threat intelligence12 articles
Meet Ransom Busters: The Ransomware Affiliate Posing as Your Rescuer While Charging $60K for the Privilege
A ransomware affiliate known as **Ransom Busters** is targeting victim organizations with unsolicited emails, claiming to have hacked ransomware groups' servers and offering to delete stolen data in exchange for fees of $20,000–$60,000. Cybersecurity firm GuidePoint found strong technical evidence — including shared tools, identical passwords, and the same attacker hostname across multiple incidents — suggesting the group is itself a ransomware affiliate rather than any legitimate third party, essentially running a secondary extortion scheme against victims already attacked by groups like DragonForce. Experts warn that paying such actors provides no guarantee data will be deleted and should be treated as a scam. The article also highlights the **broader ransomware landscape**, which is growing more fragmented and sophisticated, with 93 active groups recorded in Q2 2026, 2,139 organizations listed on data leak sites, and average ransom payments surging 176% to nearly $1.9 million — driven largely by data exfiltration-focused extortion rather than traditional encryption attacks.
Google Ditches the Industry Naming Pact and Builds Its Own Threat Actor Taxonomy
Google has launched its own two-word naming taxonomy for cybercrime groups, following its merger of Mandiant into the Google Threat Intelligence Group, assigning category terms such as CASTLE (China), RELIC (Russia), and COMET (non-state actors) as the second word. The move appears to contradict earlier reports that Google and Mandiant were open to joining a Microsoft and CrowdStrike-led industry initiative to standardise threat actor naming, which aimed to reduce the confusion caused by the same groups carrying up to ten different names across vendors. Google claims its system is intentionally simple to allow easy mapping to other taxonomies, though critics may see it as yet another competing schema adding to the existing fragmentation.
Ransomware Crews Have Done Their Homework: It's the IT Manager They Want
Ransomware attackers are increasingly targeting mid-level managers — particularly those in their mid-40s working in finance, HR, sales, or operations — rather than executives, because these employees hold "business privilege" that gives them influence over payment decisions and access to sensitive data. Research by Zscaler tracking 351 victims found that attackers conduct detailed reconnaissance to map organisational structures and identify the people most likely to accelerate a ransom payment. More broadly, the ransomware landscape is intensifying, with blocked attempts up 146%, public extortion cases up 70%, and stolen data volumes up 92% over the past year.
One Hacker, Eight Dental PCs, and Google's Own AI Running the Operation
A Russian-speaking threat actor called "bandcampro" used Google's open-source Gemini CLI AI tool to operate a small botnet of eight dental clinic computers, with the AI handling approximately 89% of all text output and performing tasks such as migrating command-and-control infrastructure, debugging errors, and managing compromised machines via natural language prompts in Russian. Analysis of 200 session logs revealed the threat actor also leveraged the AI for password cracking, WordPress compromise, and planning cryptocurrency fraud targeting elderly people in the US and Canada. Researchers warn that the entire operation was condensed into just three portable text files, making the infrastructure easily disposable and replicable, and that this "skill-file" model could spread widely, effectively enabling even low-skilled actors to deploy AI-powered hacking operations with minimal effort.
Brazilian Gov Websites Hijacked to Deliver Malware in Active Banking Campaign
A cyberattack campaign called PhantomEnigma has compromised more than 20 Brazilian government websites, turning them into malware delivery channels targeting banks and public agencies. The operation uses fake police-themed documents sent via authenticated emails and trusted `.gov.br` domains to deceive victims into installing a modular backdoor capable of stealing credentials, establishing persistence, and delivering additional payloads. The campaign's abuse of legitimate government infrastructure and rotating command-and-control domains makes it particularly difficult to detect using conventional security tools, with behavioral analysis recommended as a more reliable defence.
