Visualização normal

Antes de ontemFirewall Daily – The Cyber Express
  • ✇Firewall Daily – The Cyber Express
  • Gunra Ransomware Builds a New Attack Network Through RaaS Samiksha Jain
    Gunra ransomware has expanded its operations through a structured ransomware-as-a-service (RaaS) affiliate program, prompting the FBI, CISA and other agencies to issue a joint advisory warning organizations about the threat. The Gunra ransomware variant uses a double-extortion model, encrypting victim data while threatening to publish stolen information on a dedicated leak site if ransom demands are not met. The FBI first observed Gunra in April 2025 as a double-extortion ransomware variant d
     

Gunra Ransomware Builds a New Attack Network Through RaaS

11 de Agosto de 2026, 08:01

Gunra ransomware

Gunra ransomware has expanded its operations through a structured ransomware-as-a-service (RaaS) affiliate program, prompting the FBI, CISA and other agencies to issue a joint advisory warning organizations about the threat. The Gunra ransomware variant uses a double-extortion model, encrypting victim data while threatening to publish stolen information on a dedicated leak site if ransom demands are not met. The FBI first observed Gunra in April 2025 as a double-extortion ransomware variant derived from leaked Conti ransomware source code.

Gunra Ransomware Shifts to Affiliate Model

By early 2026, the group had expanded through a formal ransomware-as-a-service affiliate program advertised on dark web forums. The program provides affiliates with a management panel, configurable ransomware builder, cross-platform locker payloads and affiliate documentation. The FBI also observed Gunra operating under new branding aliases, including Golden Community, while recruiting penetration testers and ethical hackers as initial access brokers. Gunra initially focused on Windows environments before introducing a Linux variant and moving toward broader cross-platform targeting. Victims observed on the group’s dedicated leak site include organizations across the Americas, Europe, the Middle East, Africa and the Asia-Pacific. Targeted sectors include healthcare and public health, financial services and insurance, critical manufacturing, transportation, government services, utilities, academia, media and communications, retail, and professional and nonprofit services. Gunra ransomware

VPN Vulnerabilities Used for Initial Access

According to the advisory, Gunra actors primarily gained initial access by exploiting known vulnerabilities in internet-facing devices, including firewall and VPN gateways. The FBI observed exploitation of CVE-2024-55591 and CVE-2025-24472, authentication bypass vulnerabilities affecting specific FortiOS and FortiProxy versions. The Republic of Korea’s National Police Agency also observed Gunra actors exploiting credential exposure and SSH access control weaknesses in internet-facing VPN gateways to obtain unauthorized remote access. After gaining access, attackers used tools including Impacket utilities to move laterally through victim networks using SMB. In one case, actors compromised an SSL-VPN appliance using default credentials where account lockout controls were absent. They later used stolen session information to access internal virtual desktop infrastructure and move through systems including Active Directory servers and IT personnel workstations.

Data Theft Precedes Encryption

The double-extortion ransomware operation involves stealing sensitive information before encrypting systems. The FBI observed Gunra actors collecting business-critical documents, databases, personally identifiable information, and internal email communications. In at least one case, the actors used a malicious executable called main.exe to exfiltrate data from Microsoft OneDrive and SharePoint. Compressed archives containing sensitive information were also transferred to the Mega file-sharing service, with the volume of exfiltrated data reaching tens of terabytes. For encryption, Gunra uses ChaCha20 and RSA-4096 algorithms and has been observed using the .ENCRT extension for encrypted files. A documented sample from July 2025 used the .CRYPT extension. The ransomware also uses Windows Management Instrumentation to delete volume shadow copies before encryption, while one victim had backup and archived data deleted from both primary and disaster recovery infrastructure.

Agencies Urge Patching and Network Segmentation

The authoring agencies recommend that organizations prioritize patching known exploited vulnerabilities in internet-facing systems, including VPN gateways and RDP-exposed infrastructure. They also advise implementing and testing offline, immutable backups stored in physically separate and segmented locations. Network segmentation is another key recommendation, intended to restrict lateral movement and limit the spread of ransomware between systems. The agencies also recommend reviewing domain controllers, servers, workstations and Active Directory environments for unrecognized accounts, auditing administrative privileges, requiring MFA where possible and testing security controls against the Gunra techniques mapped to the MITRE ATT&CK framework. The joint advisory was published August 10, 2026, as part of the ongoing #StopRansomware initiative.
  • ✇Firewall Daily – The Cyber Express
  • Ransomware Kingpin Gets 16 Years for Global Cyberattacks Samiksha Jain
    A Ransom Cartel ransomware leader has been sentenced to 16 years in prison after being convicted of conspiracy to commit offenses against the United States, conspiracy to commit wire fraud, and aggravated identity theft, according to the U.S. Department of Justice. Maksim Silnikau, a 40-year-old Belarusian national, was identified in court documents as the creator and administrator of the Ransom Cartel ransomware strain, which was developed in 2021. Silnikau had been active on Russian-speakin
     

Ransomware Kingpin Gets 16 Years for Global Cyberattacks

10 de Agosto de 2026, 04:54

Ransom Cartel ransomware

A Ransom Cartel ransomware leader has been sentenced to 16 years in prison after being convicted of conspiracy to commit offenses against the United States, conspiracy to commit wire fraud, and aggravated identity theft, according to the U.S. Department of Justice. Maksim Silnikau, a 40-year-old Belarusian national, was identified in court documents as the creator and administrator of the Ransom Cartel ransomware strain, which was developed in 2021. Silnikau had been active on Russian-speaking cybercrime forums since at least 2005 and was also a member of the cybercrime website Direct Connection between 2011 and 2016.

Ransom Cartel Ransomware Operation

Beginning in May 2021, Silnikau developed the ransomware scheme and recruited participants through cybercrime forums. He distributed information and tools to participants, including stolen credentials linked to compromised computers and tools designed to encrypt or lock those systems. Silnikau also maintained a hidden website used by himself and his co-conspirators to monitor and control ransomware operations. According to the court documents, the website provided a platform for the group to communicate with one another, interact with victims, send and negotiate ransom demands, and manage the distribution of funds among the conspirators. The operation targeted companies between 2021 and 2023. During that period, Ransom Cartel ransomware conspirators carried out attacks against at least 18 companies around the world, including organizations based in California, New York, Nebraska, and other countries outside the United States.

Ransomware Attacks Targeted Companies Worldwide

The ransomware attacks involved data theft and monetary demands. The attackers sought payment in exchange for providing keys to unlock stolen data or for promises not to publish the information taken from victims. The operation’s growth was disrupted following Silnikau’s arrest in July 2023. He was later extradited from Poland to face prosecution in the Eastern District of Virginia and the District of New Jersey. The sentencing announcement was made by Theophani K. Stamos, First Assistant U.S. Attorney for the Eastern District of Virginia; Acting Special Agent in Charge Andrew Forrest of the U.S. Secret Service Criminal Investigative Division; Chris Ormerod, Special Agent in Charge of the FBI Kansas City Field Office; and Craig L. Tremaroli, Special Agent in Charge of the FBI Albany Field Office.

Maksim Silnikau Sentenced to 16 Years

The Justice Department’s Office of International Affairs provided substantial assistance with Silnikau’s extradition and the collection of evidence. The U.S. Attorney’s Office for the District of New Jersey and the Computer Crime and Intellectual Property section also assisted with the case. Assistant U.S. Attorney Jonathan S. Keim and former Assistant U.S. Attorney Zoe Bedell prosecuted the case. The 16 years in prison sentence follows the disruption of an international ransomware operation that targeted at least 18 companies during its active period. Silnikau’s role, according to court documents, extended across the development and administration of the ransomware strain, recruitment of participants, provision of attack tools, victim communications, and management of funds generated through the operation.
  • ✇Firewall Daily – The Cyber Express
  • How the World’s Most Active Ransomware Operation Expanded in H1 2026 Ashish Khaitan
    The first half of 2026 reinforced a familiar reality in ransomware: a small number of highly capable operators continue to drive a disproportionate share of global attacks. Among them, Qilin ransomware emerged as the most active threat group tracked by Cyble Research and Intelligence Labs (CRIL), demonstrating the scale and reach of today’s ransomware-as-a-service (RaaS) ecosystem. CRIL observed Qilin targeting organizations across multiple regions and industries, with activity spanning North
     

How the World’s Most Active Ransomware Operation Expanded in H1 2026

Qilin ransomware

The first half of 2026 reinforced a familiar reality in ransomware: a small number of highly capable operators continue to drive a disproportionate share of global attacks. Among them, Qilin ransomware emerged as the most active threat group tracked by Cyble Research and Intelligence Labs (CRIL), demonstrating the scale and reach of today’s ransomware-as-a-service (RaaS) ecosystem. CRIL observed Qilin targeting organizations across multiple regions and industries, with activity spanning North America, Europe, Asia-Pacific, South America, and other global markets. Its widespread campaigns highlight how modern ransomware groups leverage affiliate networks, purchased access, and proven extortion techniques to maintain sustained operational momentum.

Download the Cyble H1 2026 Cyber Threat Landscape Report for the full analysis.

Breaking Down the Qilin Ransomware Operation 

Qilin’s activity was particularly significant in North America, where the group accounted for 370 ransomware attacks during H1 2026. This represented nearly one-fifth of all ransomware incidents recorded in the region. Qilin ransomware The group also maintained a strong presence in Europe and the UK, claiming 158 attacks, while Asia-Pacific recorded 64 incidents linked to Qilin. In South America, the group was responsible for 40 attacks, further demonstrating its ability to operate across diverse geographic environments. Rather than concentrating on a single market, Qilin followed a broad targeting strategy designed to maximize opportunities across industries. 

Targeting Sectors Where Downtime Hurts Most 

Qilin’s victim profile reflected a common ransomware strategy: focusing on organizations where operational disruption creates immediate pressure.  Manufacturing organizations remain especially attractive because ransomware incidents can interrupt production lines and affect supply chains. Healthcare organizations face additional pressure due to the critical nature. Construction, Healthcare, and Professional Services were among the sectors most frequently targeted. These industries often depend on continuous availability, hold sensitive information, and face significant financial or regulatory consequences when systems are disrupted.  Manufacturing organizations remain especially attractive because ransomware incidents can interrupt production lines and affect supply chains. Healthcare organizations face additional pressure due to the critical nature of their services and the sensitivity of patient information.  Professional Services firms, including legal and consulting organizations, also represent valuable targets because they manage confidential client data that can increase the impact of double-extortion campaigns. 

The RaaS Model Behind Qilin’s Growth 

Qilin’s success reflects the maturity of the ransomware-as-a-service model. Instead of relying on a single internal team to handle every stage of an attack, RaaS groups operate through specialized ecosystems that include affiliates, initial access brokers, and other underground service providers.  This structure allows ransomware brands to expand quickly, launch simultaneous campaigns, and maintain activity even as individual operators face disruption. The continued success of groups like Qilin shows why ransomware remains difficult to contain. Law enforcement actions and infrastructure takedowns can affect individual operations, but decentralized affiliate models allow new campaigns to continue.

Defending Against the Qilin Threat 

The group’s activity reinforces several priorities for organizations: reducing exposed attack surfaces, strengthening identity controls, monitoring suspicious access activity, and preparing for data theft alongside encryption.  Since ransomware operators increasingly rely on stolen credentials and compromised infrastructure, security programs must focus on preventing initial access as much as responding to active attacks. 

To explore Qilin’s attack patterns, global ransomware trends, targeted industries, and the broader threat landscape observed in H1 2026, download the complete Cyble H1 2026 Cyber Threat Landscape Report

The Cyber Express Weekly Roundup: Ransomware Surge, Data Breaches, and Rising Digital Threats

The Cyber Express weekly roundup July 2026

This week’s cybersecurity landscape highlights the continued expansion of cyber risks across governments, businesses, and consumers. From ransomware campaigns targeting organizations worldwide to credential-based attacks, data breaches, online fraud, and digital piracy crackdowns, recent incidents show how threat actors are exploiting both technical vulnerabilities and human behavior.  The latest developments underline the need for stronger security practices, including improved identity protection, faster incident response, and greater awareness of evolving cyber threats. Organizations are increasingly dealing with attacks that go beyond data theft, affecting operations, customer trust, and critical services. 

The Cyber Express Weekly Roundup 

U.S. Accounts for Nearly Half of Global Ransomware Attacks in H1 2026 

The United States experienced 1,721 ransomware attacks during the first half of 2026, representing nearly 45% of all incidents tracked globally, according to research from Cyble Research and Intelligence Labs (CRIL). The report identified ransomware groups Qilin and Akira as among the most active threat actors during the period. Read more... 

Dubai Police Warns Against Online Visa Fraud Schemes 

Dubai Police has issued a warning about fraudulent online advertisements offering work, residency, and visit visas in exchange for payment. Scammers have reportedly used social media platforms and messaging applications to impersonate government entities or unauthorized service providers to trick victims. Read more... 

Craneware Data Breach Exposes Employee and Customer Information 

Healthcare technology company Craneware confirmed that unauthorized individuals accessed part of its data environment, resulting in the exposure of employee information as well as some customer and partner records. The company stated that the incident has been contained and has not disrupted business operations or customer services. Read more...  

U.S. Targets Illegal FIFA World Cup Streaming Networks 

The U.S. Department of Justice seized more than 1,000 domains allegedly involved in illegally streaming FIFA World Cup 2026 matches. The action was carried out under Operation Offsides, an initiative focused on combating online piracy and protecting intellectual property rights. Read more... 

Chick-fil-A Customer Accounts Targeted in Credential Attack 

Chick-fil-A confirmed that certain customer accounts were accessed during an automated credential-stuffing attack between June 17 and June 19, 2026. The attackers used account credentials obtained from an external source to gain unauthorized access. The company said affected information may have included customer names, email addresses, membership details, and limited payment-related data. Read more... 

South Korea Diplomatic System Breach Lasted Nearly 10 Months 

South Korea’s Ministry of Foreign Affairs revealed that attackers maintained access to the National Diplomatic Academy’s online education system for almost 10 months. The breach, which began in April 2025, exposed information linked to thousands of current and former ministry employees. Compromised data included user IDs, names, email addresses, and encrypted passwords. Read more... 

Weekly Cybersecurity Takeaway 

The week’s incidents demonstrate how cyber threats continue to evolve across multiple areas, from ransomware and account compromise to online scams and government-related breaches. Attackers are increasingly targeting weaknesses in identity management, user behavior, and digital infrastructure.  Organizations and individuals must focus on proactive security measures, including stronger authentication controls, regular monitoring, timely updates, and greater awareness of social engineering tactics. As cyber threats become more widespread and interconnected, improving resilience remains essential for protecting data, services, and public trust. 
  • ✇Firewall Daily – The Cyber Express
  • Three Russians Indicted in $62M Cybercrime Scheme Targeting U.S. Infrastructure Samiksha Jain
    Three Russian nationals have been charged in a sweeping Russian cybercrime indictment tied to an alleged bulletproof hosting operation that U.S. authorities say enabled ransomware, malware, phishing, and other cybercriminal activities, resulting in more than $62 million in losses to victims across the United States and several other countries. The U.S. Attorney's Office for the Northern District of Ohio announced the unsealing of the indictment following a seven-year investigation. Alongside th
     

Three Russians Indicted in $62M Cybercrime Scheme Targeting U.S. Infrastructure

Three Russian cybercrime indictment

Three Russian nationals have been charged in a sweeping Russian cybercrime indictment tied to an alleged bulletproof hosting operation that U.S. authorities say enabled ransomware, malware, phishing, and other cybercriminal activities, resulting in more than $62 million in losses to victims across the United States and several other countries.

The U.S. Attorney's Office for the Northern District of Ohio announced the unsealing of the indictment following a seven-year investigation. Alongside the criminal charges, the U.S. Department of State is offering a reward of up to $10 million for information on foreign government-linked associates connected to the operation.

Three Russian Nationals and Two Companies Indicted

A federal grand jury returned the indictment in December 2024 against:

  • Alexander Alexandrovich Volosovik, 43, of St. Petersburg, Russia
  • Kirill Andreevich Zatolokin, 34, of St. Petersburg, Russia
  • Yulia Vladimirovna Pankova, 29, of St. Petersburg, Russia
  • Media Land LLC
  • ML.Cloud LLC

The defendants face charges including conspiracy to commit computer fraud, wire fraud, money laundering, and aiding cybercriminal activities.

Russian cybercrime indictment

Assistant Attorney General A. Tysen Duva said the defendants allegedly operated criminal infrastructure from overseas that supported attacks against U.S. critical institutions and placed the public at risk.

Bulletproof Hosting Allegedly Enabled Cybercrime Operations

According to court documents, Media Land, owned by Volosovik, and ML.Cloud, owned by Pankova, provided internet infrastructure and server hosting services designed to help cybercriminals evade law enforcement.

Authorities allege the companies operated from St. Petersburg while maintaining infrastructure in multiple countries, including China, Finland, the Netherlands, and the United States.

The businesses allegedly offered bulletproof hosting services that enabled criminal clients to deploy malware and ransomware, extort victims for money and cryptocurrency, register fraudulent domains, operate criminal marketplaces, and launch phishing and brute-force attacks.

Investigators said the companies also provided technical support to cybercriminal customers, allowing malicious campaigns to continue while avoiding detection.

Victims Spanned Critical Sectors Across 21 States

Officials said the operation targeted dozens of organizations across 21 U.S. states as well as multiple countries.

Victims included:

  • Banks
  • Schools
  • Government entities
  • Hospitals
  • Media companies

Communities affected in Ohio included Akron, Brookfield, Canton, Cleveland, Elyria, Medina, Findlay, Solon, and Valley View.

Russian cybercrime indictment

Additional affected states included California, Florida, Georgia, Illinois, Louisiana, Maryland, Massachusetts, Michigan, Minnesota, New Hampshire, New York, North Carolina, Pennsylvania, Tennessee, Texas, Utah, Virginia, Washington, Wisconsin, and Delaware.

International victims were identified in Australia, Canada, the European Union, the United Arab Emirates, and the United Kingdom.

FBI Cyber Division Assistant Director Brett Leatherman said Media Land enabled malicious activity that caused tens of millions of dollars in losses while impacting victims across multiple countries.

Russian Cybercrime Indictment Prompts $10 Million Reward Offer

The U.S. Department of State's Rewards for Justice program announced a reward of up to $10 million for actionable information regarding foreign government-linked associates of the indicted individuals, their malicious cyber activities, or foreign government-linked use of Media Land or ML.Cloud.

The program also noted that relocation assistance may be available for qualifying information.

International Sanctions Expand Pressure

The indictment follows coordinated international action against the alleged operators. In November 2025, the U.S. Department of the Treasury's Office of Foreign Assets Control, together with authorities from the United Kingdom and Australia, sanctioned Media Land for facilitating global ransomware operations, distributed denial-of-service attacks, and other malicious cyber activities.

The sanctions also targeted Volosovik, Zatolokin, and Pankova individually, along with Media Land subsidiaries Media Land Technology (MLT), Data Center Kirishi (DC Kirishi), and sister company ML Cloud.

On July 13, the European Union also announced sanctions against the companies and key individuals as part of broader efforts to disrupt cybercrime infrastructure.

International Agencies Back the Investigation

The investigation was led by the FBI Cleveland Division with support from the Cybersecurity and Infrastructure Security Agency (CISA) and the Office of Foreign Assets Control.

Authorities also received assistance from the National Police of the Netherlands, the Public Prosecutor's Office of the Netherlands, the United Kingdom's National Crime Agency, the United Kingdom Foreign Commonwealth and Development Office, the Australian Department of Foreign Affairs and Trade, and the Australian Federal Police.

Officials from CISA and partner agencies said disrupting bulletproof hosting providers remains essential because these services form a critical part of the cybercriminal ecosystem by enabling ransomware, phishing, malware, and other malicious operations while helping threat actors remain anonymous.

  • ✇Firewall Daily – The Cyber Express
  • Vishing Call Becomes Key Lead in Massive Odido Cyberattack Samiksha Jain
    The investigation into the Odido cyberattack has uncovered possible involvement of Dutch nationals, according to Dutch police, as authorities continue to investigate the ShinyHunters ransomware-linked attack that exposed the personal data of approximately 6.39 million customers. Law enforcement has urged the public to come forward with information as investigators work to identify those responsible for one of the country's largest telecom data breaches. The cyberattack took place on February 5
     

Vishing Call Becomes Key Lead in Massive Odido Cyberattack

Odido cyberattack

The investigation into the Odido cyberattack has uncovered possible involvement of Dutch nationals, according to Dutch police, as authorities continue to investigate the ShinyHunters ransomware-linked attack that exposed the personal data of approximately 6.39 million customers. Law enforcement has urged the public to come forward with information as investigators work to identify those responsible for one of the country's largest telecom data breaches.

The cyberattack took place on February 5 and 6 after attackers allegedly used voice phishing (vishing) to deceive Odido's customer service team.

According to the company, the attackers posed as members of its internal IT staff, gaining unauthorized access before exfiltrating customer data. Odido said its teams detected the unauthorized access immediately on both occasions and revoked the attackers' access, but the incident still resulted in a large-scale data breach.

Odido Cyberattack Investigation Finds Possible Dutch Link

Under the direction of the National Public Prosecution Service, the High Tech Crime Team (THTC) of the National Investigation and Intervention Unit launched an extensive investigation into the breach.

Authorities said investigators have found strong indications that Dutch criminals may have been involved. One key lead centers on a phone call made shortly before the breach in which a Dutch-speaking man allegedly impersonated an Odido IT employee while speaking with customer service representatives. Police are continuing efforts to identify the caller and have indicated that his voice could be made public if necessary.

Investigators believe people within cybercrime circles may have information about those responsible and are encouraging anyone with relevant details to contact law enforcement.

ShinyHunters Named as Threat Actor

Odido attributed the attack to the cybercriminal group ShinyHunters, which the company said carried out the social engineering campaign.

Chief Executive Officer Søren Abildgaard acknowledged the incident in a public statement, apologizing to customers and outlining the company's commitment to strengthening its cybersecurity capabilities. He said Odido would continue investing in security, improve data protection practices, expand customer support, and share lessons learned from the incident.

The CEO also explained why the company refused to pay the ransom demand. According to Odido, paying cybercriminals would reward illegal activity and could encourage future attacks against other Dutch organizations. The company said the decision was made following guidance from authorities, despite knowing that stolen data could eventually be published.

Millions of Customers Impacted

Odido confirmed that approximately 6.39 million active and former customers of Odido and its Ben brand were affected by the breach. Customers of Simpel were not impacted.

The exposed information varied by individual and included names, addresses, mobile phone numbers, customer numbers, email addresses, IBAN numbers, dates of birth, identification details, nationality, and gender.

The company clarified that My Odido account passwords, call records, location data, billing information, and scans of identity documents were not compromised.

Odido also addressed reports claiming customer passwords had been leaked, stating that login passwords remain securely encrypted and were never accessible during the attack. Instead, a separate telephone verification field known as "password_c," used as a customer challenge code, was included for a limited number of customers. The company has since discontinued using that verification method.

Customer Support and Security Measures Expanded

Following the breach, Odido increased customer support by adding more than 140 service agents and introduced additional security measures. These include its "Check je Gesprek" verification service, allowing customers to confirm whether communications claiming to be from Odido are legitimate, along with access to the F-Secure digital security service.

The telecom provider said all customers identified as affected have been notified by email or SMS, while customer service teams continue assisting users with questions related to their specific data exposure.

Meanwhile, Dutch authorities expect investigations into the Odido cyberattack to continue for several months. Police have also warned that cyberattacks targeting businesses and institutions are becoming increasingly common, urging organizations to strengthen cybersecurity defenses and encouraging citizens to remain vigilant against follow-on fraud and phishing attempts.

  • ✇Firewall Daily – The Cyber Express
  • Japan’s Aflac, KDDI, Sapporo, Nidec: Four Breaches, One Common Entry Point Samiksha Jain
    Four major Japan cyberattacks reported within two weeks point to a common trend, with attackers gaining access through subsidiaries and third-party infrastructure rather than corporate headquarters. While the incidents affected companies from different industries, including insurance, telecommunications, brewing, and manufacturing, the breaches shared one notable characteristic. Rather than directly compromising corporate headquarters, attackers gained access through subsidiaries, overseas oper
     

Japan’s Aflac, KDDI, Sapporo, Nidec: Four Breaches, One Common Entry Point

Japan cyberattacks

Four major Japan cyberattacks reported within two weeks point to a common trend, with attackers gaining access through subsidiaries and third-party infrastructure rather than corporate headquarters. While the incidents affected companies from different industries, including insurance, telecommunications, brewing, and manufacturing, the breaches shared one notable characteristic.

Rather than directly compromising corporate headquarters, attackers gained access through subsidiaries, overseas operations, or third-party infrastructure.

The affected organizations include Aflac Japan, KDDI, Sapporo Holdings, and Nidec, each of which reported separate cyber incidents during the second half of June 2026. Although the attacks involved different circumstances, the disclosures point to an expanding attack surface that extends well beyond an organization's primary network.

Aflac Japan Breach Exposed Customer Data

Aflac Japan disclosed on June 30 that attackers accessed its Japanese operations between June 15 and June 25. According to the company, approximately 4.38 million customers and agents were affected, with a subset of records including bank account information used for insurance premium payments.

The insurer stated that the incident was limited to its Japanese business and did not affect its U.S. operations.

While the company has not attributed the attack to any specific threat group, the reported tactics resemble social engineering techniques previously associated with Scattered Spider.

KDDI Incident Impacts Millions Through Shared Platform

Telecommunications provider KDDI reported unauthorized access involving an email platform used by multiple Japanese internet service providers.

The company said the incident stemmed from a vulnerability in third-party software, potentially exposing up to 14.22 million email account records across six ISPs.

The breach demonstrates how a single vulnerability within shared infrastructure can affect multiple organizations simultaneously.

Sapporo Holdings and Nidec Target Overseas Subsidiaries

Sapporo Holdings disclosed suspected unauthorized access involving two overseas subsidiaries, Singapore-based Pokka and Canadian brewer Sleeman. The company detected suspicious activity, shut down affected systems, and launched an investigation to determine whether any information had been accessed or stolen.

Meanwhile, manufacturing company Nidec confirmed a ransomware attack targeting its Taiwanese subsidiary, Nidec Chaun Choung Technology.

The BlackField ransomware group claimed responsibility for the attack, alleging it had stolen more than two terabytes of company data, including employee, financial, procurement, manufacturing, legal, and IT records. The group reportedly demanded a $2 million ransom.

A Shared Pattern Across the Japan Cyberattacks

Despite involving different industries and attack methods, the four Japan cyberattacks reveal a similar point of compromise.

Aflac's breach was limited to its Japanese business. KDDI's exposure originated from a shared email platform relying on vulnerable third-party software. Sapporo's investigation centers on overseas subsidiaries, while Nidec's ransomware incident affected its Taiwan-based operation rather than its headquarters.

These cases suggest attackers are increasingly targeting subsidiaries, shared services, overseas business units, and technology partners instead of attempting to breach an organization's primary corporate network.

Growing Risks Across the Extended Enterprise

The incidents highlight the importance of treating subsidiaries and external partners as part of the organization's overall security perimeter.

Organizations that rely on overseas offices, acquired businesses, vendors, or shared platforms may inherit additional cybersecurity risks if those environments are not protected to the same standard as corporate headquarters.

The KDDI incident illustrates how third-party dependencies can significantly increase the scale of a breach, while the Nidec cyberattack demonstrates how ransomware groups continue to combine data theft with extortion demands.

The reported tactics observed in the Aflac incident also reinforce the continued effectiveness of social engineering as an initial access method.

While investigations into several of the incidents remain ongoing, the recent disclosures underscore a broader trend. As enterprise environments become increasingly interconnected, subsidiaries, shared infrastructure, and external technology providers are becoming attractive targets for attackers seeking indirect access to larger organizations.

  • ✇Firewall Daily – The Cyber Express
  • Alleged Scattered Spider Member Arrested in Finland, Extradited to U.S. Samiksha Jain
    An alleged member of the Scattered Spider cybercrime group has been extradited from Finland to the United States to face federal charges related to conspiracy, cyber intrusion, and fraud. U.S. authorities said the case marks another step in their ongoing efforts to prosecute individuals accused of participating in high-profile cybercrime operations linked to the notorious hacking group. Peter Stokes, 19, a dual U.S. and Estonian citizen, made his initial appearance in federal court in Chicago a
     

Alleged Scattered Spider Member Arrested in Finland, Extradited to U.S.

Scattered Spider

An alleged member of the Scattered Spider cybercrime group has been extradited from Finland to the United States to face federal charges related to conspiracy, cyber intrusion, and fraud. U.S. authorities said the case marks another step in their ongoing efforts to prosecute individuals accused of participating in high-profile cybercrime operations linked to the notorious hacking group.

Peter Stokes, 19, a dual U.S. and Estonian citizen, made his initial appearance in federal court in Chicago after being extradited from Finland.

According to the U.S. Department of Justice, Stokes was arrested by Finnish authorities in April following an Interpol Red Notice and was transferred to the United States last week. A criminal complaint filed in the Northern District of Illinois accuses him of participating in cyberattacks carried out as part of the Scattered Spider group.

Scattered Spider Linked to More Than 100 Network Intrusions

According to the complaint, Scattered Spider, also known as Octo Tempest, UNC3944, and 0ktapus, has been associated with more than 100 network intrusions. Authorities allege the group's activities have resulted in over $100 million in ransom payments and millions of dollars in additional damages suffered by victims.

Investigators said the group targeted companies across the United States by obtaining access to employee accounts through fraudulent methods.

Once inside corporate networks, the attackers allegedly encrypted data or exfiltrated sensitive information to remote servers before demanding cryptocurrency payments to restore access or prevent the public release of stolen data.

Complaint Details Alleged Luxury Retailer Cyberattack

The criminal complaint describes an alleged cyber intrusion that occurred in May 2025 involving a luxury jewelry retailer.

Federal prosecutors allege that Stokes and other co-conspirators breached the retailer's computer systems, exfiltrated company data, and demanded approximately $8 million in cryptocurrency as ransom. According to court documents, the retailer's security team successfully removed the threat actors from its network before any ransom payment was made.

Although the company did not pay the ransom, authorities said it still incurred losses of at least $2 million due to business disruption, investigation costs, and mitigation efforts following the incident.

Operation Riptide Targets Cybercrime Networks

The extradition and criminal charges were announced by the Department of Justice, the U.S. Attorney's Office for the Northern District of Illinois, and the FBI. The investigation also involved the FBI's Copenhagen Law Enforcement Attaché Office, the FBI Las Vegas Field Office, the Justice Department's Office of International Affairs, and Finland's National Bureau of Investigation.

Officials said the case forms part of Operation Riptide, an ongoing FBI campaign focused on disrupting cybercriminal actors, infrastructure, financial networks, and fraud schemes targeting Americans.

According to the FBI, Americans reported more than $20 billion in cybercrime losses last year, representing a 26% increase compared with the previous year.

Authorities Cite International Cooperation

Assistant Attorney General A. Tysen Duva said the charges stem from years of investigative work by the Justice Department, the U.S. Attorney's Office, and the FBI, adding that authorities would continue working together to pursue cybercriminals operating across international borders.

U.S. Attorney Andrew S. Boutros said the alleged attacks caused significant disruption to businesses across the United States and emphasized the government's commitment to prosecuting individuals involved in cyber intrusions.

FBI Special Agent-in-Charge Douglas S. DePodesta also highlighted the role of international law enforcement partnerships in identifying alleged members of the hacking group and pursuing cross-border cybercrime investigations.

Recent Guidance on Scattered Spider Threat

The arrest follows recent law enforcement efforts targeting the Scattered Spider threat group. In July 2025, the FBI and CISA released updated guidance describing the group's latest attack techniques, including the use of DragonForce ransomware to encrypt VMware ESXi servers.

The advisory urged organizations to maintain isolated offline backups, implement phishing-resistant multifactor authentication (MFA), and apply application controls to manage software execution.

Separately, in November 2025, two alleged Scattered Spider members appeared before Southwark Crown Court in the United Kingdom and pleaded not guilty to charges related to the August 2024 cyberattack on Transport for London (TfL).

The Department of Justice emphasized that the complaint against Stokes contains allegations only. As with all criminal cases, he is presumed innocent unless and until proven guilty in court.

Ransomware Attacks Surge 30% in 2026 as Qilin and INC Ransom Intensify Operations

Qilin

Ransomware attacks surged 30% in the first half of 2026 compared to the same period in 2025, with Qilin and INC Ransom emerging as two of the most prolific and dangerous operators in a crowded criminal ecosystem. Healthcare continues to be the top targeted industry, with 27 incidents in January 2026 alone, a figure that reflects both the sector's operational sensitivity and the premium value of health records on darknet markets.

Qilin: The Dominant Force

Qilin — also known as Agenda — is a ransomware group that entered 2026 accelerating, not slowing down. By early 2026, Qilin had already posted 55 confirmed victims, placing it ahead of its own 2025 pace. By June 2026, tracking data, Qilin had accumulated 168 confirmed victims in the healthcare sector alone, behind only manufacturing (291) and business services (245) in overall victim count. Qilin operates as a Ransomware-as-a-Service (RaaS) platform, recruiting affiliates who conduct attacks using Qilin's ransomware builder and infrastructure in exchange for a percentage of ransom proceeds. This model allows the core group to expand operational throughput without directly executing every attack. The group's double extortion model — encrypting victim data while simultaneously exfiltrating it and threatening public release on their leak site — has proven effective at pressuring victims into paying ransom demands even when robust backups exist. Public exposure of sensitive patient records creates regulatory, legal, and reputational pressure that many healthcare organisations find more immediately damaging than operational downtime. A notable recent case involves Covenant Health, which suffered a Qilin ransomware breach that exposed 478,188 patient records. The Covenant Health incident highlights Qilin's willingness to attack hospitals and health systems regardless of the direct patient safety implications.

INC Ransom: Targeting Critical Sectors

INC Ransom is another highly active operator that was among the top ransomware groups by victim count in January 2026, with 47 known attacks that month. The group targets organisations across multiple sectors, including healthcare, legal services, and public administration. INC Ransom gained significant attention in 2025 for its attack on NHS Scotland, which exposed 3 terabytes of patient data. The group continues to operate aggressively in 2026, targeting entities including healthcare practices, municipal agencies, and regional service providers. Recent INC Ransom victims include healthcare organisations such as Lymphedema Therapy Specialists, Inc. (February 2026, affecting 378 Texas patients) and various municipal and public sector entities, including Champaign-Urbana Public Health District.

The 2026 Ransomware Landscape

Beyond Qilin and INC Ransom, the broader 2026 ransomware ecosystem is characterised by:
  • AI-assisted operations: Multiple ransomware groups are now using AI tools to accelerate phishing campaign creation, target research, and initial access operations, reducing the operational cost of launching attacks.
  • Healthcare as a premium target: Patient records sell for up to 10 times as much as financial records on darknet markets, making it a persistently attractive target. Operational disruption of healthcare services also creates patient-safety leverage that can pressure organisations to make faster payment decisions.
  • The Play and SafePay operators were also confirmed in recent June 2026 attack disclosures, targeting organisations including Clínica Maitenes and various regional businesses.

Why It Matters

The 30% year-over-year increase in ransomware incidents confirms that neither law enforcement action nor improved defensive capabilities has materially reduced the operational tempo of ransomware criminal enterprises. The professionalisation of RaaS platforms, combined with AI-assisted tooling and shortened attack timelines, is creating conditions in which even well-defended organisations face materially elevated risk. For healthcare specifically, the combination of operational sensitivity, high data value, and historically underfunded security programmes creates a structural vulnerability that the industry has not yet resolved despite years of high-profile attacks.
  • ✇Firewall Daily – The Cyber Express
  • Foxconn Confirms Cyberattack as Nitrogen Ransomware Claims 8TB Data Theft Ashish Khaitan
    Foxconn, one of the world’s largest electronics manufacturers and a major supplier to Apple, has confirmed that a recent Foxconn cyberattack disrupted operations at several of its North American facilities. According to online reports, a ransomware group known as Nitrogen claimed responsibility for the incident and alleged that it stole massive amounts of company data. The Nitrogen ransomware group claimed earlier this week that it exfiltrated more than eight terabytes of data from Foxconn sy
     

Foxconn Confirms Cyberattack as Nitrogen Ransomware Claims 8TB Data Theft

Foxconn cyberattack

Foxconn, one of the world’s largest electronics manufacturers and a major supplier to Apple, has confirmed that a recent Foxconn cyberattack disrupted operations at several of its North American facilities. According to online reports, a ransomware group known as Nitrogen claimed responsibility for the incident and alleged that it stole massive amounts of company data. The Nitrogen ransomware group claimed earlier this week that it exfiltrated more than eight terabytes of data from Foxconn systems. The group alleged that the stolen information included over 11 million files. Researchers also said the attackers claimed to possess schematics connected to several major technology companies that work with Foxconn. While the Nitrogen ransomware operators made claims regarding the cyberattack on Foxconn, the company itself has not publicly confirmed whether any data was stolen, whether systems were encrypted, or whether a ransom demand was issued.

Company Activates Emergency Response Measures 

In a statement addressing the Foxconn cyberattack, the company said its cybersecurity team responded immediately after detecting the incident.  “Some of Foxconn’s factories in North America suffered a cyberattack,” the company said, as reported by the DysruptionHub. “The cybersecurity team immediately activated the response mechanism and implemented multiple operational measures to ensure the continuity of production and delivery. The affected factories are currently resuming normal production.”  The ransomware-related disruption reportedly affected operational systems at several facilities, although Foxconn did not identify which factories were impacted. The company operates more than 230 factories and offices across 24 countries, including major facilities in Wisconsin, Texas and other parts of the United States.

Wisconsin Facility Employees Report Network Outages 

The cyberattack on Foxconn first became publicly noticeable after employees at one of the company’s Wisconsin facilities reported severe IT disruptions. An employee told DysruptionHub that workers began experiencing Wi-Fi issues on Friday, before being sent home due to widespread network outages. According to the employee, computers stopped functioning properly, forcing staff members to complete certain tasks manually using paper and pen. At the time, Foxconn confirmed only that it was experiencing technical issues and had activated emergency response mechanisms to address the situation. The company later stated that certain functions affected by the Foxconn cyberattack were gradually being restored.

Nitrogen Ransomware Group Publishes Data Theft Claims 

The Nitrogen ransomware group publicly listed Foxconn on its leak site on Monday, May 11, only days after reports emerged regarding operational disruptions at Foxconn’s Wisconsin sites. The group claimed it possessed approximately 8 terabytes of data collected during the ransomware attack and shared sample images it described as evidence of the breach.  However, those claims remain unverified. DysruptionHub reported that it could not independently confirm whether the files posted by Nitrogen were authentic, whether data had actually been stolen, or whether the alleged leak was directly connected to the operational disruptions experienced at Foxconn facilities in Wisconsin.  Foxconn has not confirmed ransomware involvement, data theft, or the existence of a ransom demand. The company previously described the disruption as a technical issue affecting IT systems and said restoration efforts were underway.

Experts Link Nitrogen to Conti-Based Ransomware Builder 

Cybersecurity experts have linked Nitrogen ransomware activity to tools and infrastructure associated with the now-defunct Conti ransomware operation. Researchers at Barracuda Networks described Nitrogen as “a sophisticated and financially motivated threat group that was first observed as a malware developer and operator in 2023.”  Experts believe the Nitrogen ransomware strain may have been created using a builder derived from the Conti ransomware codebase. The growing sophistication of ransomware groups has raised concerns across the manufacturing sector, particularly among companies managing large-scale supply chains and sensitive operational infrastructure. 

Foxconn Has Faced Multiple Ransomware Incidents 

The latest Foxconn cyberattack is not the first time the company has faced threats from ransomware gangs. Foxconn has repeatedly been targeted by cybercriminal groups in recent years. In 2024, the company’s semiconductor business reportedly suffered a ransomware attack carried out by the LockBit gang. Prior to that, Foxconn’s manufacturing facilities in Mexico were targeted in 2022 by the same cybercriminal group. Another ransomware attack also affected Foxconn operations in Mexico in 2020.  As the world’s largest contract electronics manufacturer, Foxconn produces hardware for companies including Apple, Google, Microsoft and Cisco. The company reported approximately $258.3 billion in revenue in 2025, highlighting the scale of its operations and the potential global impact of disruptions caused by ransomware attacks. The Cyber Express has also reached out to the organization to learn more about this Foxconn cyberattack. We will update this post once we have more information on the attack or any new information from the company.

The Cyber Express Weekly Roundup: Data Breaches, Malware Campaigns, and Cyber Fraud Investigations

weekly roundup TCE cybersecurity news

In this week’s edition of The Cyber Express weekly roundup, we explore the latest developments in the world of cybersecurity, focusing on high-profile data breaches, growing malware campaigns, and law enforcement actions against cybercriminals.   As the digital threat landscape continues to evolve, attackers are targeting sensitive personal and organizational data, from health records to financial credentials. Meanwhile, government regulators are ramping efforts to protect minors and combat harmful content on social platforms, while cybercriminals continue to exploit vulnerabilities in both public and private sectors.  This weekly roundup highlights how various industries, from healthcare and social media to finance and government, are grappling with rising threats, making it clear that the intersection of data security, regulation, and cybercrime is more critical than ever.  

The Cyber Express Weekly Roundup 

UK Biobank Data Breach Triggers Urgent Review of Data Security Measures 

A significant data breach at the UK Biobank has raised major concerns over the security of health-related data used in scientific research. In April 2026, de-identified participant information was discovered being sold on a Chinese consumer platform, sparking widespread alarm among the research community. Read more... 

Vercel CEO Reveals Expansion of Malware Campaign Affecting Multiple Targets 

Vercel's CEO, Guillermo Rauch, confirmed that the recent breach involving Context.ai was part of a much larger malware campaign affecting multiple targets. Following a review of network logs, Vercel’s security team uncovered evidence of malware distribution that compromised several customer accounts, including access to valuable Vercel account keys. Read more... 

Ofcom Investigates Telegram and Teen Platforms 

In the UK, Ofcom has launched an investigation into Telegram and several popular teen chat platforms, such as Teen Chat and Chat Avenue, after reports surfaced of online grooming and child sexual abuse material (CSAM) on these services. Under the Online Safety Act, platforms are required to take proactive steps to prevent harmful content and protect minors from exploitation. Read more... 

Personal Data Exposed in Breach of France’s ANTS Portal 

A recent breach of France’s ANTS (Agence Nationale des Titres Sécurisés) portal has compromised personal data, including names, email addresses, and birthdates, although no documents or sensitive attachments were affected. The breach, which occurred on April 15, 2026, raises significant concerns about identity theft and phishing risks, as the exposed data could be used to target individuals. Read more... 

Bluesky Faces Coordinated DDoS Attack 

Bluesky, the rapidly expanding social media platform, suffered a major disruption on April 15, 2026, when it was targeted by a sophisticated distributed denial-of-service (DDoS) attack. The attack caused widespread outages, impacting core platform functions such as user feeds, notifications, and search capabilities. Read more... 

Indian Authorities Arrest Key SIM Card Supplier in Cyber Fraud Crackdown 

India’s Central Bureau of Investigation (CBI) has arrested a key conspirator in a major cyber fraud operation as part of Operation Chakra-V. The suspect, arrested in Guwahati, is accused of supplying fraudulent SIM cards used in various cybercrime schemes, including extortion and fake loan scams. The SIM cards were acquired using fake identities and distributed to cybercriminal networks. Read more... 

Weekly Takeaway 

This week’s roundup highlights the diverse and evolving nature of cyber threats. From the exposure of sensitive health data and sophisticated malware campaigns to DDoS attacks and SIM card fraud schemes, the cybersecurity landscape remains fraught with challenges. Regulatory bodies and companies alike continue to grapple with emerging risks, particularly in sectors like public health data, social media platforms, and digital content safety. As these incidents unfold, it’s clear that both technical vulnerabilities and human factors, such as social engineering, continue to be central targets for attackers.  With regulatory frameworks like the Online Safety Act and increased investigative efforts in places like India and France, the pressure on platforms and authorities to act quickly and decisively is higher than ever. As the cyber threat landscape becomes more interconnected, the need for enhanced security protocols, improved monitoring, and greater accountability in digital spaces remains critical. 

March 2026 Cyber Threat Landscape Fueled by Ransomware, Breaches, and Access Markets

2026 threat landscape

The 2026 threat landscape continued to intensify in March, with ransomware attacks, expanding data breach activity, and a growing underground market for compromised access shaping the global cybersecurity environment. According to analysis from CRIL (Cyble Research & Intelligence Labs), organizations worldwide faced a highly active and coordinated threat ecosystem throughout the month.  CRIL’s findings point to a cybercriminal landscape driven by financial extortion, credential theft, and operational disruption. Attackers consistently targeted industries that rely heavily on uptime or store large volumes of sensitive data, reinforcing the urgency for stronger defensive strategies. 

Ransomware Attacks Dominate the 2026 Threat Landscape 

Top five ransomware actors (Data Source: Cyble Blaze AI) One of the most defining aspects of the March 2026 threat landscape was the scale of ransomware attacks. CRIL recorded 702 ransomware incidents globally, underscoring the continued dominance of ransomware as a primary attack vector.  Among the most active threat groups were Qilin, Akira, The Gentlemen, Dragonforce, and INC Ransom. Collectively, these actors were responsible for over 56% of all observed ransomware activity, reflecting their operational maturity and extensive affiliate networks.  Industries most affected by ransomware attacks included: 
  • Construction  
  • Professional Services  
  • Manufacturing  
  • Healthcare  
  • Energy & Utilities  
Attackers frequently employed double-extortion tactics, combining data theft with system disruption to increase pressure on victims. Geographically, the United States remained the primary target, influenced in part by ongoing geopolitical tensions, including those involving Iran. 

Rise of Access Brokers in the CRIL Threat Analysis 

Another notable trend in the 2026 threat landscape, as identified by CRIL, was the continued growth of the compromised access market. During March, 20 separate incidents involving the sale of unauthorized network access were tracked across cybercrime forums.  The most targeted sectors for access sales were: 
  • Professional Services (25%)  
  • Retail (20%)  
  • IT & ITES  
  • Manufacturing  
A small group of threat actors, vexin, holyduxy, and algoyim, dominated this space, accounting for more than 55% of observed listings. These access brokers play a critical upstream role, enabling ransomware attacks, espionage campaigns, and financial fraud operations. 

Data Breaches and Leak Markets Stay Active 

CRIL also documented 54 significant data breach and leak incidents in March, further highlighting the scale of data exposure risks in the current 2026 threat landscape.  The most targeted sectors for data breaches included: 
  • Government & Law Enforcement  
  • Retail  
  • Technology  
Several incidents stood out: 
  • A threat actor known as “nightly” claimed to have stolen over 5TB of data from Hospitality Holdings, including biometric data, CCTV footage, and financial records. 
  • Another actor, XP95, advertised 3.8TB of allegedly stolen South African government data for sale.  
  • A separate breach exposed more than 95,000 travel-related records, including passport and payment information.  

Exploitation of Critical Vulnerabilities Accelerates 

The 2026 threat landscape also saw increased exploitation of critical vulnerabilities, particularly those listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog.  Key vulnerabilities targeted included: 
  • CVE-2026-20131 (Cisco Secure Firewall Management Center)  
  • CVE-2025-53521 (F5 BIG-IP APM)  
  • CVE-2026-20963 (Microsoft SharePoint Server)  
  • CVE-2026-33017 (Langflow AI)  
  • CVE-2021-22681 (Rockwell Automation ICS 
CRIL observed attackers exploiting both newly disclosed zero-day vulnerabilities and older, unpatched flaws. This trend reflects persistent gaps in patch management and exposure mitigation across organizations. 

Emerging Threat Developments in March 2026 

Beyond ransomware attacks and data breaches, CRIL identified several strategic developments shaping the 2026 threat landscape: 
  • AI-Driven Attacks: Threat actors reportedly leveraged an open-source framework called CyberStrikeAI to target Fortinet FortiGate devices across 55 countries, compromising more than 600 systems. 
  • Supply Chain RisksNorth Korean-linked actors were associated with 26 malicious npm packages distributing remote access trojans (RATs) via infrastructure hosted on Pastebin and Vercel. 
  • Geopolitical Cyber Activity: Iran-linked cyber operations are expected to increase, with potential ransomware attacks and hacktivist campaigns targeting organizations in the Middle East. 

The Cyber Express Weekly Roundup: Crypto Breaches, State-Linked Schemes, and Platform Exploits

The Cyber Express weekly roundup cybersecurity

In this week’s weekly roundup, The Cyber Express reviews major developments across the cybersecurity domain. highlighting incidents involving crypto ecosystem attacks, state-linked fraud operations, regulatory scrutiny, and underground cybercrime activity. The broader threat landscape continues to show attackers targeting infrastructure weaknesses, social engineering pathways, and third-party dependencies rather than isolated technical flaws.  Across multiple cases, state-aligned and financially motivated actors are focusing on routers, DNS layers, and decentralized systems to intercept data and manipulate transactions. At the same time, gaps in regulation and enforcement continue to complicate platform accountability, particularly in online safety and digital content governance.  

