eCrime.ch: RT by @ecrime_ch: #ESETresearch has observed DeadLock ransomware expanding its use of Polygon blockchain smart contracts. Previously used only for chat proxy server address rotation, DeadLock has now added a new contract with the gang's DLS entries - a first of its kind we are aware of. 1/62026-06-16
ecrime_chransomwareUnknownT1566
eCrime.ch cybercrime intelligence covering financial fraud, phishing campaigns and criminal infrastructure.
Group-IB Threat Intelligence: SilabRAT places significant emphasis on #cryptocurrency theft. Beyond harvesting credentials and browser data, it can identify wallet-related artifacts and automatically attempt password recovery using credentials collected from infected systems. These additions reflect the growing focus on direct monetization within modern #malware ecosystems.2026-06-10
x-ctimalwareUnited States
Group-IB Threat Intelligence feed featuring APT research, ransomware analysis and cybercrime investigations.
Group-IB Threat Intelligence: One of SilabRAT's most notable capabilities is its use of Hidden Virtual Network Computing (HVNC). By interacting with services directly from the victim's device, attackers can perform account activity, access sensitive platforms, and conduct fraudulent operations while appearing as a legitimate user originating from the trusted device and IP address. #InfoSec2026-06-10
x-cticampaignUnknown
Group-IB Threat Intelligence feed featuring APT research, ransomware analysis and cybercrime investigations.
Group-IB Threat Intelligence: As browser security evolves, attackers are moving beyond traditional cookie theft. #SilabRAT advertises browser profile cloning, allowing operators to replicate a victim's browser environment, including extensions, storage, and fingerprinting artifacts. This enables access to authenticated sessions that may otherwise resist conventional session hijacking techniques. #CyberThreats #ThreatIntelligence2026-06-10
x-cticampaignUnknown
Group-IB Threat Intelligence feed featuring APT research, ransomware analysis and cybercrime investigations.
Group-IB Threat Intelligence: Validation of sample datasets from claims targeting Gulf banks showed that names and phone numbers were sourced from the 2021 Facebook leak while corresponding password hashes were taken from the October 2020 Eatigo breach, creating composite records that contain legitimate individual identifiers but do not represent actual customers of the targeted organizations.2026-05-20
x-ctibreachUnknown
Group-IB Threat Intelligence feed featuring APT research, ransomware analysis and cybercrime investigations.
Group-IB Threat Intelligence: These brokers, operating channels like #Aiqianjin and #YiqunData on Telegram, in addition to other individual brokers on dark web forums such as Exchange Market and Chang'An Sleepless Night, post between 500 to over 1,000 messages monthly across these platforms — a volume that would represent an unprecedented number of real breaches if true.2026-05-20
x-cticampaignUnited States
Group-IB Threat Intelligence feed featuring APT research, ransomware analysis and cybercrime investigations.
Park Dental Research2026-05-11
interlockransomwareUnited States
Park Dental Research, una empresa que proporciona tecnologías y materiales para laboratorios dentales y clínicas ortodóncicas, ha sido identificada como un objetivo de ciberataques. Según in...
Group-IB Threat Intelligence: Victimology analysis shows overlapping global targeting across both campaigns. Reward Points phishing primarily targets #financial services and telecom users across #APAC, while Failed Parcel Delivery campaigns focus on logistics entities across Europe, APAC, and the US. Despite sector-specific lures, the geographic distribution and brand impersonation patterns indicate coordinated deployment within the same smishing infrastructure. #ThreatIntel2026-04-29
x-ctiphishingUnited StatesT1566
Group-IB Threat Intelligence feed featuring APT research, ransomware analysis and cybercrime investigations.
Group-IB Threat Intelligence: Since January 2025, Group-IB has tracked over 2,500 #phishing domains tied to a single #PhaaS ecosystem known as the "Phoenix System" (不死鳥系統), which has targeted more than 70 organizations across financial services, telecom, and logistics.2026-04-29
x-ctiphishingUnited StatesT1566
Group-IB Threat Intelligence feed featuring APT research, ransomware analysis and cybercrime investigations.
Shock for Israeli Intelligence: Mossad Ex-Deputy Director Leak (handala-hack.to)2026-03-16
handalaransomwareIsraelT1566
Un incidente que ha sacudido a la inteligencia israelí reveló que el correo personal de Sima Shine, exjefe del Departamento de Irán en Mossad y actual líder de una de sus instituciones más s...
MarketGraphics Research Group2026-03-04
akiraransomwareUnited States
MarketGraphics Research Group es una empresa especializada en investigación y análisis de mercados, que ha sido alertada sobre un riesgo de ataque ransomware. Según los datos proporcionados,...