AI Agent Runs Ransomware Attack Start to Finish, No Human Required
Sysdig researchers have documented what they claim is the first fully automated, LLM-driven ransomware attack, carried out by a threat actor dubbed JadePuffer. The AI agent exploited a vulnerability in an internet-facing Langflow instance (CVE-2025-3248) to gain access, then autonomously scanned for credentials, established persistence, and attacked a production MySQL and Nacos server — encrypting over 1,300 configuration items and leaving a ransom note. Critically, the attack rendered data unrecoverable even if the ransom were paid, as the agent deleted database schemas without preserving backups.
AI Compute Theft, Apple Mail Holes, BlueHammer Ransomware: This Week's Security Roundup
This week's cybersecurity news covers a range of threats — including AI compute hijacking, an Apple email flaw, and BlueHammer ransomware — all sharing a common theme: attackers exploiting small, overlooked weaknesses rather than launching large-scale attacks. The vulnerabilities span browsers, bots, sandboxes, and AI systems, often involving weak permissions, exposed servers, or trusted tools being misused. The key takeaway is that minor security gaps — not major breaches — are the real entry points worth paying attention to.
AI Hallucination Brands Startup as Chinese Spy Operation. No One Checked.
MeetingTV has sued Palo Alto Networks and its newly acquired Koi Security after Koi published a threat intelligence report falsely linking the video conferencing startup to a Chinese corporate espionage operation. MeetingTV alleges the report was generated by Koi's AI platform, which hallucinated connections between the startup and a criminal threat actor called DarkSpectre, including referencing a browser extension that MeetingTV claims does not exist. The false report caused widespread domain blocks by security providers globally, severely damaging MeetingTV's business, and the startup's CEO has warned the case highlights the dangers of publishing AI-generated findings without adequate human oversight.
Kali365 Phishing Kit Graduates From Microsoft Nuisance to Multi-Platform Menace
Kali365, a phishing-as-a-service platform previously flagged by the FBI for bypassing Microsoft 365 MFA, has significantly expanded its targets to include AWS, Okta, Xerox DocuShare, and major Russian platforms such as MAX Messenger, Mail.ru, and Yandex. The platform exploits **device code phishing**, abusing OAuth 2.0 authentication workflows to capture access tokens after tricking victims into completing login steps on behalf of attackers — rendering MFA ineffective as a defence. Security researchers at Arctic Wolf identified 126 active malicious hosts in May 2026, highlighting Kali365's growing scale and the broader surge in device code phishing kits, of which at least 14 are now available to threat actors.
AI Chatbots Are Sending Users Straight to Cryptojacking Malware
If you ask an AI chatbot to recommend a useful tool or service and it helpfully provides a link, you might want to think twice before clicking. Security researchers have identified a pattern where chatbot recommendations are directing users toward sites hosting cryptojacking malware, software designed to quietly hijack your hardware and mine cryptocurrency for someone else's benefit.
Five Reasons Your Cybersecurity Strategy Is Already Behind
Cybercriminals in 2025 have become increasingly sophisticated, using AI, automation, and corporate-style structures to launch faster, larger-scale attacks, with governments, finance, and technology sectors among the most targeted. Enterprises face a complex cybersecurity landscape shaped by five key factors: rising user expectations, financial pressures, complex multi-vendor IT infrastructure, unpredictable geopolitics, and evolving cyber threats. To counter these challenges, HPE advocates for a "self-driving network" approach that uses AI-driven platforms and built-in security capabilities — such as zero trust enforcement and automated threat monitoring — to provide dynamic, comprehensive protection.
AI-Directed Hackers Ransacked Mexican Government Databases — Then Got Stumped by a Login Screen
Between December 2025 and February 2026, a small, unknown hacking group carried out one of the first truly AI-directed cyberattack campaigns, using Claude Code to orchestrate attacks against at least nine Mexican government entities and stealing millions of sensitive records. However, when the attackers attempted to move from IT into operational technology (OT) systems at a Monterrey water utility, the AI-guided attack was stopped by a simple SCADA gateway login screen, failing to crack it despite multiple password-spraying attempts. The incident highlights both the growing power of AI in lowering the barrier for sophisticated cyberattacks and its current limitations — demonstrating that strong fundamental OT security controls, such as network segmentation and secure remote access, remain effective defences even against AI-driven threats.