LIVE
LATEST THREAT: China-Nexus Actor Exploits Critical VMware vCenter Flaw to Deploy Babuk-Derived Ransomware THREAT ALERT ACTIVE
Threat Intelligence Feed — Active Monitoring

RANSOMWARE
THREAT INTELLIGENCE
GROUPS // CAMPAIGNS // TTPs // VICTIMS

Track active ransomware groups, ongoing campaigns, and emerging tactics. Timely intelligence to help defenders stay ahead of threat actors.

View All Intelligence RSS Feed
$2.1B+ 2025 Ransom Payments
480+ RansomHub Victims
$1.2M Median Settlement
11 days Median Dwell Time
Group Profile RansomHub Aug 9, 2026

RansomHub: The Most Active RaaS Operation of 2025-2026

RansomHub emerged in February 2024 and rapidly became the highest-volume ransomware operation following LockBit's February 2025 disruption. This profile covers the group's affiliate model, technical tooling, victim statistics, and the specific sectors and countries under sustained targeting.

Access Report →
Threat Level
8/10
Sectors Targeted
— healthcare— critical-infrastructure— finance— manufacturing
All Reports →
Campaign Alert Babuk-derived (.babyk) Aug 24, 2026

China-Nexus Actor Exploits Critical VMware vCenter Flaw to Deploy Babuk-Derived Ransomware

A suspected China-nexus threat actor weaponized CVE-2026-59310, a critical vCenter directory-traversal flaw, within five days of patch release, compromising 361 IPs across 47 countries and deploying Babuk-derived ransomware on ESXi hosts.

9
Intel Report Aug 23, 2026

'Ransom Busters': A Rogue Affiliate Is Re-Extorting Its Own Gangs' Victims

A threat actor calling itself Ransom Busters LTD is contacting ransomware victims before their breaches go public, posing as a recovery firm. GuidePoint Security assesses it is actually a rogue affiliate double-dipping on victims of DragonForce, Settra, and Anubis.

6
Group Profile Panzer Aug 22, 2026

Panzer: New RaaS Operation Rapidly Expands Global Victim List

Panzer, a newly emerged ransomware-as-a-service operation, has posted victims across Europe, Asia, and Africa within weeks of its leak site going live, including an Italian engineering firm listed August 21, 2026. The group is actively recruiting affiliates with an 80/20 revenue split and a cross-platform locker.

8
Group Profile Titan Aug 21, 2026

Titan Ransomware: A New RaaS Group Behind a Nine-Victim, Single-Day Strike on Italian Firms

Titan, a RaaS operation first seen in April 2026, has claimed 24 victims to date — including nine Italian manufacturing and professional-services firms posted to its leak site in a single day on August 20, 2026. Here's what's known about the group's origins, TTPs, and targeting shift.

8
Intel Report Qilin Aug 20, 2026

Qilin's 443% Surge: Inside the RaaS Operation Now Leading the 2026 Ransomware Market

Qilin has gone from a mid-tier RaaS operation to the single largest source of disclosed ransomware victims in 2026, with claimed attacks up 443% year-over-year. This report examines the volume data, the affiliate economics driving the surge, the firewall and VPN exploitation behind initial access, and the group's unusual pull toward state-linked operators.

6