Attackers Abuse VSS to Steal Active Directory Credentials and Block Recovery
Endpoint antivirus blocks attempted shadow-copy deletion
What ransomware crews are doing right now — the groups picking up momentum, the breaches they're posting, and the stories tracking their operations. Aggregated from vendor reports, leak sites, researcher analysis, and underground chatter.
Actors ranked by Mallory's mention-velocity model across sources.
The Gentlemen is a financially motivated ransomware-as-a-service operation, also tracked as Storm-2697 and Gentlemen. Active since approximately mid-2025, it has become a prolific extortion operation with hundreds of alleged victims internationally. The group uses a double-extortion model, combining data theft and ransomware encryption with publication threats through a leak site; its operations rely on affiliates. Reported affiliate tradecraft includes initial access through compromised credentials, use of legitimate administrative and remote-access tools, rapid privilege escalation, and aggressive defense evasion. Affiliates have reportedly progressed from initial compromise to ransomware deployment in under 24 hours. Documented affiliate activity includes network and database discovery, staging data for exfiltration, modifying VPN, firewall, and directory-service configurations, recovering service-account credentials, and creating concealed backdoor accounts. An affiliate also used a commercial AI coding assistant interactively during intrusions, including against an Australian energy utility and U.S. manufacturing organizations. The Gentlemen has targeted organizations across healthcare, manufacturing, information technology, financial services, food production, public-sector housing, education, and energy. Victim claims should be treated cautiously where they are based solely on the operation's leak-site postings; however, its extortion activity and use of stolen-data publication threats are established characteristics.
Qilin is a financially motivated cybercriminal ransomware operation, also known as Agenda, Gold Feather, Water Galura, Qiling, Qirin, and Phantom Mantis. The operation uses an affiliate-based model and has targeted organizations across numerous countries and sectors, including agriculture and food production, manufacturing, transportation, and health care. Qilin has been associated with the Synnovis incident. A Qilin-associated intrusion cluster, UAT-11988, targeted Cisco Secure Firewall Management Center environments using static credentials associated with CVE-2026-20316. The cluster performed Active Directory and database credential discovery, enumerated domain infrastructure and endpoints, deployed SOCKS proxying and reverse SSH tunnels, forwarded enterprise authentication and remote-management protocols, and used Impacket and pass-the-hash tooling. Before deploying Qilin ransomware, operators used tools intended to disable endpoint security products. The activity demonstrates reconnaissance, credential theft, defense evasion, lateral movement, and post-compromise ransomware deployment.
Black Axe, formally associated with the Neo Black Movement of Africa, is a highly structured transnational organized-crime network of Nigerian origin with operations across Africa, Europe, and other regions. The group is organized into regional chapters commonly called zones and is linked to cyber-enabled financial crime, including romance scams, advance-fee fraud, business email compromise, investment and cryptocurrency fraud, identity theft, and money laundering. Black Axe operations use fraudulent personas, social-media and dating platforms, aliases, and internet-based communications to deceive victims and induce payments. Members and facilitators have used mule accounts, victim-controlled accounts, business entities, remittance mechanisms, and other financial infrastructure to move and obscure criminal proceeds. Black Axe has also been associated with coercive extortion in which victims are threatened with disclosure of sensitive images. Law-enforcement actions have targeted Black Axe leaders, members, facilitators, and laundering infrastructure in multiple countries. The organization has also been linked to serious non-cyber criminal activity, including violent crime, trafficking, kidnapping, armed robbery, and drug trafficking.
Storm is a ransomware operation that has claimed attacks against organizations in the United States, Canada, and Australia. Reported victims span healthcare, financial services, manufacturing, construction, aerospace services, retail and office-services providers, and agricultural businesses. The group was associated with 15 self-reported ransomware claims during a single week in August 2026. Storm markets itself as an AI-powered, quantum-resistant ransomware operation; the claimed AI functionality and technical characteristics of its ransomware have not been independently verified. Public reporting on its alleged victimizations generally does not establish the malware family, intrusion vector, encryption activity, data theft, affected systems, or ransom demands. One reported incident involved the alleged exposure of engineering designs and firmware source code from a U.S. power-systems manufacturer.
