Ido Cohen: Two ransomware groups are showing a sharp increase in activity during 2026. SafePay Q1 2026: 22 victims Q2 2026: 59 victims (+168%) RALord (Nova) Q1 2026: 14 victims Q2 2026: 60 victims (+329%) Both groups have significantly accelerated their operations in recent months, making them two of the fastest-growing ransomware threats to watch. Track ransomware trends and emerging threat groups with DarkFeed.2026-06-26
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Tracking the pulse of ransomware in 2026—these are the groups leading the global attack landscape right now: Qilin – 665 attacks The Gentleman – 453 attacks Akira – 290 attacks DragonForce – 245 attacks INC – 239 attacks Lockbit – 199 attacks Play – 154 attacks CLOP – 127 attacks NightSpire – 115 attacks CoinBase Cartel – 97 attacks Stay ahead of ransomware threats.2026-06-26
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
MalwareHunterTeam: List of names: "CamScanner 19-06-2026 16.49.accdr" "Adv Int Course (Rome).accdr" "Expression of Interest (EOI).accdr" "Security Orientation Course-41.accdr" "001210.accdr" "Proposal for Area Admin Meeting - SLNS Barana.accdr" "UN-System-wide-Strategy-on-SSC-2026-2029.accdr" 2026-06-26
malwrhunterteamcampaignUnknown
Malware samples, IOCs and indicators of compromise distributed by the MalwareHunterTeam research group.
MalwareHunterTeam: A possible interesting, low detected sample that was seen from Italy has @ET_Labs "ET MALWARE Win32/Darkme Trojan Checkin M1" traffic match to that IP address. In case correct, that IP can be related to Evilnum APT... As soon as @smica83 has time, the sample will be uploaded to Bazaar and then anyone can look. cc @marsomx_ @G609309532026-06-26
malwrhunterteammalwareItaly
Malware samples, IOCs and indicators of compromise distributed by the MalwareHunterTeam research group.
Hackmanac: Cyber Alert ‼ USA - 𝗣𝗼𝗹𝘆𝗺𝗮𝗿𝗸𝗲𝘁 Polymarket confirmed a third-party compromise that enabled attackers to inject malicious code into its website, leading to the theft of user funds. The company contained the incident and will refund affected users. Around the same time, researchers reported a phishing campaign targeting Polymarket users that allegedly stole about US$3 million in cryptocurrency.2026-06-26
H4ckmanacphishingUnited StatesT1566
Threat intelligence and cyber alert feed covering data breaches, ransomware incidents and vulnerability disclosures.
Ransomware News: Noticis kiberuzbrukums Latvijas Valsts mežiem; drošības apsvērumu dēļ slēgts LVM GEO, karšu sistēma un "Mednis" [papildināts]2026-06-25
anggipradanareportUnited Kingdom
Noticis kiberuzbrukums Latvijas Valsts mežiem; drošības apsvērumu dēļ slēgts LVM GEO, karšu sistēma un "Mednis" [papildināts] Noticia sobre ransomware publicada en . Extracto Sin e...