Wednesday , 10 September 2025

Tag Archives: ransomware

Office of Public Affairs | “LockerGoga,” “MegaCortex,” and “Nefilim” Ransomware Administrator Charged with Ransomware Attacks

Office of Public Affairs | “LockerGoga,” “MegaCortex,” and “Nefilim” Ransomware Administrator Charged with Ransomware Attacks

Earlier today, the U.S. District Court for the Eastern District of New York unsealed a superseding indictment charging Volodymyr Viktorovich Tymoshchuk — also known as deadforz, Boba, msfv, and farnetwork — a Ukrainian national, with serving as an administrator in the LockerGoga, MegaCortex, and Nefilim ransomware schemes. “Volodymyr Tymoshchuk is charged for his role in ransomware schemes that extorted more …

Read More »

Federal, state officials investigating ransomware attack targeting Nevada

Federal, state officials investigating ransomware attack targeting Nevada

Federal and state authorities are investigating a ransomware attack that has disrupted key services across the state of Nevada. The Sunday attack interrupted multiple government services, including phone systems and state agency websites.  The attackers were able to steal data during the intrusion, but officials still don’t know what they took, Tim Galluzi, Nevada chief information officer and executive director …

Read More »

Nevada targeted in ransomware attack; some data taken out of state, officials say

Nevada targeted in ransomware attack; some data taken out of state, officials say

A massive ransomware cyberattack that has crippled Nevada’s state government since Sunday has resulted in some data being moved outside of the network by “malicious actors,” state officials said Wednesday. State agency officials would not disclose the nature of the data that was taken outside the state network during the press conference in Carson City, and stressed that it is …

Read More »

The Era of AI-Generated Ransomware Has Arrived

The Era of AI-Generated Ransomware Has Arrived

While such activity so far does not appear to be the norm across the ransomware ecosystem, the findings represent a stark warning. “There are definitely some groups that are using AI to aid with the development of ransomware and malware modules, but as far as Recorded Future can tell, most aren’t,” says Allan Liska, an analyst for the security firm …

Read More »

Someone Created First AI-Powered Ransomware Using OpenAI's gpt-oss:20b Model – The Hacker News

Someone Created First AI-Powered Ransomware Using OpenAI’s gpt-oss:20b Model  The Hacker News Researchers flag code that uses AI systems to carry out ransomware attacks  CyberScoop First known AI-powered ransomware uncovered by ESET Research  WeLiveSecurity The first AI-powered ransomware has been discovered — “PromptLock” uses local AI to foil heuristic detection and evade API tracking  Tom’s Hardware Oh goody, the ‘first known AI-powered ransomware’ has …

Read More »

First AI Ransomware ‘PromptLock’ Uses OpenAI gpt-oss-20b Model for Encryption

First AI Ransomware ‘PromptLock’ Uses OpenAI gpt-oss-20b Model for Encryption

A new ransomware has been identified, which is believed to be the first-ever ransomware strain that leverages a local AI model to generate its malicious components. Dubbed “PromptLock” by the ESET Research team that discovered it, the malware uses OpenAI’s gpt-oss:20b model via the Ollama API to create custom, cross-platform Lua scripts for its attack chain. #ESETResearch has discovered the …

Read More »

First AI-powered ransomware PoC spotted • The Register

First AI-powered ransomware PoC spotted • The Register

ESET malware researchers Anton Cherepanov and Peter Strycek have discovered what they describe as the “first known AI-powered ransomware,” which they named PromptLock.  The good news, according to the duo, who detailed PromptLock in a series of social media posts and screenshots on Tuesday, is that the malware doesn’t appear to be fully functional — yet. “Although multiple indicators suggest the …

Read More »

Scattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. Infrastructure – The Hacker News

Scattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. Infrastructure  The Hacker News Scattered Spider is running a VMware ESXi hacking spree  BleepingComputer UNC3944 Attacking VMware vSphere and Enabling SSH on ESXi Hosts to Reset ‘root’ Passwords  CyberSecurityNews Cybercrime trendsetter Scattered Spider rarely needs to hack  Techzine Global Scattered Spider Targeting VMware vSphere Environments  SecurityWeek Source link

Read More »

Microsoft cyberattack expands: Ransomware deployed, South African Treasury hit (MSFT:NASDAQ) – Seeking Alpha

Microsoft cyberattack expands: Ransomware deployed, South African Treasury hit (MSFT:NASDAQ)  Seeking Alpha Microsoft says some SharePoint server hackers now using ransomware  Reuters Disrupting active exploitation of on-premises SharePoint vulnerabilities  Microsoft Microsoft Hack Hits Hundreds of Firms, Agencies as Damage Spreads  Yahoo Finance ToolShell: An all-you-can-eat buffet for threat actors  WeLiveSecurity Source link

Read More »