May 20, 2025

RVTools Website Hacked to Spread Bumblebee Malware

In a concerning case of software supply chain compromise, the official RVTools website was hacked to distribute malware. RVTools is a trusted utility used by VMware administrators. The installer, normally used to help IT professionals audit virtual environments, was tampered with to deliver the Bumblebee malware loader, a known precursor to ransomware attacks. This incident underscores the persistent and growing

RVTools Website Hacked
May 19, 2025

Skitnet Malware Fuels Ransomware Attacks

Ransomware gangs are evolving fast, and their newest weapon, Skitnet malware, proves it. Known alternately as “Bossnet,” this emerging post-exploitation malware is gaining traction among threat actors like BlackBasta and Cactus. Designed for stealth, Skitnet leverages in-memory execution, DNS-based command and control, and anti-forensics to maintain a low profile while enabling persistent remote access. As its use spreads in phishing

skitnet malware
May 15, 2025

CPU-Level Ransomware: Is It Possible and How Dangerous Is It?

Ransomware has officially leveled up. In a chilling new development, cybersecurity researchers have unveiled the world’s first proof-of-concept CPU-level ransomware - an attack so deeply embedded in hardware that it bypasses every traditional defense in the cybersecurity playbook. Unlike conventional ransomware that encrypts files through software-level exploits, this innovation taps directly into the processor’s microcode, rewriting the rules of engagement.

CPU-Level Ransomware
May 14, 2025

LockBit Ransomware Hacked: What We Know So Far

In a major blow to one of the world’s most active ransomware groups, LockBit has been hacked, and the fallout could reshape the cybercrime landscape. On May 7, 2025, an unknown hacker gained access to LockBit’s administration panel, defaced its dark web site with the message “Don’t do crime, crime is bad xoxo from Prague,” and leaked a trove of

LockBit Ransomware Group Hacked
May 13, 2025

DoppelPaymer Ransomware Suspect Arrested in Moldova

DoppelPaymer Ransomware suspect was arrested. In a significant blow to the global ransomware ecosystem, Moldovan authorities have seized a 45-year-old foreign national. He is suspected of playing a central role in the notorious DoppelPaymer ransomware attacks. The arrest, carried out on May 6, 2025, follows a coordinated operation with Dutch law enforcement and is part of a broader international effort

DoppelPaymer Ransomware Suspect Arrested