The DragonForce ransomware attack is exploiting weak points in Managed Service Providers (MSPs) by abusing SimpleHelp, a remote access tool. The attackers launched a supply chain attack by leveraging publicly accessible and unsecured SimpleHelp instances, enabling lateral movement across client networks. Researchers warn this marks a significant evolution in attacker strategy—shifting from direct infiltration to […]
A new kind of Hyper-V ransomware attack is raising alarms across the cybersecurity landscape. RedCurl, a corporate cyber-espionage group known for stealthy attacks since 2018, has pivoted to deploying custom ransomware called QWCrypt. Unlike common ransomware campaigns focused solely on ransom payments, RedCurl’s approach fuses espionage and extortion—targeting Hyper-V environments that form the backbone of […]
Medusa ransomware has emerged as one of the most disruptive cyber threats, infiltrating over 300 critical infrastructure organizations across various industries. First detected in June 2021, Medusa has quickly gained notoriety due to its double extortion tactics—encrypting data and threatening to leak it unless a ransom is paid. Recent statistics highlight the escalating threat posed […]