Tag
Detection of Destructive NFS File Operations
2 TTPsDetection logic identifies ransomware-like activity on NFS shares by flagging high-frequency bursts of successful WRITE, REMOVE, and RENAME operations from a single client within a one-minute window.
Toy Ghouls Deploying Custom GenieLocker Ransomware
1 rule 4 TTPs 1 IOCThe Toy Ghouls threat actor is deploying a custom ransomware family called GenieLocker against manufacturing organizations, utilizing compromised VPN credentials and legitimate system tools for lateral movement and encryption.
Detection of Common Ransomware File Extension Modifications
1 rule 1 TTPThis analytic identifies ransomware activity by detecting file creation or modification events on endpoint filesystems where the resulting file extensions match known ransomware patterns, potentially leading to significant data loss and operational disruption.
Uncommon Process Loading RstrtMgr.DLL for Malicious Purposes
1 rule 2 TTPsAttackers, including ransomware families like Conti and Cactus, and wipers such as BiBi, abuse the legitimate Windows `RstrtMgr.dll` (Restart Manager) by loading it into uncommon processes to terminate applications, including security software and those holding locks on files, facilitating data encryption or destruction.
Detecting Rclone Command-Line Usage for Data Exfiltration
1 rule 1 TTPThis brief details the detection of `rclone.exe` command-line usage with arguments indicative of file transfer to cloud services, a technique frequently leveraged by threat actors for data exfiltration during ransomware and other attacks, which can lead to data breaches and sensitive information loss.
Detection of Common Ransomware Notes
1 rule 1 TTPThis brief details the detection of files commonly associated with ransomware notes on endpoints, indicating active data encryption and potential extortion attempts by various threat actors.
Qilin Ransomware Claims New Victim in Agriculture and Food Production Sector
2 rules 13 TTPs 156 IOCsThe Qilin ransomware group, active since July 2022 and utilizing Golang, has claimed a new victim, Danone (International Delights) in the US Agriculture and Food Production sector, employing double extortion tactics involving data encryption and threatened data release.
Potential Ransomware Note File Dropped via SMB
1 rule 4 TTPsElastic has released a detection rule to identify the creation of ransomware note files by the Windows System process (PID 4) via the SMB protocol, indicating a remote ransomware attack often leveraging lateral movement to perform data encryption, destruction, or inhibit system recovery.
Suspicious File Renaming via SMB Indicating Remote Ransomware Activity
1 rule 4 TTPsThis threat brief details a high-severity detection rule that identifies remote ransomware activity on Windows systems, leveraging SMB to initiate rapid, high-entropy file renames by the System process (PID 4) on user-owned files, which often signifies data encryption for impact.
Sophos State of Ransomware 2026 Report Highlights Evolving Attack Vectors
8 TTPsThe Sophos State of Ransomware 2026 report indicates that while median ransom payments are dropping, successful data encryption by ransomware attackers is climbing, with malicious email, phishing, and compromised credentials now surpassing exploited vulnerabilities as the primary initial access vectors, often leveraging identity-based attacks against critical systems like VPNs and firewalls.
Unusual AWS S3 Object Encryption with SSE-C
1 rule 2 TTPsAdversaries with compromised AWS credentials can exploit Server-Side Encryption with Customer-Provided Keys (SSE-C) in Amazon S3 to encrypt objects, rendering them unreadable and potentially enabling ransomware operations, which detection engineers can identify by monitoring CloudTrail logs for specific `PutObject` or `CopyObject` API calls.
Potential AWS S3 Bucket Ransomware Note Uploaded
1 rule 3 TTPs 2 IOCsAdversaries exploit misconfigured AWS S3 buckets or compromised credentials to upload ransomware notes, often after deleting or encrypting data, aiming to extort victims.
US Sanctions First VPN Service and Administrator for Aiding Ransomware Groups
2 TTPs 2 IOCsThe U.S. Treasury Department sanctioned First VPN Service (1VPNS) and its administrator, Dmytro Rashevskyi, for facilitating ransomware attacks by providing anonymity and evasion capabilities to cybercriminals, and also sanctioned Yegeniy Vladimirovich Silayev for selling 'cryptors' that make malware harder to detect, impacting critical infrastructure.
