LIVE
LATEST THREAT: Arcus Media: The RaaS Operation Targeting Healthcare and Critical Infrastructure THREAT ALERT ACTIVE
Threat Intelligence Feed — Active Monitoring

RANSOMWARE
THREAT INTELLIGENCE
GROUPS // CAMPAIGNS // TTPs // VICTIMS

Track active ransomware groups, ongoing campaigns, and emerging tactics. Timely intelligence to help defenders stay ahead of threat actors.

View All Intelligence RSS Feed
$2.1B+ 2025 Ransom Payments
480+ RansomHub Victims
$1.2M Median Settlement
11 days Median Dwell Time
Group Profile LockBit Apr 15, 2026

LockBit 4.0: Resurgence After Operation Cronos

Following the February 2024 law enforcement takedown, LockBit has re-emerged as LockBit 4.0 with hardened infrastructure, a new encryptor, and a reformed affiliate program targeting mid-market enterprises.

Access Report →
Threat Level
8/10
Sectors Targeted
— finance— manufacturing— healthcare— legal
All Reports →
Group Profile Arcus Media Jul 20, 2026

Arcus Media: The RaaS Operation Targeting Healthcare and Critical Infrastructure

Arcus Media emerged in April 2024 as a Rust-based ransomware-as-a-service operation with a focus on healthcare, utilities, and critical infrastructure sectors. Despite a relatively low public profile, the group has claimed over 80 victims across 15 countries, operates a professional affiliate recruitment programme, and has been linked to credential theft campaigns targeting unpatched VPN appliances.

8
Group Profile Embargo Jul 19, 2026

Embargo Ransomware: Rust-Based RaaS Targeting Enterprise and Healthcare

Embargo emerged in mid-2024 deploying a custom Rust-based ransomware and locker toolset against enterprise targets in North America and Europe. With double extortion infrastructure, a dedicated leak site, and affiliate recruitment, Embargo operates a mature RaaS model despite its relative youth. This profile covers their TTPs, victim profile, and defensive considerations.

8
Group Profile Spirals Jul 18, 2026

Spirals Ransomware: New Group Completes Full Attack Chain in Under 24 Hours

Spirals is a newly documented ransomware group that emerged in July 2026, notable for completing the full attack chain from IIS initial access to network-wide encryption in under 24 hours. The group uses intermittent encryption for large files and leaves a distinctive RECOVERY_SECTION.log ransom note.

8
Group Profile RansomExx Jul 17, 2026

RansomExx: Long-Running Enterprise Ransomware Group Targeting Critical Infrastructure and Government

RansomExx is one of the oldest continuously active ransomware operations, with confirmed victims across government, critical infrastructure, healthcare, and education in North America, Europe, and Latin America. This profile covers the group's history, Linux/Windows dual-platform tooling, and current 2026 activity.

8
Campaign Alert Akira Jul 16, 2026

Akira's SonicWall Campaign: How a VPN Appliance Became a Gateway to 100+ Intrusions

From July 2025, Akira ransomware operators systematically shifted initial access focus to SonicWall SSL-VPN appliances, exploiting CVE-2024-40766 to generate a wave of intrusions across manufacturing, professional services, and healthcare organisations.

9