Metaencryptor is a ransomware threat group associated with attacks against organizations in manufacturing, health care, utilities, construction, food production, and defense-related engineering. Reported victims include organizations in the United States, Canada, Germany, Japan, Singapore, and South Korea. The group has been observed using the modular .NET remote-access trojan CSHARP-STREAMER during a ransomware intrusion. In that operation, operators loaded the malware in memory through a PowerShell loader incorporating AMSI bypass and XOR decryption functionality, used its TCP relay capability to reach a more protected network segment, and enumerated domain users using PowerShell scripts. Metaencryptor has shown particular interest in IT service providers. The group is also tracked as an active ransomware operation in victim-posting-based incident reporting.
TeamPCP is a financially motivated cybercriminal threat actor tracked as UNC6780 and also known as Altered Spider. The group has conducted large-scale software supply-chain compromises against open-source development ecosystems, including PyPI, npm, Docker Hub, GitHub Actions, and CI/CD tooling. Its operations have targeted developer, cloud, package-registry, SSH, cryptocurrency-wallet, and AI-service credentials, with stolen access used to expand compromise across downstream organizations and development environments. TeamPCP has deployed credential-stealing malware including SANDCLOCK, also publicly referred to as CanisterWorm, and DUSTMAKER. SANDCLOCK targeted Linux and Kubernetes environments and included container-escape functionality. DUSTMAKER is a cross-platform JavaScript payload optimized for CI/CD environments; variants have targeted AI-development tooling and used poisoned AI-assistant workspace configurations and prompt injection for defense evasion. The actor has also used compromised developer accounts and package-publishing credentials to distribute trojanized resources, establish persistence, collect secrets from CI/CD runners, exfiltrate data through code-hosting services, and propagate through trusted software dependencies. Documented TeamPCP activity includes compromises of CI/CD components and packages associated with Trivy, KICS, LiteLLM, and Telnyx, as well as campaigns affecting npm packages. The group has used filesystem and process-memory collection for secrets, Kubernetes discovery and lateral movement, privileged container deployment attempts, and cloud-credential theft. It has also been linked to ShadowRay 2.0 activity targeting exposed Ray clusters, although the relationship between TeamPCP and earlier activity tracked as TA-NATALSTATUS and IronErn remains an assessment rather than conclusive attribution. Australian authorities charged two Western Australia residents in August 2026 as alleged TeamPCP members in a joint operation with U.S. law enforcement.
Genesis is a financially motivated ransomware and data-extortion actor associated with claims of intrusions against organizations primarily in the United States, with additional reported victims in Denmark and Canada. Its reported victim set spans construction and contracting, healthcare, information-technology services, accounting and other professional services, real estate, staffing, and pipeline-related businesses. Genesis claimed unauthorized access to Interim HealthCare operations in Oklahoma and Tulsa, theft of a large volume of patient, clinical, personal, and corporate data, and threatened public release unless a ransom was paid. Available reporting supports data theft and extortion activity, but does not establish a specific ransomware payload, initial-access method, encryption activity, or a verified relationship to the separate Genesis cybercrime marketplace known for selling stolen browser fingerprints and account data.
