Visualização normal

Antes de ontemGBHackers on Security | #1 Globally Trusted Cyber Security News Platform

The Gentlemen Ransomware Hackers Use TukTuk C2 to Steal Credentials and Disable EDR Security

The Gentlemen ransomware operation has been linked to a previously undocumented, cross-platform command-and-control framework named TukTuk, alongside EDR-disabling tooling, DLL sideloading research, and datasets apparently stolen from technology and healthcare organizations. Analysis of a Finland-hosted server identified what researchers assess as the complete TukTuk development project, providing an unusually detailed view into the group’s post-compromise capabilities. […]

The post The Gentlemen Ransomware Hackers Use TukTuk C2 to Steal Credentials and Disable EDR Security appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

TITAN RaaS Uses AI for Data Classification, Regulatory Analysis and Automated Ransom Calculation

A newly emerged ransomware-as-a-service operation named TITAN is advertising an AI-driven extortion platform that it claims can autonomously classify stolen corporate data, identify regulatory risk. Founded on April 4, 2026, TITAN has been active since May and has listed 24 alleged victims across 10 countries. Italy accounts for 10 published victims, followed by Czechia with […]

The post TITAN RaaS Uses AI for Data Classification, Regulatory Analysis and Automated Ransom Calculation appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Ransomware Hacker Uses AI to Plan Attacks and Compromises More Than 20 Organizations

A Russian-speaking affiliate of the Aurora ransomware operation compromised more than 20 organizations across nine countries between April and July 2026, using the AI coding assistant Cursor to plan intrusion activity and Active Directory escalation. The exposed server offered an unusually complete view of a ransomware affiliate’s operational workflow. It contained victim-specific directories, shell history, […]

The post Ransomware Hacker Uses AI to Plan Attacks and Compromises More Than 20 Organizations appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Ransom Busters Ransomware Affiliate Targets Victims With Fake Data Recovery Extortion

A threat actor calling itself “Ransom Busters” is targeting ransomware victims with a deceptive recovery offer, claiming it can restore encrypted files and delete stolen data from ransomware infrastructure. GuidePoint Security’s Research and Intelligence Team (GRIT) assesses with moderate confidence that the purported recovery service is actually a ransomware affiliate attempting to divert extortion payments […]

The post Ransom Busters Ransomware Affiliate Targets Victims With Fake Data Recovery Extortion appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

MessiahGPT Unrestricted AI Model Lets Hackers Generate Ransomware and Phishing Kits

A newly surfaced criminal AI service named MessiahGPT is being marketed on BreachForums as an unrestricted offensive model capable of generating ransomware, phishing kits, stealers, crypters, rootkits, and social-engineering content on demand. The Trellix Advanced Research Center has reported that this service operates through the domain messiahgpt[.]de and promotes an associated Telegram community, marking a […]

The post MessiahGPT Unrestricted AI Model Lets Hackers Generate Ransomware and Phishing Kits appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Play Ransomware Masquerades as PsExec to Blend Into Legitimate Windows Administration

Play ransomware is using a familiar Windows-administration disguise to reduce suspicion during intrusions: a custom service binary named PSexesvc.exe. The group’s use of a custom service binary named PSexesvc.exe, mimicking Microsoft Sysinternals PsExec, illustrates how attackers can turn routine Windows administration into cover for lateral movement and payload execution. The binary has been observed alongside […]

The post Play Ransomware Masquerades as PsExec to Blend Into Legitimate Windows Administration appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Sophos Warns Unprotected Endpoints Let Interlock Credential Theft Go Undetected

Interlock ransomware incident that shows how unprotected endpoints can give attackers enough time to steal credentials, establish persistence, and reach a domain controller before defenders intervene. During a March 2026 response engagement, Sophos Emergency Incident Response investigators found the group abusing legitimate forensic utilities, including Volatility3 and WinPmem, to acquire memory and extract credential material […]

The post Sophos Warns Unprotected Endpoints Let Interlock Credential Theft Go Undetected appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Ransomware Hackers Are Hiding Malware Command Servers Inside Ethereum Smart Contracts

Ransomware operators are now abusing Ethereum smart contracts as stealthy command‑and‑control resolvers, with a Gentlemen ransomware affiliate using the EtherRAT backdoor to pull rotating C2 domains directly from the blockchain instead of hardcoding them in the malware. The toolkit shows a clear progression: scheduled tasks that bootstrap PowerShell, privileged account creation (“support2” with Supp0rt2@2026!). LSASS […]

The post Ransomware Hackers Are Hiding Malware Command Servers Inside Ethereum Smart Contracts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Ransomware Attack Abuses Legitimate Windows Tool to Evade Traditional Containment

Microsoft Defender’s new automatic device isolation capability has emerged as a decisive control against modern ransomware intrusions that abuse legitimate Windows binaries, as demonstrated in a recent incident at QNET where a multi-stage attack was stopped in just 128 seconds. The mshta.exe process reached out to attacker-controlled infrastructure, retrieved a remote second-stage payload, and began […]

The post Ransomware Attack Abuses Legitimate Windows Tool to Evade Traditional Containment appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Russian Access Broker Sells Network Access to Ransomware Gangs While Spying on Ukraine

An exposed server linked to a Russian‑speaking initial access broker (IAB) has revealed a sprawling operation that simultaneously fuels ransomware intrusions worldwide and supports Russian state-aligned intelligence collection against Ukrainian defense and aerospace targets. The artefacts show a mature, high‑volume access brokerage pipeline that industrialises exploitation of internet‑facing appliances, pivots to full Active Directory compromise, […]

The post Russian Access Broker Sells Network Access to Ransomware Gangs While Spying on Ukraine appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Ransomware Killers Overwrite Security Process Memory Without Terminating Applications

Ransomware operators are increasingly deploying “ransomware killers” that surgically overwrite the memory of security processes instead of simply terminating them, allowing encryption to proceed. At the same time, endpoint tools appear to run normally but are effectively blind. This evolution marks a shift from crude process-killing to stealthy, in‑memory tampering that targets EDR/AV telemetry, kernel […]

The post Ransomware Killers Overwrite Security Process Memory Without Terminating Applications appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New GenieLocker Ransomware Encrypts Windows, Linux and VMware ESXi Systems

GenieLocker is a custom ransomware family linked to the Toy Ghouls group (also known as Bearlyfy or Labubu). It can encrypt systems running Windows, Linux, and VMware ESXi, with a current focus on the manufacturing sector and related industries in Russia. This ransomware strain replaces the group’s earlier dependence on third-party lockers such as RedAlert, […]

The post New GenieLocker Ransomware Encrypts Windows, Linux and VMware ESXi Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy Chaos Ransomware

Hackers are abusing Microsoft Teams voice calls and fake IT helpdesk personas to gain remote access to corporate endpoints, drop a custom post‑exploitation toolchain, and, in multiple cases rapidly pivot to Chaos ransomware deployment across North American organizations. Nearly 95% of observed intrusions hit North American targets, with services, manufacturing, energy, construction and IP‑focused legal […]

The post Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy Chaos Ransomware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌
❌