Ido Cohen: Two ransomware groups are showing a sharp increase in activity during 2026. SafePay Q1 2026: 22 victims Q2 2026: 59 victims (+168%) RALord (Nova) Q1 2026: 14 victims Q2 2026: 60 victims (+329%) Both groups have significantly accelerated their operations in recent months, making them two of the fastest-growing ransomware threats to watch. Track ransomware trends and emerging threat groups with DarkFeed.2026-06-26
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Tracking the pulse of ransomware in 2026—these are the groups leading the global attack landscape right now: Qilin – 665 attacks The Gentleman – 453 attacks Akira – 290 attacks DragonForce – 245 attacks INC – 239 attacks Lockbit – 199 attacks Play – 154 attacks CLOP – 127 attacks NightSpire – 115 attacks CoinBase Cartel – 97 attacks Stay ahead of ransomware threats.2026-06-26
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
MalwareHunterTeam: List of names: "CamScanner 19-06-2026 16.49.accdr" "Adv Int Course (Rome).accdr" "Expression of Interest (EOI).accdr" "Security Orientation Course-41.accdr" "001210.accdr" "Proposal for Area Admin Meeting - SLNS Barana.accdr" "UN-System-wide-Strategy-on-SSC-2026-2029.accdr" 2026-06-26
malwrhunterteamcampaignUnknown
Malware samples, IOCs and indicators of compromise distributed by the MalwareHunterTeam research group.
MalwareHunterTeam: A possible interesting, low detected sample that was seen from Italy has @ET_Labs "ET MALWARE Win32/Darkme Trojan Checkin M1" traffic match to that IP address. In case correct, that IP can be related to Evilnum APT... As soon as @smica83 has time, the sample will be uploaded to Bazaar and then anyone can look. cc @marsomx_ @G609309532026-06-26
malwrhunterteammalwareItaly
Malware samples, IOCs and indicators of compromise distributed by the MalwareHunterTeam research group.
Ransomware News: Noticis kiberuzbrukums Latvijas Valsts mežiem; drošības apsvērumu dēļ slēgts LVM GEO, karšu sistēma un "Mednis" [papildināts]2026-06-25
anggipradanareportUnited Kingdom
Noticis kiberuzbrukums Latvijas Valsts mežiem; drošības apsvērumu dēļ slēgts LVM GEO, karšu sistēma un "Mednis" [papildināts] Noticia sobre ransomware publicada en . Extracto Sin e...
Clearview Eye Centre2026-06-25
interlockransomwareCanada
Un incidente de ciberseguridad ha afectado a Clearview Eye Centre, una clínica oftalmológica en Calgary, Alberta. Según informaciones recientes, el grupo malicioso "interlock" ha comprometid...