The recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were…
A ransomware operation linked to the FortiBleed campaign, with an operator using FortiBleed infrastructure to access negotiation panels and deploy ransomware.
A ransomware operation linked to the FortiBleed campaign, with an operator using FortiBleed infrastructure to access negotiation panels and deploy ransomware.
A large-scale credential-harvesting operation targeting FortiGate firewalls globally, stealing over 110 million credentials and linked to INC and Lynx ransomware operations.
A threat actor known for deploying Warlock ransomware by exploiting vulnerabilities in on-premises SharePoint servers since mid-2025. Uses tools like Velociraptor, Cloudflare…
UNC3944 is Mandiant's designation for the threat actor group known as Scattered Spider. The group has been involved in numerous high-profile extortion…
The Brazilian Tetrade is a group of banking trojans identified by Kaspersky, including Grandoreiro, Guildma, Melcoz, and Ousaban (Javali). They originated in…