Latest updates for Ransomware

Fresh curated links around Ransomware are collected here so marketers can spot useful updates and turn timely ideas into posts faster.

Recent items include:

  • DeadLock Ransomware Stores C2 Configuration on Polygon Blockchain to Resist Takedowns
  • Rogue ransomware affiliate poses as data recovery firm to steal payments
  • Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

Post angles to try

Share the most useful takeaway for your audience.
Turn one article into a quick practical checklist.
Ask your audience how this shift affects their work.
Turn angles into scheduled posts

Fresh articles and ideas

Recent curated links from global sources. Generate one free draft from any story, then use SocialBu to schedule and refine your content calendar.

cybersecuritynews.com /4 weeks ago

DeadLock Ransomware Stores C2 Configuration on Polygon Blockchain to Resist Takedowns

DeadLock ransomware has emerged as a financially motivated threat that locks files while threatening to publish stolen information. First observed in July 2025, it had listed more...

Read source
bleepingcomputer.com /2 weeks ago

Rogue ransomware affiliate poses as data recovery firm to steal payments

A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able...

Read source
thehackernews.com /3 weeks ago

Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' se...

Read source
bleepingcomputer.com /2 weeks ago

Rogue ransomware affiliate poses as recovery firm to steal payments

A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able...

Read source
thehackernews.com /4 weeks ago

DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt

The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operati...

Read source
arstechnica.com /1 month ago

Pay up or not? Ransomware surge has victims facing tough choices.

Governments look at banning ransom payments in face of increasingly sophisticated threats.

Read source
thehackernews.com /4 weeks ago

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The...

Read source
insurancebusinessmag.com /3 weeks ago

Ransomware groups have stopped locking your clients’ files. Now they just steal them

The old "restore from backup and move on" playbook doesn't work like it used to

Read source
bleepingcomputer.com /4 weeks ago

DeadLock ransomware uses blockchain to resist infrastructure takedown

The DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims and data-leak activity...

Read source
venturebeat.com /1 month ago

New ransomware targets AI model weights and can't even collect the ransom

The same attacker broke into the same internet-facing Langflow server twice, and the second time brought ransomware built to destroy trained AI models. Sysdig's Threat Research Tea...

Read source
cybersecuritynews.com /4 weeks ago

Eclipse Ransomware Launches RaaS Platform Targeting Windows, Linux, and ESXi Infrastructure

A threat actor operating under the handle EclipseSupport is actively promoting a new Ransomware-as-a-Service (RaaS) operation named Eclipse Ransomware on cybercrime forums. The gro...

Read source
theregister.com /2 weeks ago

Ransomware crook poses as recovery firm to steal payments from fellow extortionists

Because apparently even ransomware gangs can't trust the people they do business with

Read source
gbhackers.com /1 month ago

New GenieLocker Ransomware Encrypts Windows, Linux and VMware ESXi Systems

GenieLocker is a custom ransomware family linked to the Toy Ghouls group (also known as Bearlyfy or Labubu). It can encrypt systems running Windows, Linux, and VMware ESXi, with a...

Read source
bleepingcomputer.com /1 month ago

Clop ransomware targets Windchill, FlexPLM in data theft attacks

The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. [...]

Read source
bleepingcomputer.com /4 weeks ago

New StormEncryptor ransomware used by former Medusa affiliate

A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. [...]

Read source
cybersecuritynews.com /4 weeks ago

Ransomware Operators Disable EDR, Backup Software and Windows Telemetry Before Encryption

Ransomware crews are increasingly trying to blind a victim before they encrypt anything. Analysis shows that attackers can disable endpoint detection and response tools, interrupt...

Read source
gbhackers.com /4 days ago

New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption

Panzer ransomware has emerged as a new Ransomware-as-a-Service (RaaS) operation, publishing 16 alleged victims across 11 countries while combining data theft with file encryption....

Read source
theregister.com /1 month ago

Greedy ransomware crews return for seconds after victims cough up first extortion payments

Some never saw their files again either, infosec biz Proofpoint finds

Read source
cybersecuritynews.com /1 month ago

Qilin Ransomware Claims 1,358 Victims as Global Attacks Reach New Record

Qilin ransomware has grown from a fast-moving criminal operation into one of the most visible threats in the global extortion landscape. The group encrypts systems and steals data,...

Read source
infosecurity-magazine.com /1 month ago

JadePuffer Returns With Ransomware Designed to Wipe AI Models

JadePuffer follow-up campaign deployed ENCFORGE locker built to destroy AI model artifacts

Read source
prweb.com /1 month ago

ThreatBreaker Brings Automated Forensics to the Endpoint - Starting With Ransomware

New anti-ransomware capability kills the encryptor, isolates the machine and seals the evidence on its own – offline, air-gapped, and without shutting anything down. LAS VEGAS, Jul...

Read source
koreatimes.co.kr /4 weeks ago

Korea, US issue joint advisory on 'Gunra' ransomware attacks

Police on Tuesday called on domestic companies and institutions to strengthen their security against a ransomware variant named "Gunra," as they jointly released details of its lat...

Read source
theregister.com /4 weeks ago

Akira ransomware scum blocked victim's security tools – and broke their own encryptor

Gives a whole new meaning to Safe Mode

Read source
fastcompany.com /1 month ago

Ransomware attacks rose 20% in the first half of 2026

Hackers leaned further into ransomware in the second quarter of 2026, with a surge of new attacks led by two competing ransomware-as-a-service groups. A new report  from NordSte...

Read source

Turn fresh research into a full content calendar

Use SocialBu to discover ideas, generate post drafts, and schedule them across your social channels.

Sources covering Ransomware

feeds.arstechnica.com

Recent coverage from public sources
Public source

feeds.feedburner.com

Recent coverage from public sources
Public source

cybersecuritynews.com

Recent coverage from public sources
Public source

feeds.feedburner.com

Recent coverage from public sources
Public source

gbhackers.com

Recent coverage from public sources
Public source

bleepingcomputer.com

Recent coverage from public sources
Public source