Plain Text Passwords: A Direct Path to Organizational Compromise
2 rules 4 TTPs 2 IOCsA threat actor, after gaining initial access via a SonicWall VPN vulnerability, exploited plain text Huntress portal recovery codes found on a security engineer's desktop to infiltrate the security platform, enabling defense evasion and furthering malicious activity.
CitrixBleed 2 (CVE-2025-5777) Exploitation Leading to Dragonforce Ransomware
4 rules 9 TTPs 1 CVE 7 IOCsInitial Access Brokers are actively exploiting CitrixBleed 2 (CVE-2025-5777) on NetScaler appliances to steal session tokens, achieve local privilege escalation, establish persistence via legitimate remote access tools, and ultimately deploy Dragonforce ransomware.
GigaWiper: Multi-Payload Destructive Backdoor
3 rules 6 TTPs 2 IOCsGigaWiper is a sophisticated, Golang-based destructive backdoor observed since October 2025 by Microsoft Threat Intelligence, that combines robust command-and-control (C2) capabilities with multiple destructive payloads, including physical disk wiping, ransomware-like encryption derived from Crucio, and multi-pass secure wiping reimplemented from FlockWiper.
Qilin Ransomware Claims New Financial Services Victim
2 rules 20 TTPs 60 IOCsThe Qilin ransomware group, known for its Golang-based ransomware and double extortion tactics, has claimed a new victim in the Financial Services sector, www.tqfinancials.com, as part of its ongoing campaign, highlighting the persistent threat of data encryption and exfiltration.
AWS KMS Imported Key Material Deleted
1 rule 1 TTPAdversaries leverage the `DeleteImportedKeyMaterial` API call against AWS KMS customer managed keys (CMKs) with external material, instantly rendering encrypted data inaccessible with no recovery window, facilitating cloud ransomware or data destruction attacks.
AWS Backup Recovery Point Deletion as Anti-Recovery Tactic
1 rule 1 TTPAdversaries are leveraging the AWS Backup `DeleteRecoveryPoint` API call by non-service principals to remove critical data backups, a high-signal anti-recovery technique observed in ransomware and data-destruction attacks that prevents victims from restoring associated data.
Suspicious Process Creation via WMIC.exe
1 rule 1 TTPA high-severity threat involves adversaries abusing `wmic.exe` to create new processes like `rundll32` or `powershell` on Windows systems, a technique observed in ransomware campaigns such as Ryuk, Hive, and Conti, indicating post-compromise execution.
Computer System Reconnaissance Via Wmic.EXE
1 rule 1 TTPThis brief details the use of `wmic.exe` with the `computersystem` flag for reconnaissance, a technique observed in campaigns by adversaries such as DEV-0270 (Phosphorus), to gather system information like domain, username, and model.
Antivirus - Ransomware Signature Detection
1 rule 1 TTPThis brief describes a critical Sigma rule designed to detect highly relevant Antivirus alerts reporting known ransomware families, enabling detection engineers to ensure immediate investigation even when the malware has been blocked.
Windows Defender Disabled Via SystemSettingsAdminFlows.EXE
1 rule 1 TTPThreat actors are observed abusing the legitimate Windows utility `SystemSettingsAdminFlows.exe` to disable or modify Windows Defender settings, a defense impairment technique utilized in post-exploitation stages of campaigns, including ransomware.
Agentic AI Used to Conduct Ransomware Attack via Langflow
2 rules 10 TTPs 2 CVEsThreat actor JadePuffer exploited CVE-2025-3248 in Langflow instances, leveraging agentic LLM capabilities for advanced reconnaissance, lateral movement, and ultimately encrypting data on production servers with ransomware.
Vect and TeamPCP Partner for Ransomware Campaigns Exploiting Supply Chain Compromises
1 rule 10 TTPs 1 IOCThe threat groups Vect and TeamPCP have formally partnered since March 2026 to conduct widespread ransomware deployment and extortion campaigns by leveraging TeamPCP's credential harvesting and data theft capabilities, often initiated through supply chain compromises involving poisoned software updates and exploitation of critical vulnerabilities like CVE-2025-55182, leading to significant data exfiltration and encrypted systems across multiple sectors.
