Threat Research

    The StopRansomware: Akira Ransomware advisory warns of Akira’s expanding operations, including new activity as of Nov. 13, 2025, targeting Windows, Linux, and virtualization platforms....
    Bumblebee malware has been used for initial access since 2021, with SEO poisoning reported as a delivery method in 2023. In 2025, campaigns impersonating IT tools delivered trojanized software, leading to Bumblebee infections and Akira ransomware deployment. Threat actors leveraged this access to move laterally, steal credentials, install persistent tools, and exfiltrate data....
    Akira continues to establish itself as one of the most significant ransomware operations, as highlighted by Cisco Talos' findings. Their ongoing evolution contributes to their success; after releasing a new version of their encryptor earlier this year, they have introduced another iteration that targets both Windows and Linux systems....
    Looking for Something?
    Threat Research Categories:
    Tags