Normal view

There are new articles available, click to refresh the page.
Today — 11 August 2026Security/Privacy

U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang

10 August 2026 at 15:13

U.S. and South Korean cyber agencies warned Monday about a ransomware-as-a-service outfit, Gunra, that reportedly recruits ethical hackers and penetration testers and benefits from North Korean government-linked hackers’ tools to target government and critical infrastructure organizations.

Gunra has gone after sectors such as academia, financial services and insurance, government services and facilities, healthcare, manufacturing and construction, media, retail, transportation and utilities. Its global scope is far-ranging, according to Monday’s alert: Africa, the Americas, the Asia-Pacific, Europe and the Middle East.

“Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations,” said Chris Butera, acting assistant director for cybersecurity at the Cybersecurity and Infrastructure Security Agency, which produced the advisory with the Department of Defense’s Cyber Crime Center, FBI, National Security Agency, Secret Service and Republic of Korea’s National Police Agency.

The alert is part of the #StopRansomware series, a joint FBI-CISA project aimed at network defenders.

The FBI first took notice of Gunra in April of last year. The double-extortion group established a data leak site on Tor to list victims and publish purloined data. By January of this year, Gunra had launched a formal ransomware-as-a-service affiliate and was growing in its ambition, Monday’s alert states.

“The FBI observed the group adopting new branding aliases (notably operating under the name Golden Community) to support this expansion,” it reads. “Gunra has further commercialized its platform by actively recruiting penetration testers and ethical hackers to serve as initial access brokers, offering a share of the ransom profits in exchange for enterprise network access.”

Gunra seeks initial access with known vulnerabilities in internet-facing devices like firewalls or virtual private networks, and is based on or influenced by the Conti ransomware code leaked in 2022, according to the agencies.

Research published in July by a South Korean cybersecurity firm took note of Gunra overlap with Lazarus Group, although it doesn’t explicitly mention the latter group’s name.

“These commonalities suggest that although the state-sponsored threat group and the Gunra ransomware group appear to be separate threat actors with different ultimate objectives, they may have shared certain techniques, tools, and infrastructure or collaborated to a limited extent during the attacks,” AhnLab wrote in its report.

That kind of North Korean government-ransomware gang collaboration dates back to at least 2024. Nor is Gunra alone among ransomware-as-a-service outfits recruiting penetration testers.

The post U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang appeared first on CyberScoop.

Before yesterdaySecurity/Privacy

Canadian Man Pleads Guilty in Snowflake Extortions

6 August 2026 at 13:00

A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers.

A surveillance photo of Connor Riley Moucka, a.k.a. “Judische” and “Waifu,” dated Oct 21, 2024, 9 days before Moucka’s arrest. This image was included in an affidavit filed by an investigator with the Royal Canadian Mounted Police (RCMP).

The U.S. Justice Department said between February and October 2024, Moucka and co-conspirators used stolen login credentials to steal cloud-hosted data belonging to at least 165 customers of a U.S.-based software-as-a-service company.

The hackers targeted stolen credentials for Snowflake customer accounts that did not enforce multi-factor authentication, and extorted or attempted to extort a host of well-known companies, including TicketMaster, Lending Tree, Advance Auto Parts and Neiman Marcus. Snowflake responded to the data thefts by increasing password complexity requirements and enforcing multi-factor authentication.

Moucka adopted new nicknames frequently — sometimes operating multiple identities concurrently — but two of his best-known monikers were “Judische” and “Waifu.” Judische’s admitted role in the Snowflake data thefts was first documented by KrebsOnSecurity in a September 2024 story about the overlap between Western, English-speaking cybercriminals and extremist groups that harass and extort minors into harming themselves or others.

That September 2024 story identified Judische as a software engineer from Ontario who has been involved in numerous data breaches and voice phishing attacks against U.S. companies since at least 2020. A little more than a month later, Canadian authorities arrested Moucka on a provisional warrant from the United States.

The government says Moucka and others used their unauthorized access to steal billions of sensitive customer records and download terabytes of information, “including individuals’ non-content call and text history records, banking and other financial information, payroll records, Drug Enforcement Administration (DEA) registration numbers, driver’s license numbers, passport numbers, social security numbers and other personally identifiable information. They then extorted victims by threatening to publish data online.”

