Threat Intelligence
Actionable insights to stay ahead of evolving cyber threats.
SafePay Ransomware
Oct 8, 2025SafePay, active since late 2024, is a quiet but fast-moving in-house ransomware group that uses VPN/RDP and stolen credentials to exfiltrate data and rapidly encrypt high-value targets; defenders should watch for unusual remote logins, privilege escalation, and shadow-copy deletions to stop it early.
read more...
DragonForce Ransomware
Sep 26, 2025DragonForce has evolved from hacktivists into a professional double-extortion ransomware operation. This post gives a hands-on technical breakdown—encryption scheme (ChaCha + appended footer), loader/evasion tactics, kernel driver abuse, exfiltration capabilities, MITRE ATT&CK mapping, IOCs, and concrete defensive takeaways.
read more...
Bert Ransomware
Sep 26, 2025Bert ransomware is brutally efficient and deceptively simple. Unlike advanced families packed with obfuscation, Bert relies on speed, multithreaded AES encryption, and ruthless process termination to cripple Windows and Linux systems. This post examines its use of PowerShell loaders, database-killing routines, intermittent encryption, and Session-based negotiations.
read more...