Quantcast
Channel: Ransomware | Latest Threats | Microsoft Security Blog
Browsing latest articles
Browse All 349 View Live

Image may be NSFW.
Clik here to view.

Storm-0501’s evolving techniques lead to cloud-based ransomware

Microsoft Threat Intelligence has observed financially motivated threat actor Storm-0501 continuously evolving their campaigns to achieve sharpened focus on cloud-based tactics, techniques, and...

View Article


Investigating active exploitation of CVE-2025-10035 GoAnywhere Managed File...

In this article Vulnerability analysis Exploitation activity by Storm-1175Mitigation and protection guidanceMicrosoft Defender XDR detectionsIndicators of compromise On September 18, 2025, Fortra...

View Article


Image may be NSFW.
Clik here to view.

Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa...

In this article Storm-1175’s rapid attack chain: From initial access to impactMitigation and protection guidanceMicrosoft Defender detectionsIndicators of compromise The financially motivated...

View Article

Image may be NSFW.
Clik here to view.

Exposing Fox Tempest: A malware-signing service operation

In this article Fox Tempest’s role and impactFox Tempest’s malware signing as a service infrastructureDefending against Fox Tempest-enabled attacksMicrosoft Defender detectionsIndicators of compromise...

View Article

Image may be NSFW.
Clik here to view.

Storm-0501: Ransomware attacks expanding to hybrid cloud environments

August 27, 2025 update: Storm-0501 has continuously evolved to achieve sharpened focus on cloud-based TTPs as their primary objective shifted from deploying on-premises endpoint ransomware to using...

View Article


Image may be NSFW.
Clik here to view.

​​Cyber Signals Issue 8 | Education under siege: How cybercriminals target...

Introduction | Security snapshot | Threat briefingDefending against attacks | Expert profile  Education is essentially an “industry of industries,” with K-12 and higher education enterprises handling...

View Article

Exploitation of CLFS zero-day leads to ransomware activity

Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC) have discovered post-compromise exploitation of a zero-day elevation of privilege vulnerability in the...

View Article

Image may be NSFW.
Clik here to view.

Unveiling RIFT: Enhancing Rust malware analysis through pattern matching

Today, Microsoft Threat Intelligence Center is excited to announce the release of RIFT, a tool designed to assist malware analysts automate the identification of attacker-written code within Rust...

View Article


Image may be NSFW.
Clik here to view.

The Gentlemen ransomware: Dissecting a self-propagating Go encryptor

In this article Pre-encryptionFile encryptionPost-encryptionDefending against The Gentlemen ransomwareMicrosoft Defender detections and hunting guidanceIndicators of compromise Ransomware that...

View Article


Image may be NSFW.
Clik here to view.

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized...

In this article Pre-encryptionEncryptionPost-encryptionDefending against DeadLock ransomwareIndicators of compromise Microsoft Threat Intelligence tracks DeadLock ransomware as an emerging financially...

View Article
Browsing latest articles
Browse All 349 View Live


Latest Images