Moucka also threatened and harassed government officials and security researchers who were helping to track him down. The Justice Department said the conspirators made over $2.5 million in ransom payments, and that in at least one instance, Moucka re-extorted a victim with threats of further disclosure of the victim’s stolen data.

“Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt,” reads a statement from the Justice Department.

One of Moucka’s admitted co-conspirators is Cameron “Kiberphant0m” Wagenius, a U.S. Army soldier who pleaded guilty in July 2025 to extorting AT&T and Verizon for their customer account data. Less than a month before Wagenius’s arrest, KrebsOnSecurity published a deep dive into Kiberphant0m’s various Telegram and Discord identities over the years, revealing how the owner of the accounts told others they were in the Army and stationed in South Korea.

One of several selfies on the Facebook page of Cameron Wagenius.

Kiberphant0m also re-extorted victims. Immediately following Moucka’s arrest, Kiberphant0m posted on hacker forums what he claimed were the AT&T call logs for then President-elect Donald Trump and for then Vice President Kamala Harris, as well schematics allegedly stolen from the U.S. National Security Agency (NSA).

Wagenius is set to be sentenced on September 3, 2026. The government says he faces a maximum penalty of 20 years in prison for conspiracy to commit wire fraud, a maximum penalty of five years in prison for extortion in relation to computer fraud, and a mandatory two-year sentence consecutive to any other prison time for aggravated identity theft.

The third alleged co-conspirator is John Erin Binns, 26, an elusive American man who fled the United States after being indicted for his admitted role in a 2021 breach at T-Mobile that exposed the personal information of at least 76 million customers.

Sources close to the investigation said Binns, also known as “IRDev” and “IntelSecrets,” was until recently incarcerated in a Turkish prison, but that he has since been released and has resurfaced online. Those sources said Binns also recently obtained Turkish citizenship, and under Turkish law a citizen cannot be extradited to a foreign country.

An image of a passport that Binns shared in an email to KrebsOnSecurity in Feb. 2023.

Moucka pleaded guilty to four criminal counts, including computer fraud, wire fraud, aggravated identity theft, and conspiracy. He is slated to be sentenced on Oct. 27 and faces a mandatory minimum penalty of two years in prison on the aggravated identity theft count, as well as a maximum penalty of 30 years in prison on the remaining counts. Ultimately, it will be up the federal judge how much time Moucka actually serves for his extensive cybercriminal rap sheet.

For an interview with Moucka prior to his arrest and a deeper look at Binns, see our original report on Moucka’s arrest.

Ransom Cartel creator sentenced to 16 years in prison

6 August 2026 at 14:16

A longtime cybercriminal was sentenced to 16 years in prison for creating and running Ransom Cartel, a ransomware strain linked to attacks on at least 18 companies between 2021 and 2023, the Justice Department said Wednesday. 

Maksim Silnikau, a Belarusian national, actively participated in Russian-speaking cybercrime forums since at least 2005, and was a member of the cybercrime site Direct Connection from 2011 to 2016, officials said. The 40-year-old created Ransom Cartel and began recruiting participants from cybercrime forums in 2021. 

Silnikau and his co-conspirators attempted to extort at least $5.2 million from victims during the multi-year scheme. 

Victims included a group of law firms, medium-sized businesses, a small medical technology startup, educational institutions and large multinational corporations based in California, New York, Nebraska and elsewhere. Some of the victims’ operations were disrupted for several months, officials said. 

Officials said Silnikau provided his co-conspirators information and tools to attack systems, including stolen credentials and mechanisms to encrypt compromised computers. He also built a site to monitor and control ongoing attacks, communicate with co-conspirators and victims, negotiate payment demands with victims and manage the distribution of funds between co-conspirators. 

Silnikau, also known as “J.P. Morgan,” “xxx,” and “lansky,” fled from Spain while awaiting extradition to the United States and was arrested in Poland in July 2023 as he tried to return to Belarus, according to court records. He was extradited to the United States in August 2023. 

Ransom Cartel’s operations ended when Silnikau was arrested. Authorities applauded his capture at the time, noting that Ransom Cartel didn’t grow large enough to inflict losses comparable to larger ransomware variants. 

Silnikau pleaded guilty to conspiracy to commit wire fraud and aggravated identity theft.

