❌

Normal view

There are new articles available, click to refresh the page.
Today β€” 15 September 2026GBHackers

Hackers Turn Windows Shadow Copies Into a Tool for Credential Theft and Ransomware

15 September 2026 at 01:51

Threat actors are increasingly weaponizing Microsoft’s Volume Shadow Copy Service (VSS) for two distinct objectives: removing recovery options before ransomware deployment and extracting credential material from protected Windows files. The shift means VSS telemetry should no longer be treated as a simple backup or disk-maintenance event, but as behavior requiring process, identity, and endpoint context. […]

The post Hackers Turn Windows Shadow Copies Into a Tool for Credential Theft and Ransomware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Before yesterdayGBHackers

Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files

11 September 2026 at 03:14

Mantax OTAX is aggressive Android malware family combines ransomware, spyware, credential theft, and remote device-control features in a single infection chain. Linked to Indonesian threat actors, the campaign targets users through sideloaded APKs and turns compromised devices into tools for surveillance, financial fraud and real-time extortion. Unlike conventional Android ransomware that focuses primarily on locking […]

The post Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement

11 September 2026 at 02:17

A new Windows remote-access trojan dubbed SloppyRAT, which appears to be positioned as an intrusion-enablement tool for ransomware operations. First observed in June 2026, the malware is delivered through a multi-stage ClickFix chain and combines host reconnaissance, stealthy command execution, reverse proxying, and resilient command-and-control mechanisms to support post-compromise activity and lateral movement. Rather than […]

The post Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Panzer Ransomware Emerges With Windows, Linux, ESXi and FreeBSD Attack Support

8 September 2026 at 03:28

A newly identified ransomware-as-a-service operation, Panzer, has surfaced with advertised payload support for Windows, Linux, VMware ESXi and FreeBSD, positioning it as a cross-platform threat to enterprise and virtualized environments. The group’s rapid victim posting cadence, affiliate-focused infrastructure, and double-extortion model make it a ransomware operation security teams should begin tracking despite the current absence […]

The post Panzer Ransomware Emerges With Windows, Linux, ESXi and FreeBSD Attack Support appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Ransomware Hackers Can Go From Network Access to Encryption in Less Than 24 Hours

3 September 2026 at 04:11

The Gentlemen ransomware-as-a-service operation can move from confirmed access inside a victim network to encryption in under 24 hours. Demonstrating how rapidly modern affiliates can turn stolen credentials or exposed infrastructure into a full-scale business disruption. Counter Threat Unit researchers tracking the operation as GOLD SHERWOOD found that the Gentlemen affiliates follow a repeatable post-compromise […]

The post Ransomware Hackers Can Go From Network Access to Encryption in Less Than 24 Hours appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

The Gentlemen Ransomware Hackers Use TukTuk C2 to Steal Credentials and Disable EDR Security

2 September 2026 at 07:25

The Gentlemen ransomware operation has been linked to a previously undocumented, cross-platform command-and-control framework namedΒ TukTuk, alongside EDR-disabling tooling, DLL sideloading research, and datasets apparently stolen from technology and healthcare organizations. Analysis of a Finland-hosted server identified what researchers assess as the complete TukTuk development project, providing an unusually detailed view into the group’s post-compromise capabilities. […]

The post The Gentlemen Ransomware Hackers Use TukTuk C2 to Steal Credentials and Disable EDR Security appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌
❌