Ransomware Operations & Threat Actors
Ransomware Operations & Threat Actors
Articles on ransomware groups, operations, TTPs, encryption strategies, and threat intelligence about extortion campaigns targeting organizations.
ransomware operations threat actorsJun 30, 20264 min
Ukrainian National Extradited from Ireland Pleads Guilty to Conti Ransomware Conspiracy
A Ukrainian developer extradited from Ireland pleaded guilty to conspiracy charges for coding malware loaders used by the Conti ransomware syndicate, which extorted over $150 million from hospitals and businesses worldwide.
ransomware operations threat actorsJun 30, 20267 min
Prinz Eugen Ransomware: Go-Based Encryptor Targets Recent Files, Leaves No Footprint
Threatdown's deep-dive analysis of Prinz Eugen reveals a Go-based ransomware encryptor that sorts files by modification date to hit active data first, uses ChaCha20-Poly1305 with Argon2id key derivation, and leaves no ransom note — while attribution points to a lone operator known as ROOTBOY behind breaches including Standard Bank's 1.2 TB data theft.