The post Ransom Cartel creator sentenced to 16 years in prison appeared first on CyberScoop.

Prolific ransomware group behind SonicWall zero-day attacks

4 August 2026 at 11:20

Researchers said INC ransomware, one of the most active ransomware groups globally, has been the main attacker exploiting a pair of SonicWall zero-days soon after they were disclosed last month.

The prolific ransomware-as-a-service operation wasn’t the first group to exploit the flaws, which were actively exploited for three weeks before the vendor disclosed and patched the defects July 14, but it has been the most assertive and concerning group to target and chain both vulnerabilities together for full access.

“Since public disclosure, INC ransomware has emerged as the most commonly named threat actor actively weaponizing this vulnerability chain,” Brett Deroche, director of incident response at Rapid7, told CyberScoop. “While Inc is the name driving the post-disclosure wave, we can’t attribute the full body of exploitation to INC specifically.”

SonicWall did not respond to a request for comment.

The SonicWall vulnerabilities — CVE-2026-15409 and CVE-2026-15410 — are the latest in a series of security issues confronting the vendor’s customers, including actively exploited zero-days, previously disclosed defects, and an attack last year that allowed a state-sponsored threat group to steal the firewall configurations of every SonicWall customer

Just last week, Huntress researchers spotted an attack spree that compromised 30 SonicWall customers in less than two days. 

Ransomware groups have taken a special interest in SonicWall. Ten of the 17 SonicWall defects added to the Cybersecurity and Infrastructure Security Agency’s known exploited vulnerabilities (KEV) catalog since late 2021 are known to be used in ransomware campaigns.

INC ransomware, which has claimed nearly 900 victims across 71 countries since it was first discovered three years ago, is just the latest financially-motivated group to target SonicWall customers. 

Researchers haven’t determined how many organizations have been impacted by the latest SonicWall zero-days, including attacks linked to INC ransomware. 

“Attribution here isn’t a single clean answer. The earliest exploitation we observed, beginning June 22, traced back to common hosted infrastructure, though those attacks were largely unsuccessful,” Deroche said. 

“INC’s confirmed activity that we’ve observed came after public disclosure, using different infrastructure and moving from initial access to ransomware deployment in short order. That’s a meaningfully different operational tempo and skill level than what we saw pre-disclosure,” he added. 

Deroche said Rapid7 has successfully prevented data theft and encryption in the majority of recent cases, yet noted ransomware was deployed in at least one case the security vendor observed.

Yet, there could be other attacks outside the purview of Rapid7’s telemetry. INC ransomware has listed multiple new alleged victims on its data leak site, including organizations and government agencies in Australia, the United States, the United Arab Emirates, Colombia and Switzerland, Resecurity said in a blog post Saturday.

The company said it has aided several victims with incident response, and learned multiple victims received emails and phone calls from alleged hackers who pressured them to engage in negotiations.

The post Prolific ransomware group behind SonicWall zero-day attacks appeared first on CyberScoop.

ShinyHunters Claims Ernst & Young Hack

29 July 2026 at 02:23

Ernst & Young previously confirmed that personal and financial information was stolen from a third-party management platform.

The post ShinyHunters Claims Ernst & Young Hack appeared first on SecurityWeek.

Despite multiple takedowns, botnets continue to grow

24 July 2026 at 15:47

Botnets powered by residential proxy networks are proliferating, enabling cybercriminals of all types to evade detection by blending in with seemingly legitimate traffic, Lumen Technology’s Black Lotus Labs said in a report Friday.

The global scale of botnets observed by Lumen is currently approaching 60 million victim IP addresses, Chris Formosa, senior lead information security engineer at Black Lotus Labs, told CyberScoop. Roughly 1 in 4 of those compromised IPs are based in the United States, and the true number of infected devices is much greater because there are networks beyond Lumen’s visibility and multiple devices are often unknowingly running a malicious proxy network on the same IP. 

Super-sized botnets are also gaining momentum, according to Lumen, with an average of 10 distinct botnets controlling their own populations of about 1 million active victims daily.

“The only reason these botnets keep getting more and more victims is because there is clearly a market. Aside from criminal activity, who wants access to millions of IPs regularly?” Formosa said. 

That demand for botnets fuels opportunities for growth, reselling, collaboration, and quick rebounds following massive disruptions.

