Skip to main content

Threats Tagged 'encryption'

View all threats tagged with 'encryption'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: encryption

Threats Tagged 'encryption'

Click on any threat for detailed analysis and mitigation recommendations

The Gentlemen is a ransomware group active since July 2025, operating a Ransomware-as-a-Service model with dual-extortion tactics. They target Windows, Linux, and ESXi systems, focusing on extensive preparation before encrypting data. Their methods include privilege escalation using legitimate tools, persistence via registry and scheduled tasks, disabling security tools, deleting logs, and terminating backup services. They use strong encryption algorithms XChaCha20 and Curve25519. The group primarily targets medium-to-large organizations in the Asia-Pacific region, with a recent surge in activity. Victims face ransom demands with about 10-day deadlines and threats of data publication if unpaid.

Join the discussion

GenieLocker is a new ransomware family active since March 2026, targeting organizations in the Russian Federation, primarily in manufacturing. Attributed to the financially motivated Toy Ghouls group (also known as Bearlyfy, Labubu, and Laboo.boo), this custom-designed ransomware marks a shift from their previous reliance on third-party encryption tools like RedAlert, LockBit, and Babuk. GenieLocker exists in two variants: PE builds for Windows and ELF builds for Linux and ESXi. The Windows version features sophisticated capabilities including process termination, service shutdown, anti-debugging techniques, and advanced encryption using the libsodium library with XChaCha20-Poly1305 algorithm. Initial access typically occurs through compromised VPN credentials from trusted partners, followed by deployment of tools like Mimikatz, SoftPerfect Network Scanner, and SSH utilities for lateral movement before deploying ransomware using PsExec and PAExec.

Join the discussion

Kaspersky identified a new .NET Native AOT communication module for Project CAV3RN, a sophisticated cyberespionage framework targeting Israel. This module replaces the previous HTTP/WebSocket component by exchanging commands through Outlook calendar events accessed via Microsoft Graph API. Commands and results are stored in a fixed time window (2050-05-13 22:00-23:00 UTC) using specific subject patterns to identify heartbeats, commands, and outputs. The module implements RSA and AES-GCM encryption for secure communications. If Microsoft Graph authentication fails, it retrieves replacement configuration settings through DNS AAAA record responses from actor-controlled nameservers. The infrastructure analysis and behavioral patterns suggest low-confidence attribution to OilRig (APT34), based on the use of Microsoft-hosted services for command and control and compromised regional infrastructure.

Join the discussion

This analysis delves into the Beast ransomware, a Ransomware-as-a-Service (RaaS) that emerged in June 2024 as a successor to Monster ransomware. The investigation focuses on a Beast ransomware server detected in March 2026, revealing the operators' toolkit and attack methodology. The toolkit includes various tools for reconnaissance, network mapping, credential theft, persistence, lateral movement, exfiltration, and impact. Notable findings include the presence of both Windows and Linux versions of Beast ransomware, indicating targeting of workstations and Linux servers on VMware ESXi hypervisors. The report highlights the importance of proactive collection of internet telemetry in identifying ransomware operators' toolkits before they can be used against targets.

Join the discussion

LockBit 5.0, the latest version of the notorious ransomware, has been released with support for Windows, Linux, and ESXi systems. This update brings improved defense evasion, faster encryption, and enhanced modularity. The Windows variant employs extensive anti-analysis techniques, while Linux and ESXi versions remain unpacked. All variants share a common encryption scheme using XChaCha20 and Curve25519. LockBit 5.0 demonstrates a focus on enterprise and infrastructure targets, including explicit support for Proxmox virtualization. The group's data leak site reveals a primary focus on the U.S.business sector, with victims spanning various industries. LockBit's infrastructure has shown connections to SmokeLoader, suggesting possible cooperation or infrastructure reuse among malware operators.

Join the discussion

DragonForce, a ransomware group that emerged in late 2023, has become a significant cyber threat. They employ a dual-extortion strategy, encrypting and exfiltrating data, and have targeted various sectors, particularly manufacturing and construction. The group offers a flexible ransomware-as-a-service platform with advanced features, supporting multiple platforms and encryption modes. DragonForce has announced a shift to a cartel model, allowing affiliates to create their own brands. They've also introduced automated registration for new affiliates and a 'Company Data Audit' service to enhance extortion campaigns. The group has engaged in conflicts with rival ransomware operations and claims to have formed a coalition with other major groups. While their connection to DragonForce Malaysia remains unsubstantiated, technical analysis reveals similarities with other ransomware families and sophisticated attack techniques.