Qilin Ransomware Claims New Victim in French Public Sector
3 rules 14 TTPs 16 IOCsThe Qilin ransomware group has claimed a new victim, Commune d'Eyguires (www.eyguieres.org), a public sector entity in France, employing their Golang-based ransomware and double extortion tactics, leading to data encryption and potential public release of exfiltrated information.
ShinyHunters Ransomware Group Claims icsecurity.com Victim, Exfiltrates 2.7M Records
2 rules 7 TTPs 2 CVEs 13 IOCsThe financially motivated ShinyHunters ransomware group, operating its shinysp1d3r RaaS, has claimed icsecurity.com as a new victim, compromising over 2.7 million records via credential stuffing and exploitation of cloud services like Snowflake, with the intent to extort through data leakage.
The Gentlemen Ransomware: Self-Propagating Go Encryptor
2 rules 4 TTPsThe Gentlemen ransomware, operated by Storm-2697 as a RaaS, employs a combination of strong per-file encryption with aggressive self-propagation to achieve broad network compromise, targeting Windows environments and using double extortion tactics.
2026 FIFA World Cup: Cyber Threats and Attack Surface Analysis
2 rules 3 TTPsThe 2026 FIFA World Cup faces significant cyber threats from ransomware groups, state-aligned entities like Iran-nexus Handala Hack Team and Russia-nexus NoName057(16), and financially motivated cybercriminals, anticipating disruptive intrusions, large-scale criminal fraud, and politically driven DDoS and hack-and-leak operations targeting fans, hospitality services, and tournament infrastructure.
Cyber Extortion Economy Shifting Towards Data Theft
2 rules 4 TTPsCyber extortion is increasingly relying on data theft rather than ransomware encryption, with threat actors like Bling Libra and TGR-CRI-1135 leveraging techniques like vishing and software supply chain compromise, fueled by regulatory compliance pressures and the impending weaponization of frontier AI models.
Microsoft Takedown of SignSpaceCloud and Secure Messaging Concerns
2 rules 1 TTP 1 IOCMicrosoft disrupted SignSpaceCloud, a Russian cybercrime service providing code signing certificates to malware and ransomware operators, while European governments are shifting from Signal and WhatsApp due to phishing and data sovereignty risks, and the Fast16 malware targeted Iran's nuclear program.
Ransomware-as-a-Service (RaaS) Ecosystem: Affiliate Tradecraft and Initial Access Vectors
2 rules 1 TTPRansomware-as-a-service (RaaS) attacks leverage affiliates for initial access, persistence, and exfiltration, using varied techniques like compromised RDP, vulnerable VPNs, and rogue RMM tools, impacting multiple organizations in a single campaign.
Fox Tempest Malware-Signing-as-a-Service Disrupted by Microsoft
2 rules 2 TTPsMicrosoft disrupted Fox Tempest, a threat actor running a malware-signing-as-a-service (MSaaS) that abuses Microsoft Artifact Signing to generate short-lived code-signing certificates used to sign malware disguised as legitimate software, delivering ransomware and various information stealers to victims across multiple sectors.
WantToCry Ransomware Exploits SMB for Remote Encryption
2 rules 2 TTPsThe WantToCry ransomware exploits exposed SMB services via brute-force for initial access, then exfiltrates files for remote encryption, rewriting the encrypted files to the original locations, demanding ransom payments from $400 to $1,800.
Q1 2026 Malware Trends: Ransomware and Miners
2 rules 2 TTPs 1 CVEKaspersky's Q1 2026 report highlights trends in malware targeting Windows, macOS, and IoT devices, including the exploitation of CVE-2026-20131 in Cisco Secure FMC firewalls and the rise of new ransomware variants and mining activities.
Volume Shadow Copy Deletion via PowerShell
2 rules 1 TTPDetects the use of PowerShell to delete volume shadow copies, a tactic commonly employed by ransomware and other destructive attacks to hinder data recovery efforts.
Potential Ransomware Note File Dropped via SMB
2 rules 4 TTPsThe rule identifies the creation of files resembling ransomware notes via SMB, potentially indicating a remote ransomware attack on Windows systems.
Suspicious File Renamed via SMB
2 rules 4 TTPsDetection of a suspicious file rename operation following an incoming SMB connection, potentially indicating a remote ransomware attack via the SMB protocol, targeting Windows hosts.
