DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic
Threat actors associated with the DragonForce ransomware group have been observed using a custom Go-based remote access trojan (RAT) called Backdoor.Turn to…
Threat actors associated with the DragonForce ransomware group have been observed using a custom Go-based remote access trojan (RAT) called Backdoor.Turn to…
Hackledorb is the threat actor behind DragonForce ransomware, known for pivoting to a highly organized cartel structure and deploying sophisticated backdoors like…
Medusa ransomware is a threat group that has previously used the custom malicious driver ABYSSWORKER in its attacks.
Lynx is a ransomware affiliate program that has been observed deploying DeadLock ransomware. This indicates a growing trend of affiliates using multiple…
INC Ransomware is a malware family associated with the INC affiliate program. It has been used in conjunction with DeadLock, suggesting a…
Veeam is a data management company that owns Coveware, which provides ransomware payment analysis and incident response services.
BlackCat, also known as ALPHV, is a ransomware-as-a-service group that emerged in 2021. It targeted numerous organizations globally, using sophisticated encryption and…
Akira ransomware continues to use defense evasion tactics, such as rebooting victim hosts into Safe Mode with Networking to disable security tools.…
INC Ransomware is another affiliate program that has been linked to the deployment of DeadLock ransomware. The collaboration between different ransomware groups…
CVE-2025-5777, known as Citrix Bleed 2, is being exploited by threat actors to deploy DragonForce ransomware. Attackers follow a consistent post-compromise pattern…