ChimeraZ is an underground-forum persona active since at least May 2026 that has repeatedly claimed to sell or freely distribute databases and document collections allegedly taken from predominantly French organizations. Its claimed victim set is concentrated in real estate, retail, municipal and emergency services, equipment rental and agricultural machinery, renewable-energy commerce, legal services, travel, and vehicle inspection. A claimed leak involving a Swiss football club extends the activity to Switzerland. Numerous releases have been distributed as structured database exports or document archives, often accompanied by samples, download gating, or sales offers seeking cryptocurrency payment. Several operations were conducted or claimed jointly with misere; Cybernox and NightBroker were also named as collaborators in individual claims. ChimeraZ has claimed data obtained through exposed web access controls and SQL injection in some cases, and has asserted that a series of business-data leaks derived from a shared-platform compromise. These intrusion and provenance claims remain unverified. A confirmed data-exfiltration incident affecting a French recruitment platform was publicly claimed by ChimeraZ, although attribution for the original credential theft was not established. The actor's published material and claimed datasets commonly involve customer, employee, member, property, transaction, CRM, email, and operational records, creating potential for phishing, impersonation, fraud, and business-email-compromise follow-on activity. No ransomware encryption or extortion demand has been established.
Handala Hack is an Iranian state-linked cyber actor assessed by the FBI to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS). It is part of a pro-Iranian hacktivist and proxy ecosystem and has been associated with politically motivated disruptive operations, hack-and-leak activity, and threats against critical infrastructure. The FBI has linked Handala Hack to a July 2025 hack-and-leak operation and assessed it to be connected to Homeland Justice, a group responsible for destructive wiper activity against Albania. Handala claimed responsibility for a 2026 cyberattack that disrupted Stryker’s global operations; Stryker confirmed the intrusion but public attribution of that incident was not independently established. The actor is also known as VOID MANTICORE, Dune, Banished Kitten, Red Sandstorm, Storm-0842, and Homeland Justice. Reported VOID MANTICORE activity includes use of trojanized applications for persistent surveillance, concealed PowerShell execution, and collection of credentials from Windows Registry hives.
Arcus Media, also known as arcusmedia and arcus_media, is a ransomware-as-a-service operation active since at least May 2024. It has been associated with ransomware and data-breach claims against organizations in North America, Europe, Africa, Central America, and Southeast Asia, including technology, logistics, public-sector, consumer-services, tourism, and water-supply entities. Arcus Media has been characterized as focused on industrial and critical-infrastructure targets. Its activity includes ransomware operations accompanied by victim deadlines consistent with extortion demands. Arcus Media has also been reported to harvest credentials stored in web browsers.
Cl0p is a Russian-speaking, financially motivated cybercrime and ransomware/data-extortion operation. It is widely associated in public reporting with TA505, also tracked under names including Graceful Spider, GOLD Tahoe, DEV-0950, Lace Tempest, and Spandex Tempest; however, the precise relationships among TA505, Cl0p, and FIN11 remain contested. Cl0p is notable for opportunistic, high-volume exploitation of zero-day and other critical vulnerabilities in enterprise managed-file-transfer and business software. Campaigns have exploited Accellion FTA, GoAnywhere MFT, MOVEit Transfer, Cleo file-transfer products, Oracle E-Business Suite, and PaperCut servers. The group steals data from compromised organizations and uses ransom demands and public leak-site pressure to extort victims. While Cl0p has operated as ransomware, recent major campaigns have emphasized encryption-less data theft and extortion. Its victimology is cross-sector and international, with documented activity affecting food and agriculture organizations and U.S. entities.
AntiBrok3rs, also known as Nam3L3ss, is a financially motivated access broker and data leaker active against the energy sector. The actor published data associated with at least 15 energy-sector victims affected by the 2023 MOVEit supply-chain exploitation. The exposed utility-related data was traced to a compromise of CLEAResult, a North American energy-efficiency and sustainability-program consultant used by multiple utilities, rather than demonstrated direct compromises of each affected utility. AntiBrok3rs publicly denied affiliation with the Cl0P ransomware operation despite the data’s association with the Cl0P MOVEit campaign. Known affected organizations included CenterPoint Energy, Entergy, Nevada Energy, and Appalachian Power. The actor's country of origin and operating location are not established.
Breaches attributed to ransomware activity, most recently reported first.
Endpoint antivirus blocks attempted shadow-copy deletion
Hacking Cat disputes ownership of ransomware lockers