ProBackend
Ransomware Operations & Threat Actors

Ransomware Operations & Threat Actors

Articles on ransomware groups, operations, TTPs, encryption strategies, and threat intelligence about extortion campaigns targeting organizations.

ransomware operations threat actorsJun 30, 20264 min

Ukrainian National Extradited from Ireland Pleads Guilty to Conti Ransomware Conspiracy

A Ukrainian developer extradited from Ireland pleaded guilty to conspiracy charges for coding malware loaders used by the Conti ransomware syndicate, which extorted over $150 million from hospitals and businesses worldwide.

ransomware operations threat actorsJun 30, 20267 min

Prinz Eugen Ransomware: Go-Based Encryptor Targets Recent Files, Leaves No Footprint

Threatdown's deep-dive analysis of Prinz Eugen reveals a Go-based ransomware encryptor that sorts files by modification date to hit active data first, uses ChaCha20-Poly1305 with Argon2id key derivation, and leaves no ransom note — while attribution points to a lone operator known as ROOTBOY behind breaches including Standard Bank's 1.2 TB data theft.