New post from #Lamashtu : Shanpoornam Metals
More at : https://www.ransomlook.io/group/Lamashtu #Ransomware
Lamashtu Β· RansomLook

Open ransomware intelligence β€” groups, markets, actors, crypto, stats.

🚨 nuova rivendicazione #ransomware Italia 🚨 πŸ΄β€β˜ οΈ gruppo #TheGentlemen 🧬 Fonderia CorrΓ  S.P.A. | Thiene (VI) 🎯 settore: industria metallurgica πŸ”— fonderiacorra.com πŸ—“οΈ 29 maggio 2026 πŸ“„ sample: - β–ͺ️ dati esfiltrati dichiarati: - β–ͺ️ dati esfiltrati pubblicati: - ⏲️ scadenza: 07 giugno 2026 #ransomNews
🚨 nuova rivendicazione #ransomware Italia 🚨 πŸ΄β€β˜ οΈ gruppo #Nova 🧬 Bencini Giulio Casa Safer | Firenze 🎯 settore: turismo e accoglienza πŸ”— casasafer.it πŸ—“οΈ 28 maggio 2026 πŸ“„ sample: - β–ͺ️ dati esfiltrati dichiarati: - β–ͺ️ dati esfiltrati pubblicati: - ⏲️ scadenza: 10 giugno 2026 #ransomNews #cyberthreats
🚨 nuova rivendicazione #ransomware Italia 🚨 πŸ΄β€β˜ οΈ gruppo #DragonForce 🧬 Pieralisi MAIP S.P.A. | Jesi (AN) 🎯 settore: industria meccanica πŸ”— pieralisi.com πŸ—“οΈ 27 maggio 2026 πŸ“„ sample: - β–ͺ️ dati esfiltrati dichiarati: 1.31GB β–ͺ️ dati esfiltrati pubblicati: -- ⏲️ scadenza: 06 giugno 2026 #ransomNews
[AILOCK] - Ransomware Victim: Restorative Therapies, Inc[.] - RedPacket Security

NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating

RedPacket Security

The Gentlemen ransomware: Dissecting a self-propagating Go encryptor

The Gentlemen is a ransomware-as-a-service operation tracked as Storm-2697, distinguished by combining robust per-file encryption using Curve25519 with XChaCha20 stream cipher alongside aggressive self-propagation capabilities designed for broad network compromise. Emerging in mid-2025 and transitioning to RaaS by September 2025, the operation recently partnered with BreachForums to recruit affiliates including penetration testers and initial access brokers. Written in Go and obfuscated with Garble, the ransomware employs double extortion tactics, encrypting data while exfiltrating sensitive information. It utilizes 21 distinct lateral movement techniques per target host, including PsExec, WMI, scheduled tasks, services, and PowerShell remoting. The malware disables defenses, deletes shadow copies and forensic artifacts, and can optionally wipe free disk space to prevent recovery, impacting organizations globally across education, transportation, healthcare, and finance sectors.

Pulse ID: 6a189defc88ad66cd0a9d87d
Pulse Link: https://otx.alienvault.com/pulse/6a189defc88ad66cd0a9d87d
Pulse Author: AlienVault
Created: 2026-05-28 19:56:31

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#ChaCha20 #CyberSecurity #ELF #Education #Encryption #Extortion #Healthcare #ICS #InfoSec #Malware #OTX #OpenThreatExchange #PowerShell #PsExec #RAT #RaaS #RansomWare #RansomwareAsAService #bot #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange

🚨New ransom group blog post!🚨

Group name: AiLock
Post title: Restorative Therapies, Inc.
Info: https://cti.fyi/groups/AiLock.html

#ransomware #cti #threatintelligence #cybersecurity #infosec

The Gentlemen ransomware: Dissecting a self-propagating Go encryptor - RedPacket Security

Ransomware that combines robust encryption with rapid lateral movement significantly increases the risk and impact of an attack. The Gentlemen ransomware is a

RedPacket Security
New post from #Ailock : Restorative Therapies, Inc.
More at : https://www.ransomlook.io/group/Ailock #Ransomware
Ailock Β· RansomLook

Open ransomware intelligence β€” groups, markets, actors, crypto, stats.

Shinyhunters Β· RansomLook

Open ransomware intelligence β€” groups, markets, actors, crypto, stats.