❌

Reading view

There are new articles available, click to refresh the page.

Hackers Turn Windows Shadow Copies Into a Tool for Credential Theft and Ransomware

Threat actors are increasingly weaponizing Microsoft’s Volume Shadow Copy Service (VSS) for two distinct objectives: removing recovery options before ransomware deployment and extracting credential material from protected Windows files. The shift means VSS telemetry should no longer be treated as a simple backup or disk-maintenance event, but as behavior requiring process, identity, and endpoint context. […]

The post Hackers Turn Windows Shadow Copies Into a Tool for Credential Theft and Ransomware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files

Mantax OTAX is aggressive Android malware family combines ransomware, spyware, credential theft, and remote device-control features in a single infection chain. Linked to Indonesian threat actors, the campaign targets users through sideloaded APKs and turns compromised devices into tools for surveillance, financial fraud and real-time extortion. Unlike conventional Android ransomware that focuses primarily on locking […]

The post Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement

A new Windows remote-access trojan dubbed SloppyRAT, which appears to be positioned as an intrusion-enablement tool for ransomware operations. First observed in June 2026, the malware is delivered through a multi-stage ClickFix chain and combines host reconnaissance, stealthy command execution, reverse proxying, and resilient command-and-control mechanisms to support post-compromise activity and lateral movement. Rather than […]

The post Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Panzer Ransomware Emerges With Windows, Linux, ESXi and FreeBSD Attack Support

A newly identified ransomware-as-a-service operation, Panzer, has surfaced with advertised payload support for Windows, Linux, VMware ESXi and FreeBSD, positioning it as a cross-platform threat to enterprise and virtualized environments. The group’s rapid victim posting cadence, affiliate-focused infrastructure, and double-extortion model make it a ransomware operation security teams should begin tracking despite the current absence […]

The post Panzer Ransomware Emerges With Windows, Linux, ESXi and FreeBSD Attack Support appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Ransomware Hackers Can Go From Network Access to Encryption in Less Than 24 Hours

The Gentlemen ransomware-as-a-service operation can move from confirmed access inside a victim network to encryption in under 24 hours. Demonstrating how rapidly modern affiliates can turn stolen credentials or exposed infrastructure into a full-scale business disruption. Counter Threat Unit researchers tracking the operation as GOLD SHERWOOD found that the Gentlemen affiliates follow a repeatable post-compromise […]

The post Ransomware Hackers Can Go From Network Access to Encryption in Less Than 24 Hours appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

The Gentlemen Ransomware Hackers Use TukTuk C2 to Steal Credentials and Disable EDR Security

The Gentlemen ransomware operation has been linked to a previously undocumented, cross-platform command-and-control framework namedΒ TukTuk, alongside EDR-disabling tooling, DLL sideloading research, and datasets apparently stolen from technology and healthcare organizations. Analysis of a Finland-hosted server identified what researchers assess as the complete TukTuk development project, providing an unusually detailed view into the group’s post-compromise capabilities. […]

The post The Gentlemen Ransomware Hackers Use TukTuk C2 to Steal Credentials and Disable EDR Security appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