VECT Ransomware Destroys Files Due to Encryption Flaw
2 rules 1 TTPVECT 2.0 ransomware, a RaaS offering, permanently destroys large files due to an encryption flaw, discarding decryption nonces for files above 128 KB, rendering them unrecoverable and effectively acting as a wiper; it uses raw ChaCha20-IETF with no authentication.
Trigona Ransomware Employing Custom Data Exfiltration Tool
2 rules 4 TTPs 1 IOCTrigona ransomware is using a custom data exfiltration tool named 'uploader_client.exe' to steal data from compromised environments, enhancing speed and evasion.
Payouts King Ransomware Abusing QEMU VMs for Defense Evasion
2 rules 8 TTPs 1 CVE 1 IOCThe Payouts King ransomware is leveraging QEMU VMs as a reverse SSH backdoor to execute payloads, store malicious files, and establish covert remote access tunnels, bypassing endpoint security measures.
SaaS Notification Pipeline Phishing and Medusa Ransomware Exploitation
1 rule 1 TTP 1 CVE 2 IOCsThreat actors are weaponizing legitimate SaaS notification pipelines to deliver phishing and spam emails, bypassing traditional email authentication protocols, and Storm-1175 is exploiting CVE-2026-1731 to deploy Medusa ransomware.
Qilin Ransomware EDR Killer Infection Chain
2 rules 3 TTPs 1 IOCQilin ransomware employs a malicious msimg32.dll in a multi-stage infection chain to disable endpoint detection and response (EDR) solutions by evading detection and terminating EDR processes.
M-Trends 2026: Evolving Threat Landscape
3 rules 10 TTPsThe M-Trends 2026 report highlights the increasing sophistication of threat actors, including voice phishing attacks targeting SaaS environments, ransomware groups actively destroying recovery capabilities, and espionage groups exploiting edge devices for persistent access, revealing a shift towards faster hand-offs between initial access brokers and ransomware deployers.
Interlock Ransomware Campaign Targeting Enterprise Firewalls
2 rules 3 TTPsThe Interlock ransomware campaign is targeting enterprise firewalls to encrypt sensitive data and demand ransom payment.
Warlock Group Deploys Web Shells, Tunnels, and Ransomware
2 rules 4 TTPsThe Warlock group utilizes web shells and tunneling to deploy ransomware within compromised environments, impacting victim data confidentiality and availability.
Active Exploitation of Apache ActiveMQ RCE Vulnerability (CVE-2023-46604)
2 rules 2 TTPsCVE-2023-46604 is a remote code execution vulnerability affecting Apache ActiveMQ that is actively exploited in the wild by ransomware operators, allowing remote attackers to execute arbitrary shell commands.
Potential Veeam Credential Access via SQL Commands
2 rules 5 TTPsAttackers can leverage sqlcmd.exe or PowerShell commands like Invoke-Sqlcmd to access Veeam credentials stored in MSSQL databases, potentially targeting backups for destructive operations such as ransomware attacks.
Azure Compute Restore Point Collections Mass Deletion
2 rules 1 TTPA single user deleting multiple Azure Restore Point Collections in a short time period can indicate a ransomware attack or destructive operation, preventing victim recovery by inhibiting system recovery.
Potential AWS S3 Bucket Ransomware Note Upload
3 rules 3 TTPsAn adversary may upload a ransomware note to an AWS S3 bucket by abusing compromised credentials or overly permissive bucket policies, potentially leading to data encryption or exfiltration.
JetBrains TeamCity Relative Path Traversal Vulnerability (CVE-2024-27199)
2 rules 1 TTP 1 CVEA relative path traversal vulnerability in JetBrains TeamCity (CVE-2024-27199) could allow limited administrative actions and has been linked to ransomware attacks.
Detecting Pre-Ransomware Active Directory Reconnaissance
3 rules 2 TTPsAdversaries perform Active Directory reconnaissance using built-in tools like nltest, whoami, and net.exe to map the environment before deploying ransomware.
Pre-Ransomware Active Directory Discovery Burst
3 rules 3 TTPsAttackers perform a burst of Active Directory discovery commands on a Windows host to gather information prior to ransomware deployment.
