Quantcast
Channel: Ransomware | Latest Threats | Microsoft Security Blog
Browsing index pages (389 articles)

Image may be NSFW.
Clik here to view.

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized...

In this article Pre-encryptionEncryptionPost-encryptionDefending against DeadLock ransomwareIndicators of compromise Microsoft Threat Intelligence tracks DeadLock ransomware as an emerging financially...

View Article


Image may be NSFW.
Clik here to view.

The Gentlemen ransomware: Dissecting a self-propagating Go encryptor

In this article Pre-encryptionFile encryptionPost-encryptionDefending against The Gentlemen ransomwareMicrosoft Defender detections and hunting guidanceIndicators of compromise Ransomware that...

View Article


Exploitation of CLFS zero-day leads to ransomware activity

Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC) have discovered post-compromise exploitation of a zero-day elevation of privilege vulnerability in the...

View Article

Image may be NSFW.
Clik here to view.

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized...

In this article Pre-encryptionEncryptionPost-encryptionDefending against DeadLock ransomwareIndicators of compromise Microsoft Threat Intelligence tracks DeadLock ransomware as an emerging financially...

View Article

Image may be NSFW.
Clik here to view.

The Gentlemen ransomware: Dissecting a self-propagating Go encryptor

In this article Pre-encryptionFile encryptionPost-encryptionDefending against The Gentlemen ransomwareMicrosoft Defender detections and hunting guidanceIndicators of compromise Ransomware that...

View Article


Image may be NSFW.
Clik here to view.

Unveiling RIFT: Enhancing Rust malware analysis through pattern matching

Today, Microsoft Threat Intelligence Center is excited to announce the release of RIFT, a tool designed to assist malware analysts automate the identification of attacker-written code within Rust...

View Article

Exploitation of CLFS zero-day leads to ransomware activity

Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC) have discovered post-compromise exploitation of a zero-day elevation of privilege vulnerability in the...

View Article

Image may be NSFW.
Clik here to view.

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized...

In this article Pre-encryptionEncryptionPost-encryptionDefending against DeadLock ransomwareIndicators of compromise Microsoft Threat Intelligence tracks DeadLock ransomware as an emerging financially...

View Article


Image may be NSFW.
Clik here to view.

The Gentlemen ransomware: Dissecting a self-propagating Go encryptor

In this article Pre-encryptionFile encryptionPost-encryptionDefending against The Gentlemen ransomwareMicrosoft Defender detections and hunting guidanceIndicators of compromise Ransomware that...

View Article


Image may be NSFW.
Clik here to view.

Unveiling RIFT: Enhancing Rust malware analysis through pattern matching

Today, Microsoft Threat Intelligence Center is excited to announce the release of RIFT, a tool designed to assist malware analysts automate the identification of attacker-written code within Rust...

View Article

Image may be NSFW.
Clik here to view.

Storm-0501: Ransomware attacks expanding to hybrid cloud environments

August 27, 2025 update: Storm-0501 has continuously evolved to achieve sharpened focus on cloud-based TTPs as their primary objective shifted from deploying on-premises endpoint ransomware to using...

View Article

Image may be NSFW.
Clik here to view.

Unveiling RIFT: Enhancing Rust malware analysis through pattern matching

Today, Microsoft Threat Intelligence Center is excited to announce the release of RIFT, a tool designed to assist malware analysts automate the identification of attacker-written code within Rust...

View Article

Exploitation of CLFS zero-day leads to ransomware activity

Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC) have discovered post-compromise exploitation of a zero-day elevation of privilege vulnerability in the...

View Article


Image may be NSFW.
Clik here to view.

​​Cyber Signals Issue 8 | Education under siege: How cybercriminals target...

Introduction | Security snapshot | Threat briefingDefending against attacks | Expert profile  Education is essentially an “industry of industries,” with K-12 and higher education enterprises handling...

View Article

Image may be NSFW.
Clik here to view.

Storm-0501: Ransomware attacks expanding to hybrid cloud environments

August 27, 2025 update: Storm-0501 has continuously evolved to achieve sharpened focus on cloud-based TTPs as their primary objective shifted from deploying on-premises endpoint ransomware to using...

View Article


Image may be NSFW.
Clik here to view.

The Gentlemen ransomware: Dissecting a self-propagating Go encryptor

In this article Pre-encryptionFile encryptionPost-encryptionDefending against The Gentlemen ransomwareMicrosoft Defender detections and hunting guidanceIndicators of compromise Ransomware that...

View Article

Exploitation of CLFS zero-day leads to ransomware activity

Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC) have discovered post-compromise exploitation of a zero-day elevation of privilege vulnerability in the...

View Article


Image may be NSFW.
Clik here to view.

Storm-0501: Ransomware attacks expanding to hybrid cloud environments

August 27, 2025 update: Storm-0501 has continuously evolved to achieve sharpened focus on cloud-based TTPs as their primary objective shifted from deploying on-premises endpoint ransomware to using...

View Article

Image may be NSFW.
Clik here to view.

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized...

In this article Pre-encryptionEncryptionPost-encryptionDefending against DeadLock ransomwareIndicators of compromise Microsoft Threat Intelligence tracks DeadLock ransomware as an emerging financially...

View Article

Image may be NSFW.
Clik here to view.

Storm-0501: Ransomware attacks expanding to hybrid cloud environments

August 27, 2025 update: Storm-0501 has continuously evolved to achieve sharpened focus on cloud-based TTPs as their primary objective shifted from deploying on-premises endpoint ransomware to using...

View Article
Browsing index pages (389 articles)


Latest Images