026 14:37 ๐Ÿ‘ 4 ๐Ÿ” 1 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
ransomNews โ€ข your go-to source for ransomware news, insights, and analysis, also home of RedACT monthly threat report ransomNews, your go-to source for ransomware news, insights, and analysis, also home of RedACT monthly threat report

๐Ÿšจ We just upgraded ransomNews - and the numbers speak for themselves!

Our website ransomnews.online got a serious update, and we're not just talking about a new coat of paint ๐Ÿ˜‰

We've introduced threat landscape statistics, both globally and for Italy, giving you a quick pulse on what's happening

10.03.2026 14:37 ๐Ÿ‘ 8 ๐Ÿ” 3 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 2
Post image

๐Ÿšจ nuova rivendicazione #ransomware Italia ๐Ÿšจ

๐Ÿดโ€โ˜ ๏ธ gruppo #DragonForce
๐Ÿงฌ Tazzetti SPA | Volpiano (TO)
๐ŸŽฏ settore: trattamento e smaltimento rifiuti
๐Ÿ”— tazzetti.com
๐Ÿ—“๏ธ 10 marzo 2026

๐Ÿ“„ sample: -
โ–ช๏ธ dati esfiltrati dichiarati: 14.94GB
โ–ช๏ธ dati esfiltrati pubblicati: -
โฒ๏ธ scadenza: 21 marzo 2026

#ransomNews

10.03.2026 14:04 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1
Post image

โš ๏ธ Fake Signal security alerts steal accounts via phishing pages

Attackers sent fake #Signal security alert messages linking to credential-harvesting pages designed to capture account details and enable session hijacking of victimsโ€™ messaging accounts.

#Phishing #CyberSecurity

10.03.2026 13:37 ๐Ÿ‘ 3 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

โš ๏ธ Hospital forced offline after medical records system collapse

The #cyberattack disabled the hospitalโ€™s electronic medical records, forcing staff to switch to paper workflows while emergency admissions were reduced and patients redirected to nearby facilities.

#ransomNews #HealthcareCyber

10.03.2026 12:37 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

โš ๏ธ Commercial iPhone hacking kit traces back to US vendor

Security researchers link the #iPhone exploitation toolkit #Reign to US firm #QuaDream infrastructure, showing it leveraged zero-click iMessage exploits and was marketed to governments for covert device surveillance operations.

#iOS #Spyware

10.03.2026 11:37 ๐Ÿ‘ 2 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

๐Ÿšจย Custom tool turns Salesforce scanning into data theft

Attackers modified the open-source #AuraInspector tool to mass-scan public #Salesforce Experience Cloud sites and extract data directly via the `/s/sfsites/aura` API when guest user permissions are overly permissive.

#ransomNews

10.03.2026 10:37 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

๐Ÿšจ nuova rivendicazione #ransomware Italia ๐Ÿšจ

๐Ÿดโ€โ˜ ๏ธ gruppo #LockBit5
๐Ÿงฌ Commerfrutta Di Stancari | Cerlongo (MN)
๐ŸŽฏ settore: ingrosso alimentare
๐Ÿ”— commerfrutta.com
๐Ÿ—“๏ธ 09 marzo 2026

๐Ÿ“„ sample: -
โ–ช๏ธ dati esfiltrati dichiarati: -
โ–ช๏ธ dati esfiltrati pubblicati: -
โฒ๏ธ scadenza: 25 marzo 2026

#ransomNews

10.03.2026 09:14 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1
Post image

๐Ÿšจ nuova rivendicazione #ransomware Italia ๐Ÿšจ

๐Ÿดโ€โ˜ ๏ธ gruppo #LockBit5
๐Ÿงฌ FAC SRL | Augusta (SR)
๐ŸŽฏ settore: noleggio attrezzature pesanti
๐Ÿ”— fac-srl.net
๐Ÿ—“๏ธ 09 marzo 2026

๐Ÿ“„ sample: -
โ–ช๏ธ dati esfiltrati dichiarati: -
โ–ช๏ธ dati esfiltrati pubblicati: -
โฒ๏ธ scadenza: 25 marzo 2026