O365 Security Compliance Alerting for Potential Ransomware Activity
3 rules 3 TTPsThis brief focuses on detecting potential ransomware activity within Microsoft Office 365 environments by monitoring security and compliance alerts, aiding in early identification and mitigation of ransomware threats.
Potential Ransomware Behavior - Note Files Dropped via SMB
2 rules 4 TTPsThis rule detects potential ransomware behavior by identifying the creation of multiple files with the same name over SMB by the SYSTEM account, potentially indicating remote execution of ransomware dropping note files.
Unusual Azure Storage Account Key Access by Privileged User
2 rules 2 TTPsDetects unusual access to Azure Storage Account keys by users with Owner, Contributor, Storage Account Contributor, or User Access Administrator roles, potentially indicating compromised identities as seen in STORM-0501 ransomware campaigns.
PowerShell Share Enumeration via ShareFinder or Native APIs
2 rules 1 TTPDetection of PowerShell scripts employing ShareFinder functions or Windows share enumeration APIs to discover accessible network shares for reconnaissance, lateral movement, or ransomware deployment.
Ransomware Attempting to Disable Windows Recovery via Bcdedit
2 rules 1 TTPThis brief details the detection of ransomware actors using bcdedit.exe to modify boot settings, specifically disabling automatic repair mode to hinder system recovery.
ESXi System Clock Manipulation for Evasion
2 rules 1 TTPAn attacker manipulates the system clock on an ESXi host to potentially evade detection, disrupt logging, or invalidate security controls, as seen in ESXi Post Compromise scenarios and Black Basta ransomware incidents.
VssAdmin Shadow Copy Deletion or Resize
2 rules 1 TTPThe rule identifies the use of vssadmin.exe to delete or resize shadow copies on Windows endpoints, which is a common tactic used in ransomware attacks to prevent system recovery.
Mac Malware Analysis of 2016: KeRanger, Keydnap, and Eleanor
2 rules 1 TTPAnalysis of Mac malware from 2016 including KeRanger ransomware, Keydnap backdoor and credential stealer, and the Eleanor PHP-based backdoor, highlighting their infection vectors and persistence mechanisms.
Detection of Event Log Disabling via WevtUtil
2 rules 1 TTPDetection of the 'wevtutil.exe' command-line utility being used to disable event logs, a common tactic employed by ransomware actors to evade detection and hinder forensic analysis on compromised Windows systems.
Third-party Backup Files Deleted via Unexpected Process
2 rules 2 TTPsThis detection identifies the deletion of backup files by processes outside of the backup suite, specifically targeting Veritas and Veeam backups, which may indicate an attempt to prevent recovery from ransomware.
Windows High File Deletion Frequency Indicative of Ransomware
1 rule 1 TTPThis analytic identifies a high frequency of file deletions by monitoring Sysmon EventCodes 23 and 26 for specific file extensions, which can indicate ransomware activity leading to data loss and operational disruption.
Generic Ransomware Detection on macOS
2 rules 1 TTPThis brief outlines a method for generically detecting ransomware on macOS by monitoring file I/O events and identifying the rapid creation of encrypted files by untrusted processes, as proposed by Objective-See.
ESXi Host Reverse Shell Detection
3 rules 1 TTPThis detection identifies reverse shell string patterns on an ESXi host via syslog, potentially indicating a threat actor attempting to establish remote control over the system, which may lead to further compromise such as ransomware deployment.
Volume Shadow Copy Deletion via WMIC
2 rules 2 TTPsAttackers use Windows Management Instrumentation Command-line (WMIC) to delete volume shadow copies, inhibiting system recovery in ransomware and destructive attacks.
Windows Defender Disabled via Registry Modification
2 rules 1 TTPAn attacker modifies the Windows Registry key 'DisableAntiSpyware' to disable Windows Defender, a technique commonly associated with Ryuk ransomware to evade defenses.
Windows .Key File Creation in Root Directory
2 rules 1 TTPThis search detects the creation of a .key file in the root directory of the system drive, an activity associated with ransomware execution before file encryption.
Unusual AWS S3 Object Encryption with SSE-C
2 rules 3 TTPsCompromised AWS credentials are used to encrypt S3 objects using Server-Side Encryption with Customer-Provided Keys (SSE-C), rendering the objects unreadable without the attacker's key, potentially leading to data loss or extortion.
