Skip to content
feed: live
>_ 0dayNews
Vendor

Ransomware

Ransomware campaigns, extortion economics, and the tradecraft that drives them — from LOLBin-heavy intrusions to bespoke encryptors. Coverage of individual crews (Anubis, BlueHammer, Kairos, Lynx, Avalon/CrownX, JadePuffer, Inc/Lynx) sits alongside the class-level tactics that outlive any one brand.

Articles
~/articles/2026-07-10-vardanyan-ryuk-guilty-plea-portland-six-year-pipeline
A Ryuk operator pleads guilty, six years after wind-down
Analysis
ransomware

A Ryuk operator pleads guilty, six years after wind-down

Karen Vardanyan pleaded guilty in Portland to Ryuk-era conspiracy charges from 2019-2020. Sentencing is set for September. A note on how long the pipeline actually takes.

read →
~/articles/2026-07-10-digitalmint-martino-70-months-blackcat-insider-negotiation
Ex-DigitalMint negotiator gets 70 months for BlackCat scheme
Analysis
ransomware

Ex-DigitalMint negotiator gets 70 months for BlackCat scheme

Angelo Martino, ex-DigitalMint IR employee, sentenced to 70 months for feeding BlackCat victims' insurance limits and negotiation floors. An old failure mode.

read →
~/articles/2026-07-09-goddamn-ransomware-poisonx-driver-beast-rebrand
GodDamn ransomware: Beast rebrand, signed EDR-killer driver
ransomware

GodDamn ransomware: Beast rebrand, signed EDR-killer driver

Symantec attributes a new family, GodDamn, as a Beast rebrand shipping the PoisonX driver (g11.sys) — a Microsoft-signed kernel BYOVD used to neutralize endpoint defenses.

read →
~/articles/2026-07-08-mount-royal-university-cmd-organization-30-btc-breach
Mount Royal University confirms June breach, 30 BTC demand
ransomware

Mount Royal University confirms June breach, 30 BTC demand

Mount Royal University confirms a June 17 intrusion exfiltrated H drive data. A group calling itself CMD demands 30 BTC before the stated leak deadline.

read →
~/articles/2026-07-04-kairos-1m-extortion-payment-us-government-ransom-isac
Kairos Took $1M — and Never Encrypted a File
ransomware

Kairos Took $1M — and Never Encrypted a File

Ransom-ISAC's new case study confirms a ~$1M payment (9.44 BTC) to the Kairos crew on June 13, 2025. Krishnan's review found no encryption at any point — data-theft extortion only, tracked in ransomware feeds anyway.

read →
~/articles/2026-07-04-avalon-crownx-modular-malware-framework
Avalon Framework Bundles Theft, Wiper, CrownX
ransomware

Avalon Framework Bundles Theft, Wiper, CrownX

Blackpoint Cyber says the previously undocumented Avalon framework combines credential theft, EDR-aware defense evasion, shadow-copy destruction, and the CrownX ransomware payload in one multi-stage phishing chain.

read →
~/articles/2026-07-03-fortibleed-inc-lynx-ransomware-attribution
FortiBleed Tied to INC and Lynx Ransomware Crews
ransomware

FortiBleed Tied to INC and Lynx Ransomware Crews

The Hacker News reports an operator behind FortiBleed's credential-theft infrastructure was seen running ransomware negotiation panels for both INC and Lynx. Not a resale ring — a pipeline.

read →
~/articles/2026-07-03-sysdig-jadepuffer-ai-agent-langflow-ransomware
Sysdig: JADEPUFFER ran a full ransomware chain from one LLM
ransomware

Sysdig: JADEPUFFER ran a full ransomware chain from one LLM

Sysdig's Threat Research Team says JADEPUFFER is the first ransomware incident it has observed where an AI agent handled entry, credential theft, lateral movement, and destruction end-to-end. Initial access was a Langflow code-execution flaw.

read →
~/articles/2026-07-03-avalon-crownx-modular-malware-framework
Blackpoint: Avalon Bundles Theft, Wiper, CrownX
ransomware

Blackpoint: Avalon Bundles Theft, Wiper, CrownX

Blackpoint Cyber documents Avalon, a previously undocumented modular framework whose ransomware payload — CrownX — arrives at the end of a legal-lure phishing chain that stages through Proton Drive, ISO, LNK, and MSBuild.

read →
~/articles/2026-07-03-anubis-ransomware-citrix-bleed-2-cve-2025-5777
Anubis Ransomware Exploits Citrix Bleed 2
ransomware

Anubis Ransomware Exploits Citrix Bleed 2

The Hacker News reports Anubis-ransomware affiliates using Citrix Bleed 2 (CVE-2025-5777) to breach NetScaler-fronted environments, then pivoting with legit RMM, BYOVD, and stolen supply-chain credentials.

read →