#ransomNews #cybersecurity

10.03.2026 09:11 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1
Post image

๐Ÿšจ nuova rivendicazione #ransomware Italia ๐Ÿšจ

๐Ÿดโ€โ˜ ๏ธ gruppo #LockBit5
๐Ÿงฌ S.I.A. Societร  Italiana Alimenti SPA | Offida (AP)
๐ŸŽฏ settore: alimentare
๐Ÿ”— societaitalianaalimenti.it
๐Ÿ—“๏ธ 07 marzo 2026

๐Ÿ“„ sample: -
โ–ช๏ธ dati esfiltrati dichiarati: -
โ–ช๏ธ dati esfiltrati pubblicati: -
โฒ๏ธ scadenza: 21 marzo 2026

07.03.2026 15:03 ๐Ÿ‘ 3 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1
Preview
One click on this fake Google Meet update can give attackers control of your PC We found a fake Google Meet update that enrolls the victim's Windows PC in an attacker's device management system.

๐Ÿ”—ย read the full report on #Malwarebytes: www.malwarebytes.com/blog/threat-...

#ransomNews #Malware #Phishing

07.03.2026 13:37 ๐Ÿ‘ 3 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

โš ๏ธ Surveillance spyware hides inside fake meeting update

A fake #Google Meet update installs #Teramind surveillance software; the same MSI payload (SHA-256: 644ef9f..) is reused across campaigns and runs in hidden-agent mode with two auto-restarting services for persistent monitoring.

07.03.2026 13:37 ๐Ÿ‘ 4 ๐Ÿ” 1 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
White House Unveils President Trumpโ€™s Cyber Strategy for America The White House today released โ€œPresident Trumpโ€™s Cyber Strategy for America,โ€ outlining the Administrationโ€™s priorities for ensuring that America remains

๐Ÿ”—ย read the official statement: www.whitehouse.gov/articles/202...

#ransomNews #CyberStrategy #NationalSecurity

07.03.2026 12:37 ๐Ÿ‘ 3 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

๐Ÿ”Ž Five-page cyber strategy signals major policy shift

The new US cyber strategy is just 5 pages -far shorter than prior plans- and pivots toward offensive cyber operations, deregulation for industry, and AI-driven defense while leaving implementation details largely undefined.

07.03.2026 12:37 ๐Ÿ‘ 6 ๐Ÿ” 3 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
Partnering with Mozilla to improve Firefoxโ€™s security Anthropic is an AI safety and research company that's working to build reliable, interpretable, and steerable AI systems.

โš ๏ธ AI-generated bug reports flood Firefox maintainers

#Claude Opus 4.6 scanned 6k C++ files and sent 112 bug reports in two weeks. 22 confirmed vulnerabilities (14 high severity), nearly 20% of all Firefox high-severity bugs fixed in 2025.

#AIsecurity #Firefox #Vulnerabilities

07.03.2026 11:10 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

๐Ÿšจ nuova rivendicazione #ransomware Italia ๐Ÿšจ

๐Ÿดโ€โ˜ ๏ธ gruppo #LockBit5
๐Ÿงฌ Barbero Pietro SPA | Torino
๐ŸŽฏ settore: imballaggi e forniture per ufficio
๐Ÿ”— barberopietro.it
๐Ÿ—“๏ธ 05 marzo 2026

๐Ÿ“„ sample: -
โ–ช๏ธ dati esfiltrati dichiarati: -
โ–ช๏ธ dati esfiltrati pubblicati: -
โฒ๏ธ scadenza: 19 marzo 2026

#ransomNews

05.03.2026 15:54 ๐Ÿ‘ 4 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1
Post image

๐Ÿšจ nuova rivendicazione #ransomware Italia ๐Ÿšจ

๐Ÿดโ€โ˜ ๏ธ gruppo #Tengu
๐Ÿงฌ Eos Technology SRL | Roma
๐ŸŽฏ settore: riparazione computer e periferiche
๐Ÿ”— eostechnology.net
๐Ÿ—“๏ธ 04 marzo 2026

