LIVE
LATEST THREAT: Cl0p Goes Public: Windchill Campaign Victim List Tops 40, GE Quietly Disappears THREAT ALERT ACTIVE
Threat Intelligence Feed — Active Monitoring

RANSOMWARE
THREAT INTELLIGENCE
GROUPS // CAMPAIGNS // TTPs // VICTIMS

Track active ransomware groups, ongoing campaigns, and emerging tactics. Timely intelligence to help defenders stay ahead of threat actors.

View All Intelligence RSS Feed
$2.1B+ 2025 Ransom Payments
480+ RansomHub Victims
$1.2M Median Settlement
11 days Median Dwell Time
Group Profile RansomHub Aug 9, 2026

RansomHub: The Most Active RaaS Operation of 2025-2026

RansomHub emerged in February 2024 and rapidly became the highest-volume ransomware operation following LockBit's February 2025 disruption. This profile covers the group's affiliate model, technical tooling, victim statistics, and the specific sectors and countries under sustained targeting.

Access Report →
Threat Level
8/10
Sectors Targeted
— healthcare— critical-infrastructure— finance— manufacturing
All Reports →
Campaign Alert Cl0p Aug 26, 2026

Cl0p Goes Public: Windchill Campaign Victim List Tops 40, GE Quietly Disappears

Cl0p has shifted from silent exfiltration to public shaming in its PTC Windchill and FlexPLM campaign, naming Shell, Philips, Fiserv, and dozens more since August 12. General Electric's abrupt removal from the leak site hints at a negotiation already resolved.

9
Group Profile Global Group Aug 26, 2026

Global Group: RaaS Operation Pairs AI-Driven Negotiation With a Mobile Affiliate Panel

Global Group, a ransomware-as-a-service brand assessed by researchers as a likely rebrand of Black Lock, has scaled rapidly since its mid-2025 launch on the strength of an 80/20 affiliate split, a mobile-friendly control panel, and an AI chatbot that runs ransom negotiations for non-English-speaking affiliates. A related leak site operating as Global Secret Group has separately claimed a disputed tally of over 202,000 victims.

8
Group Profile Majinahanashi Aug 25, 2026

Majinahanashi: New Japanese-Themed Ransomware Group Hits 18 Victims Since July

A newly identified ransomware operation branding itself Majinahanashi has claimed 18 victims across 12 countries since first activity in early July 2026, using a double-extortion model and .majin file encryption.

8
Campaign Alert Babuk-derived (.babyk) Aug 24, 2026

China-Nexus Actor Exploits Critical VMware vCenter Flaw to Deploy Babuk-Derived Ransomware

A suspected China-nexus threat actor weaponized CVE-2026-59310, a critical vCenter directory-traversal flaw, within five days of patch release, compromising 361 IPs across 47 countries and deploying Babuk-derived ransomware on ESXi hosts.

9
Intel Report Aug 23, 2026

'Ransom Busters': A Rogue Affiliate Is Re-Extorting Its Own Gangs' Victims

A threat actor calling itself Ransom Busters LTD is contacting ransomware victims before their breaches go public, posing as a recovery firm. GuidePoint Security assesses it is actually a rogue affiliate double-dipping on victims of DragonForce, Settra, and Anubis.

6