Join the discussion
0

LockBit, originating as ABCD ransomware in 2019, has evolved to version 5.0 in September 2025. After a period of inactivity, it resumed operations in December 2025 with a reduced affiliate sign-up fee. LockBit 5.0, nicknamed ChoungDong, consists of a Loader and Ransomware component. The Loader decrypts and executes the payload in memory, while the Ransomware uses ChaCha20 and Curve25519 for encryption. This update significantly enhances evasion techniques and attack efficiency, introducing features like Mutex, Execution Delay, and Wiper. The group's history includes affiliation with the Maze cartel, independent operations, and continuous upgrades. Mitigation strategies involve monitoring process behavior, applying security patches, and preparing for swift responses using provided IoCs and MITRE ATT&CK techniques.

Join the discussion

The VVS Discord Stealer is a Python-based malware designed to exfiltrate sensitive Discord user data including credentials and tokens. It uses Pyarmor with BCC mode and AES-128-CTR encryption to heavily obfuscate its code, evading detection by static and dynamic analysis tools. The malware decrypts encrypted Discord tokens, queries Discord APIs for user information, injects malicious JavaScript into the Discord client to intercept active sessions, and extracts data from multiple web browsers. It achieves persistence by configuring itself to run at system startup and deceives victims by displaying a fake error message. While no known exploits or CVEs are reported, its capabilities pose a medium severity threat. The stealer primarily targets Windows environments where Discord and browsers are installed and relies on user interaction, likely via social engineering. European organizations with significant Discord usage, especially in technology, gaming, media, and education sectors, face risks of credential theft, unauthorized access, data leakage, and operational disruption. Detection requires behavioral and heuristic analysis due to strong obfuscation techniques.

Join the discussion

RansomHouse, a ransomware-as-a-service operated by the Jolly Scorpius group, has upgraded its encryption capabilities with a new version of its Mario ransomware component. This upgrade introduces a sophisticated two-stage encryption process, enhanced memory management, and dynamic file processing, making the ransomware more efficient and harder to analyze. The attack chain involves MrAgent managing deployments and Mario performing file encryption, primarily targeting virtualized environments such as ESXi servers. Although no known exploits are currently in the wild, the improvements signal a trend toward more resilient ransomware variants. European organizations using virtualized infrastructure are at risk, especially those with ESXi deployments. The threat requires no known CVE but poses a medium severity risk due to its complexity and potential impact on availability and data confidentiality. Mitigation should focus on securing virtualization platforms, monitoring for indicators of compromise, and implementing robust backup and recovery strategies. Countries with high virtualization adoption and critical infrastructure reliance on virtual environments are most likely to be affected.

Join the discussion

'The Gentlemen' ransomware group, active since July 2025, operates a Ransomware-as-a-Service (RaaS) platform that employs advanced dual-extortion tactics by encrypting data and exfiltrating sensitive information to coerce ransom payments. Their ransomware targets Windows, Linux, and ESXi platforms, encrypting both local and network-shared drives using strong cryptographic algorithms XChaCha20 and Curve25519. Recent updates include automatic self-restart, run-on-boot persistence, configurable encryption speeds, and attack methods, enhancing their operational resilience and adaptability. The group has publicly disclosed 47 victims within two months, indicating rapid propagation and impact. The malware leverages multiple MITRE ATT&CK techniques such as persistence (T1547.001), data encryption (T1486), and network share discovery (T1135). No known exploits or CVEs are associated yet, but the threat is significant due to its multi-platform support and dual-extortion approach. European organizations with mixed OS environments and ESXi virtualization are at particular risk. Mitigation requires tailored detection of persistence mechanisms, network segmentation, and robust incident response plans. Countries with high adoption of VMware ESXi and diverse enterprise IT infrastructures, such as Germany, France, and the UK, are likely most affected.

Join the discussion

Showing 1 to 10 of 36 results

Filters:Tag: encryption
Page 1 of 4
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses