⤷ Title: Fake Ukrainian Police Emails Spread New CountLoader Malware Loader
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Mon, 22 Sep 2025 15:15:58 +0000
════════════════════════
⌗ Tags: #Security #Cyber Attacks #Phishing Scam #BlackBasta #CountLoader #Cybersecurity #Fraud #LockBit #Malware #Phishing #Police #Qilin #Ransomware #Russia #Scam #Ukraine
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Mon, 22 Sep 2025 15:15:58 +0000
════════════════════════
⌗ Tags: #Security #Cyber Attacks #Phishing Scam #BlackBasta #CountLoader #Cybersecurity #Fraud #LockBit #Malware #Phishing #Police #Qilin #Ransomware #Russia #Scam #Ukraine
Hackread
Fake Ukrainian Police Emails Spread New CountLoader Malware Loader
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: Detecting Malicious ZIP Archive Decryption via Event 5379
════════════════════════
𐀪 Author: Abdul
════════════════════════
ⴵ Time: Tue, 23 Sep 2025 11:30:28 GMT
════════════════════════
⌗ Tags: #cybersecurity #lockbit #ransomware_protection #ransomware #siem
════════════════════════
𐀪 Author: Abdul
════════════════════════
ⴵ Time: Tue, 23 Sep 2025 11:30:28 GMT
════════════════════════
⌗ Tags: #cybersecurity #lockbit #ransomware_protection #ransomware #siem
Medium
Detecting Malicious ZIP Archive Decryption via Event 5379
1. Background & Context
⤷ Title: LockBit 5.0 Ransomware: Cross-Platform Evolution Targets Windows, Linux, and ESXi
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 27 Sep 2025 00:11:12 +0000
════════════════════════
⌗ Tags: #Malware #Cybercrime #ESXi #Linux #LockBit 5.0 #Operation Cronos #ransomware #threat actor #Trend Research #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 27 Sep 2025 00:11:12 +0000
════════════════════════
⌗ Tags: #Malware #Cybercrime #ESXi #Linux #LockBit 5.0 #Operation Cronos #ransomware #threat actor #Trend Research #windows
Daily CyberSecurity
LockBit 5.0 Ransomware: Cross-Platform Evolution Targets Windows, Linux, and ESXi
LockBit 5.0 resurfaces with advanced Windows, Linux, and ESXi variants, boasting heavy obfuscation and anti-forensic techniques, making it more dangerous than ever.
⤷ Title: LockBit 5.0 Resurfaces After Takedown: New Cross-Platform Ransomware Hits Linux and ESXi
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 04:03:05 +0000
════════════════════════
⌗ Tags: #Malware #cybercrime #ESXi #Linux #LockBit 5.0 #Operation Cronos #ransomware #Threat Actor #Trend Micro #windows
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 04:03:05 +0000
════════════════════════
⌗ Tags: #Malware #cybercrime #ESXi #Linux #LockBit 5.0 #Operation Cronos #ransomware #Threat Actor #Trend Micro #windows
Penetration Testing Tools
LockBit 5.0 Resurfaces After Takedown: New Cross-Platform Ransomware Hits Linux and ESXi
LockBit 5.0 resurfaces with advanced Windows, Linux, and ESXi variants, boasting heavy obfuscation and anti-forensic techniques, making it more dangerous than its predecessors.
⤷ Title: LockBit: from the Russian laboratory to the never-ending shadow of cybercrime
════════════════════════
𐀪 Author: Rodrigo Gutierrez
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 01:09:49 GMT
════════════════════════
⌗ Tags: #lockbit #ransomware #malware #cybersecurity #cyber_defense
════════════════════════
𐀪 Author: Rodrigo Gutierrez
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 01:09:49 GMT
════════════════════════
⌗ Tags: #lockbit #ransomware #malware #cybersecurity #cyber_defense
Medium
LockBit: from the Russian laboratory to the never-ending shadow of cybercrime
In 2019, on Russian underground forums, a piece of malware appeared without glamour, baptized simply as “ABCD” after the extension it left…
⤷ Title: Wait, What?! LockBit 5.0 is Back? (Part 1)
════════════════════════
𐀪 Author: Abdelrahmanhamdy
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 21:34:05 GMT
════════════════════════
⌗ Tags: #lockbit #cybersecurity #threat_intelligence #cybercrime
════════════════════════
𐀪 Author: Abdelrahmanhamdy
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 21:34:05 GMT
════════════════════════
⌗ Tags: #lockbit #cybersecurity #threat_intelligence #cybercrime
Medium
🤯 Wait, What?! LockBit 5.0 is Back? (Part 1)
So, I was scrolling through Hacker News and saw a headline for LockBit 5.0. I honestly couldn’t believe my eyes. Are they really still…
⤷ Title: DFIR Tool Hijacked: Ransomware Group Storm-2603 Abuses Velociraptor for Stealthy LockBit/Babuk Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 01:50:50 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Babuk #cybersecurity #DFIR #LockBit #ransomware #Storm_2603 #Tool Abuse #Velociraptor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 01:50:50 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Babuk #cybersecurity #DFIR #LockBit #ransomware #Storm_2603 #Tool Abuse #Velociraptor
Daily CyberSecurity
DFIR Tool Hijacked: Ransomware Group Storm-2603 Abuses Velociraptor for Stealthy LockBit/Babuk Attacks
Cisco Talos confirms Storm-2603 is abusing the DFIR tool Velociraptor for persistence and arbitrary code execution, deploying LockBit and Babuk ransomware against VMware and Windows servers.
⤷ Title: Ransomware Group Storm-2603 Abuses Velociraptor for Stealthy LockBit/Babuk Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 02:52:41 +0000
════════════════════════
⌗ Tags: #Malware #Babuk #cybersecurity #DFIR #LockBit #ransomware #Storm_2603 #Tool Abuse #Velociraptor
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 02:52:41 +0000
════════════════════════
⌗ Tags: #Malware #Babuk #cybersecurity #DFIR #LockBit #ransomware #Storm_2603 #Tool Abuse #Velociraptor
Penetration Testing Tools
Ransomware Group Storm-2603 Abuses Velociraptor for Stealthy LockBit/Babuk Attacks
Cisco Talos confirms Storm-2603 is abusing an outdated Velociraptor build (CVE-2025-6264) for persistence and arbitrary code execution, deploying LockBit and Babuk ransomware.
⤷ Title: LockBit Rises: New Cross-Platform 5.0 Ransomware Eclipses Former Self
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 09:38:28 +0000
════════════════════════
⌗ Tags: #Malware #cybercrime #ESXi #Linux #LockBit #Operation Cronos #ransomware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 09:38:28 +0000
════════════════════════
⌗ Tags: #Malware #cybercrime #ESXi #Linux #LockBit #Operation Cronos #ransomware
Penetration Testing Tools
LockBit Rises: New Cross-Platform 5.0 Ransomware Eclipses Former Self
After Operation Cronos, LockBit resurfaced with the cross-platform 5.0 ("ChuongDong") ransomware, which uses advanced anti-analysis and hits Windows, Linux, and ESXi servers.
⤷ Title: LockBit 5.0 Resurfaces Amid Chaos as Ransomware Market Enters New Phase of Fragmentation
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 03:48:33 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #CheckPointResearch #cybercrime #Fragmentation #LockBit #LockBit5 #OperationCronos #RansomHub #ransomware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 03:48:33 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #CheckPointResearch #cybercrime #Fragmentation #LockBit #LockBit5 #OperationCronos #RansomHub #ransomware
Penetration Testing Tools
LockBit 5.0 Resurfaces Amid Chaos as Ransomware Market Enters New Phase of Fragmentation
The ransomware market fragmented into 85 active groups in Q3 2025. LockBit 5.0 resurfaced, but Check Point notes the landscape is now highly fluid and less predictable.
⤷ Title: UK Exposes Bulletproof Hosting Operator Linked to LockBit and Evil Corp
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 19:02:47 +0000
════════════════════════
⌗ Tags: #Cyber Crime #Bulletproof #Cybersecurity #Evil Corp #Five Eyes #Hosting #LockBit #NCA #Ransomware #Russia
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 19:02:47 +0000
════════════════════════
⌗ Tags: #Cyber Crime #Bulletproof #Cybersecurity #Evil Corp #Five Eyes #Hosting #LockBit #NCA #Ransomware #Russia
Hackread
UK Exposes Bulletproof Hosting Operator Linked to LockBit and Evil Corp
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: LockBit 5.0 Resurfaces Stronger: New Variant Blinds Defenders by Disabling Windows ETW for Stealth Encryption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:06:57 +0000
════════════════════════
⌗ Tags: #Malware #anti_forensics #Cross_Platform #Cybercrime #ESXi #ETW Blinding #LockBit 5.0 #Operation Cronos #ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:06:57 +0000
════════════════════════
⌗ Tags: #Malware #anti_forensics #Cross_Platform #Cybercrime #ESXi #ETW Blinding #LockBit 5.0 #Operation Cronos #ransomware
Daily CyberSecurity
LockBit 5.0 Resurfaces Stronger: New Variant Blinds Defenders by Disabling Windows ETW for Stealth Encryption
Despite takedown, LockBit 5.0 resurges as a cross-platform threat. The new variant blinds Windows Event Tracing (ETW), uses Invisible Mode for stealth encryption, and overwrites free disk space.
⤷ Title: New 01flip Ransomware Hits APAC Critical Infra: Cross-Platform Rust Weapon Uses Sliver C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 03:10:55 +0000
════════════════════════
⌗ Tags: #Malware #01flip #APAC #Cross_Platform #CVE_2019_11580 #LockBit #ransomware #Rust #Sliver
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 03:10:55 +0000
════════════════════════
⌗ Tags: #Malware #01flip #APAC #Cross_Platform #CVE_2019_11580 #LockBit #ransomware #Rust #Sliver
Daily CyberSecurity
New 01flip Ransomware Hits APAC Critical Infra: Cross-Platform Rust Weapon Uses Sliver C2
New 01flip ransomware (written in Rust) targets APAC critical infra across Windows/Linux. The attackers use Sliver for C2 and older exploits for access. A curious "lockbit" ignore list was found in the code.
⤷ Title: GOLD SALEM Abuses Velociraptor DFIR Tool as Ransomware Precursor Following SharePoint ToolShell Exploitation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:20:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_nexus #DFIR Abuse #GOLD SALEM #LockBit #ransomware #Sharepoint #ToolShell #Velociraptor #Warlock
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:20:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_nexus #DFIR Abuse #GOLD SALEM #LockBit #ransomware #Sharepoint #ToolShell #Velociraptor #Warlock
Daily CyberSecurity
GOLD SALEM Abuses Velociraptor DFIR Tool as Ransomware Precursor Following SharePoint ToolShell Exploitation
GOLD SALEM (Storm-2603) is exploiting SharePoint via ToolShell then abusing the Velociraptor DFIR tool as a ransomware precursor. The group deploys Warlock and LockBit 3.0 variants, often targeting critical infra.
⤷ Title: The Extortion Deficit: Ransomware Payments Plunge by 33% as Victims Refuse to Pay
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 02:06:41 +0000
════════════════════════
⌗ Tags: #Malware #AML Act 2020 #BlackCat #Cybersecurity 2024 #Financial Crime #FinCEN #Healthcare Data #LockBit #Manufacturing Security #ransomware #U.S. Treasury
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 02:06:41 +0000
════════════════════════
⌗ Tags: #Malware #AML Act 2020 #BlackCat #Cybersecurity 2024 #Financial Crime #FinCEN #Healthcare Data #LockBit #Manufacturing Security #ransomware #U.S. Treasury
Penetration Testing Tools
The Extortion Deficit: Ransomware Payments Plunge by 33% as Victims Refuse to Pay
The U.S. Treasury is cautiously suggesting that the ransomware market may be beginning to cool. In a new
⤷ Title: A Desperate Cartel: Inside the Unlikely Alliance of Qilin, DragonForce, and a Fading LockBit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:43:35 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cyber_espionage #Cybercrime Cartel #data extortion #DragonForce #LockBit #Operation Cronos #Qilin #RaaS #ransomware #Yarix Intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:43:35 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cyber_espionage #Cybercrime Cartel #data extortion #DragonForce #LockBit #Operation Cronos #Qilin #RaaS #ransomware #Yarix Intelligence
Daily CyberSecurity
A Desperate Cartel: Inside the Unlikely Alliance of Qilin, DragonForce, and a Fading LockBit
In a digital underworld increasingly fractured by law enforcement takedowns and eroding trust, three of the most notorious ransomware groups have allegedly joined forces. A new report by the Yarix…