Suspicious S3 Object Upload with Ransom Keyword
2 rules 2 TTPsDetection of an S3 bucket object being uploaded containing a ransom-related keyword, potentially indicating unauthorized access or malicious activity within an AWS environment.
Suspicious Firewall Modification to Allow Network Discovery
2 rulesDetection of 'netsh' command execution to enable network discovery in the firewall, a technique commonly used by ransomware such as REvil and RedDot to discover and compromise additional machines on the network.
Shadow Copy Deletion via VSSAdmin or WMIC
2 rules 1 TTPAttackers delete shadow copies using vssadmin.exe or wmic.exe to prevent data recovery, often preceding ransomware deployment or data exfiltration.
Raccine Scheduled Task Deletion via Schtasks
2 rulesDetection of adversaries deleting the Raccine Rules Updater scheduled task via `schtasks.exe` to disable the ransomware protection tool, potentially leading to data encryption and loss.
PaperCut NG/MF Improper Authentication Vulnerability (CVE-2023-27351)
2 rules 1 TTP 1 CVECVE-2023-27351 is an improper authentication vulnerability in PaperCut NG/MF that allows remote attackers to bypass authentication via the SecurityRequestFilter class, leading to potential ransomware deployment.
Firewall Modification for File and Printer Sharing
2 rules 1 TTPThis analytic detects the modification of Windows Firewall settings to enable file and printer sharing, a common technique used by ransomware to facilitate lateral movement and broader network encryption.
Excessive Usage of SC Service Utility
2 rules 3 TTPsDetection of anomalous usage of sc.exe, often abused by ransomware and malware to manipulate services for privilege escalation or disabling security measures.
Excessive AWS S3 Object Encryption with SSE-C
2 rules 1 TTPCompromised AWS credentials can be used to encrypt a large number of S3 objects with SSE-C, rendering them unreadable without the attacker's keys, potentially leading to a ransomware-like extortion scenario.
ESXi User Granted Administrator Role
2 rules 2 TTPsA user being granted the Administrator role on an ESXi host is a critical action that can indicate potential malicious behavior, as adversaries may use this to escalate privileges, maintain persistence, or disable security controls.
ESXi Firewall Disabled Detection
2 rulesThis detection identifies when the ESXi firewall is disabled or set to permissive mode, potentially exposing the host to unauthorized access and network-based attacks, often preceding lateral movement, data exfiltration, or malware installation.
ESXi Bulk VM Termination Detection
2 rules 2 TTPsDetection of abrupt virtual machine termination on ESXi hosts, potentially indicating denial-of-service, ransomware staging, or destruction of critical workloads.
Detection of ETW Disabling via Registry Modification
2 rulesAttackers may disable Event Tracing for Windows (ETW) by modifying specific registry keys to evade detection and hinder security monitoring, potentially leading to further system compromise.
BCDEdit Failure Recovery Modification
2 rules 1 TTPDetection of modifications to Windows error recovery boot configurations using bcdedit.exe, a technique commonly used by ransomware to disable system restoration options.
AWS User Performing S3 Encryption with KMS Keys
2 rules 1 TTPA user with KMS keys is performing encryption operations on S3 buckets, potentially masking exfiltration or tampering efforts by encrypting sensitive data to evade detection or preparing it for exfiltration.
AWS KMS Key Creation with Public Encryption Policy
2 rules 1 TTPAn attacker may create AWS KMS keys with a permissive encryption policy, granting `kms:Encrypt` permissions to all principals, potentially leading to unauthorized encryption and data compromise across multiple organizations.
AMSI Disablement via Registry Modification
2 rulesAttackers disable the Antimalware Scan Interface (AMSI) by modifying the Windows registry value 'AmsiEnable' to '0x00000000' to evade detection, commonly employed by ransomware, RATs, and APTs.
AWS S3 Bucket Versioning Disabled
2 rules 1 TTPAn adversary disables AWS S3 bucket versioning, preventing recovery of deleted or modified data as a potential precursor to data exfiltration or ransomware activity.
Wbadmin Backup Catalog Deletion
2 rules 2 TTPsAdversaries may delete Windows backup catalogs using wbadmin.exe to inhibit system recovery, often as part of ransomware or other destructive attacks.