IPIDEA, one of the largest residential proxy networks in operation when its infrastructure was disrupted by coordinated strikes in January, recovered at nearly half-strength within hours and earlier this surpassed its pre-disruption botnet size with a current botnet population of about 10 million IPs, researchers said.

“Their rebuild was eye-opening as they began to rebound from that interdiction,” Ryan English, information security engineer at Black Lotus Labs, told CyberScoop. “Even for how quickly some botnets can rebound, theirs was surprising. We’ve seen them all rebuild, but we haven’t seen anybody do it that fast.”

Meanwhile, botnets are continuously growing, as cybercriminals seek out the cover they provide, more cheap and poorly defended devices hit the market and vendors stop providing security updates for older but still usable products. 

“Your available pool for those proxy hunters grows every year, and it will continue to grow every year,” English said, adding that more than 1 billion devices are currently vulnerable and available to be unknowingly sucked up into botnets.

The challenge for defenders is lopsided, and while disruptions and seizures occur relatively often, botnet operators have formed a global supply chain with pathways that are difficult to break. 

“We have observed multiple residential proxy services collaborating to form what amounts to the largest cooperative network ever seen on the internet,” researchers wrote in the report.

Black Lotus Labs currently tracks more than 30 distinct malicious proxy botnet clusters, and most of those regularly boast more than 100,000 daily victims.

“Our understanding of the various botnets in this space, along with experience in multiple disruptions, leads us to a very important conclusion: taking down a single malicious proxy provider or their botnet in isolation is likely to result in a short-lived solution,” researchers wrote. 

“In recent years, the malicious proxy environment has essentially created the largest collective botnet currently active on the internet, capable of moving millions of IPs within hours to wherever they are needed,” they added. “Until the malicious proxy landscape is properly addressed and regulated on both the private industry and law enforcement sides, this issue will grow and, along with the DDoS botnet landscape, will most likely become a greater problem in the long term.”

The post Despite multiple takedowns, botnets continue to grow appeared first on CyberScoop.

The Signs Were There: What the First Autonomous Ransomware Case Confirms

An AI agent has run a ransomware intrusion on its own for the first time, from break-in to data destruction. The autonomous attacks TrendAI™ Research predicted are beginning to arrive, and defending against them shifts from blocking known indicators to detecting behavior.

Leading members of Scattered Spider sentenced in UK to 66 months in jail

17 July 2026 at 10:12

A pair of young men were sentenced to 66 months in jail for committing a cyberattack on the Transport for London that brought the network’s operations to a standstill in 2024, the United Kingdom’s National Crime Agency said Thursday.

Thalha Jubair and Owen Flowers were arrested at their homes in September 2025, barely a year after the attack, and pleaded guilty last month just as their trials were set to begin. Flowers was previously arrested in connection with the attack in September, but was released after questioning by officers.

Jubair and Flowers were leading members and highly involved in Scattered Spider, a nebulous hacker subset of The Com, according to researchers. The 20-year-old Jubair was a prolific cybercriminal and core member of the unbound collective

U.S. authorities last year accused Jubair of direct, prominent involvement in at least 120 cyberattacks, including extortion of 47 U.S.-based organizations and the January 2025 attack on the federal court system. 

Officials said they traced a combined total of at least $89.5 million in cryptocurrency, at the time of payments, to Bitcoin addresses and servers controlled by Jubair. Two financial services firms paid Jubair $25 million and $36.2 million, respectively, in Bitcoin between June and November 2023, according to an unsealed criminal complaint against Jubair. 

At the time of Jubair’s arrest, “he was one of the four principal people that we associated with Scattered Spider,” and one of the two most core players, Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, told CyberScoop. 

Jubair and Owens had significant resources and support, and “victim payments were reinvested back into the enterprise,” said Allison Nixon, chief research officer at Unit 221B. 

The lasting impact of Jubair and Owens’ capture and imprisonment remains hazy.

U.K. authorities insist Jubair and Owens’ arrests and punishment “effectively halted the group’s criminal activity,” yet they added that other cybercriminals continue to use the Scattered Spider brand in more recent attacks. 

Thursday’s announcement “represents a significant step in holding accountable two members of Scattered Spider, a group that has repeatedly relied on data extortion, SIM-swap attacks, and other social engineering techniques to infiltrate networks and undermine critical services,” Brett Leatherman, assistant director of the FBI Cyber Division, said in a statement. 