๐Ÿ“„ sample: sรฌ
โ–ช๏ธ dati esfiltrati dichiarati: 20.78GB
โ–ช๏ธ dati esfiltrati pubblicati: -
โฒ๏ธ scadenza: 11 marzo 2026

#ransomNews

04.03.2026 18:10 ๐Ÿ‘ 6 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1
Post image

๐Ÿšจ nuova rivendicazione #ransomware Italia ๐Ÿšจ

๐Ÿดโ€โ˜ ๏ธ gruppo #LockBit5
๐Ÿงฌ Paoli Dental Center | Mestre (VE)
๐ŸŽฏ settore: sanitario
๐Ÿ”— paolidental.org
๐Ÿ—“๏ธ 04 marzo 2026

๐Ÿ“„ sample: -
โ–ช๏ธ dati esfiltrati dichiarati: -
โ–ช๏ธ dati esfiltrati pubblicati: -
โฒ๏ธ scadenza: 19 marzo 2026

#ransomNews #cybersecurity

04.03.2026 18:09 ๐Ÿ‘ 5 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1
Post image

โš ๏ธ North Korean StegaBin campaign targets developers

Researchers uncovered a North Korean #StegaBin operation using steganographic malware hidden in images to target developers, blending social engineering and covert payload delivery to evade traditional detection.

#ransomNews #APT #Steganography

04.03.2026 09:37 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

๐Ÿšจ nuova rivendicazione #ransomware Italia ๐Ÿšจ

๐Ÿดโ€โ˜ ๏ธ gruppo #LockBit5
๐Ÿงฌ Formula50 | Anagni (FR)
๐ŸŽฏ settore: sviluppo IT
๐Ÿ”— formula50.it
๐Ÿ—“๏ธ 04 marzo 2026

๐Ÿ“„ sample: -
โ–ช๏ธ dati esfiltrati dichiarati: -
โ–ช๏ธ dati esfiltrati pubblicati: -
โฒ๏ธ scadenza: 18 marzo 2026

#ransomNews #cybersecurity #cyberthreats

04.03.2026 09:34 ๐Ÿ‘ 3 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1
Preview
Hacktivists claim to have hacked Homeland Security to release ICE contract data | TechCrunch A hacking group called Department of Peace said they hacked a specific office within Homeland Security to protest ICEโ€™s mass deportation campaign, and the companies aiding it.

๐Ÿ”Žย Hacktivists claim DHS breach exposing ICE contracts

Hacktivists allege they accessed US Homeland Security systems to leak sensitive ICE contract data, raising concerns over federal network security and the potential exposure of vendor and operational information.

#ransomNews #DataBreach

04.03.2026 08:37 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

However, some victim claims are unverified, indicating possible fabrications to inflate reputation.

#ransomNews #cybersecurity #newthreatactor

03.03.2026 18:01 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

The group's activity pattern suggests it is still establishing its operational tempo.
#Security teams should prioritize behavior-based detection and assume zero-trust principles, as traditional IOCs may be insufficient against an AI-augmented and state-aligned adversary.

03.03.2026 18:01 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

as this is an evolving pressure tactic

๐Ÿค“ Analyst take (confidence: low)
While AiLock's re-emergence and ties to sophisticated state actors are concerning, its public embrace of AI may be as much a marketing ploy as a technical reality.

03.03.2026 18:01 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

- enhance detection for AI-assisted behaviors, focusing on anomalous user interaction patterns and rapid, large-scale encryption
- track blockchain transactions involving Wasabi mixer and FixedFloat exchange, especially conversions to Monero
- scrutinize threats of regulatory reporting,

03.03.2026 18:01 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

โ€ข exfiltration (T1567): exfiltration over web service
โ€ข financial Motivation (T1657): the primary objective is financial gain through extortion, with potential secondary strategic disruption

๐Ÿ‘‰๐Ÿป What to watch next (#SOCPlaybook cues)
- monitor their DLS for re-emergence and new victim postings

03.03.2026 18:01 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0