The Cyber Express Weekly Roundup 

$15M Grinex Hack Halts Trading After Wallet Breach 

Grinex suspended trading and withdrawals following a coordinated attack that compromised its wallet infrastructure, resulting in the theft of more than $15 million in USDT. The attackers rapidly moved assets across Ethereum and Tron networks, using chain-hopping and layering techniques to obscure transaction trails and avoid detection. Read more... 

Two U.S. Nationals Sentenced in $5M North Korea IT Worker Scheme 

Two U.S. nationals, Kejia Wang and Zhenxing Wang, received prison sentences of 108 and 92 months for their roles in a North Korea-linked remote employment scheme that generated over $5 million. The operation used stolen identities, domestic “laptop farms,” and shell companies to present overseas workers as U.S.-based employees across more than 100 companies. Read more... 

Australia Social Media Ban Faces Enforcement Questions 

Australia’s under-16 social media restriction is facing renewed scrutiny after a study of 1,050 children found that over 60% of previously active users aged 12–15 continue accessing platforms such as TikTok, YouTube, and Instagram. Many accounts remained active without intervention from providers, and in some cases, users created new profiles after restrictions were applied. Read more... 

TierOne Dark Web Contest Offers $10K for Exploit Writeups 

A dark web forum known as TierOne has launched a $10,000 contest encouraging detailed technical write-ups on vulnerability exploitation techniques. Running from April 13 to May 14, 2026, and reportedly sponsored by a ransomware group, the contest focuses on topics such as remote code execution, IDOR, SSTI, firmware attacks, and EDR bypass methods.  Read more... 

Rockstar Cyberattack Confirmed Amid Extortion Threat 

Rockstar Games confirmed a cyberattack involving unauthorized access through a third-party service, though it stated that core operations and player systems were unaffected. The threat actor group ShinyHunters claimed responsibility, alleging access to internal company data and demanding payment by April 14, 2026, under threat of public release. Read more... 

Weekly Takeaway 

The Cyber Express weekly roundup reflects a threat landscape that is fragmented yet interconnected. From multimillion-dollar crypto thefts and criminal employment schemes to underground exploit markets and extortion-driven breaches, attackers are consistently blending technical exploitation with deception and supply chain targeting.   Regulatory uncertainty and weak enforcement mechanisms further amplify these risks, allowing both state-linked and financially motivated actors to operate with greater flexibility across digital environments. 
  • ✇Firewall Daily – The Cyber Express
  • JanaWare Ransomware Targets Turkish Users Through Adwind RAT Campaign Samiksha Jain
    A newly identified cyber campaign involving JanaWare ransomware is targeting users in Turkey, with researchers linking the activity to a customized version of the Adwind Remote Access Trojan (RAT). The findings come from an analysis by researchers at Acronis’ Threat Research Unit (TRU), who identified the threat cluster during an investigation into suspicious Java-based malware samples. According to the researchers, the JanaWare ransomware operation appears to have been active since at least
     

JanaWare Ransomware Targets Turkish Users Through Adwind RAT Campaign

JanaWare Ransomware Targets Turkish Users

A newly identified cyber campaign involving JanaWare ransomware is targeting users in Turkey, with researchers linking the activity to a customized version of the Adwind Remote Access Trojan (RAT). The findings come from an analysis by researchers at Acronis’ Threat Research Unit (TRU), who identified the threat cluster during an investigation into suspicious Java-based malware samples. According to the researchers, the JanaWare ransomware operation appears to have been active since at least 2020. Evidence from malware samples and infrastructure indicates that the campaign has continued into late 2025, suggesting sustained activity with limited visibility. The attack relies on a modified Adwind RAT that includes polymorphic capabilities. This allows the malware to change its structure across infections, making detection more difficult. Combined with code obfuscation, these techniques have likely contributed to the campaign remaining relatively unnoticed. Unlike large ransomware groups that focus on high-value enterprise targets, JanaWare ransomware appears to follow a different strategy. Observed ransom demands range between $200 and $400, pointing to a model that prioritizes volume over large individual payouts.

Phishing Identified as Primary Infection Vector

The JanaWare ransomware campaign primarily spreads through phishing emails. Victims are lured into clicking malicious links, which lead to the download of a Java archive file. In many observed cases, the payload is hosted on cloud storage platforms. Telemetry data reviewed by researchers shows a consistent attack chain. A phishing email is opened in Microsoft Outlook, followed by a browser session that downloads the malicious file. The file is then executed using Java, triggering the infection. [caption id="attachment_111347" align="aligncenter" width="761"]JanaWare Ransomware Image Source: Acronis’ Threat Research Unit (TRU)[/caption] User reports on public cybersecurity forums also describe similar incidents, supporting the assessment that phishing is the main entry point.

Geofencing Restricts Janaware Ransomware Attacks to Turkey

A key feature of the JanaWare ransomware is its use of geofencing. The malware is designed to execute only on systems that meet specific regional criteria linked to Turkey. It checks system language, locale settings, and external IP geolocation before proceeding. If the system does not match Turkish parameters, the malicious activity is halted. Researchers note that this approach likely serves both operational and defensive purposes. It allows attackers to focus on a specific region while reducing exposure to global security monitoring and automated analysis systems.

Obfuscation and Polymorphism Hinder Detection

The JanaWare ransomware incorporates multiple techniques to evade detection. Researchers identified the use of known obfuscation tools such as Stringer and Allatori, alongside custom methods that complicate analysis. The malware also includes a self-modifying component that alters its file structure during deployment. By adding random data to its Java archive, each instance generates a unique file hash, limiting the effectiveness of signature-based detection. In addition, the malware contains embedded configuration parameters that control its behavior. These include command-and-control server details, communication ports, and authentication values used during initial connections.

Security Controls Disabled Before Encryption Stage

Before encrypting files, the malware attempts to weaken system defenses. It executes commands to disable Microsoft Defender, suppress security alerts, and remove recovery mechanisms such as Volume Shadow Copies. It also interferes with Windows Update and scans for installed antivirus software. These steps reduce the likelihood of detection or recovery once the ransomware payload is activated. The encryption process is carried out by a secondary module delivered after the initial compromise. This module uses AES encryption and communicates with command-and-control infrastructure over the Tor network.

Turkish-Language Ransom Notes Signal Targeted Approach

After encryption, the malware drops ransom notes across affected systems. These notes are written in Turkish and instruct victims to contact the attackers through encrypted communication channels such as qTox or Tor-based websites. Researchers say the consistent use of Turkish-language content, combined with geofencing, indicates a deliberate focus on users in Turkey rather than a broad, global campaign. The JanaWare ransomware campaign highlights how targeted, lower-profile operations can persist over long periods without drawing significant attention. By focusing on home users and small businesses, and keeping ransom demands relatively low, the attackers appear to maintain a steady but less visible operation. Researchers caution that such localized campaigns may continue to operate alongside larger ransomware groups, adding another layer to the evolving threat landscape.
❌
❌