The FBI also noted, in a LinkedIn post, that members of Scattered Spider “continue to victimize organizations around the world and cause significant financial and operational harm.”

When Owens, now 18, was first arrested for the Transport for London attack in 2024, investigators said he was “in the process of hacking the systems of U.S. health care companies SSM Health Care Corporation and Sutter Health, which had been infiltrated and damaged.”

Officials also said Jubair and Owens failed to cooperate after their arrests. 

“This is the largest cybercrime prosecution ever brought before the U.K. courts and the culmination of nearly two years of painstaking work,” Paul Foster, head of the National Crime Center’s National Cybercrime Unit, said in a statement. 

“Scattered Spider has been the most significant cybercrime threat to the U.K. in recent years. Through this investigation, we have severely disrupted that threat and brought key offenders to justice,” Foster added.

Despite the upbeat reaction from U.K. officials, Nixon said the punishment for Jubair and Owens is “remarkably lenient considering the period of continuous reoffending lasted longer than the sentence.”

Nixon hopes the United States will eventually extradite the pair to face additional charges. “If that happens, they won’t be able to use mental illness as a loophole to get back to harming society as soon as possible,” she added.

“No one who worked on their case was surprised they would reoffend, and there seems to be no allowance in the law to protect the public from what everyone knew was going to happen,” Nixon said. “I know the narrative in the cybercriminal culture will glorify them, but they wouldn’t if they knew the full story.”

The post Leading members of Scattered Spider sentenced in UK to 66 months in jail appeared first on CyberScoop.

Russian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrime

16 July 2026 at 13:24

Three Russian nationals and a pair of bulletproof hosting providers directly supported a series of attacks on critical infrastructure in 21 states and several countries, according to a 2024 indictment unsealed in federal court Tuesday. 

Officials, who have been investigating the trio and their companies since 2019, said the attacks resulted in losses surpassing $62 million.

Alexander Alexandrovich Volosovik, the 43-year-old owner of Media Land; Yulia Vladimirovna Pankova, the 29-year-old owner of ML.Cloud; and 34-year-old Kirill Andreevich Zatolokin were charged with conspiracy to commit and aid computer fraud, conspiracy to commit wire fraud, wire fraud and conspiracy to commit money laundering.

The State Department also offered a reward up to $10 million for information on government-linked associates of the alleged cybercriminals and malicious use of Media Land or ML.Cloud. The Treasury Department and officials from the United Kingdom and Australia imposed sanctions on Volosovik, Zatolokin, Pankova, Media Land and ML.Cloud in November 2025. 

The three accused Russians, Media Land and ML.Cloud were all based in St. Petersburg as of 2024.

“With today’s actions, the FBI and our partners are striking at the core services that cybercriminals rely on to attack U.S. critical infrastructure,” Brett Leatherman, assistant director of the FBI Cyber Division, said in a statement. “This is another step in our broader campaign to shrink the space in which these actors can operate, forcing them to work harder, take greater risks, and lose the anonymity they depend on.”

Media Land and ML.Cloud allegedly provided cybercriminals with infrastructure and technical support to infect systems with malware and ransomware for extortion. Officials said the organizations also supported criminal marketplaces, fraudulent domain registrations and platforms that cybercriminals used to commit phishing and brute-force attacks.

Officials said they identified a consistent and long-running pattern of criminal activities facilitated by Volosovik, Pankova, Zatolokin, Media Land and ML.Cloud.

Investigators located victims across 21 states, including nine cities in the Northern District of Ohio, where the indictment was filed. Additional victims were located in Australia, the European Union, the United Arab Emirates, Canada and the United Kingdom.

Bulletproof hosting providers are increasingly used by cybercriminals to obfuscate their activities, deliver malware, phishing, and host content and services that support ransomware, data extortion and denial-of-service attacks.

“From their overseas safe haven, these defendants ran the criminal infrastructure that powered attacks on critical institutions across our nation,” A. Tysen Duva, assistant attorney general of the Justice Department’s Criminal Division, said in a statement. “Their actions put the American public at risk. We will continue to dismantle these networks and protect our critical infrastructure from cybercriminals at home and abroad.”

The post Russian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrime appeared first on CyberScoop.

❌
❌