Dark Web Profile: Orion Ransomware

Orion Ransomware is a newly observed operation whose public activity is limited to a data leak site listing 13 alleged victims and affiliate recruitment messaging rather than demonstrated ransomware development or independently verified intrusions. Analysis links the operator to prior reputation-driven extortion activity associated with Babuk2, indicating recycled leak material and low confidence in original operational capability. #Orion #Babuk2

Read More
deVixor: An Evolving Android Banking RAT with Ransomware Capabilities Targeting Iran

Cyble’s analysis describes deVixor, an evolving Android banking RAT distributed via fake automotive websites that deploy malicious APKs to Iranian users to harvest SMS-based financial data, capture credentials, perform keylogging, and surveil devices. The malware now includes WebView-based JavaScript injection, a remotely triggered ransomware module, and uses Telegram and Firebase for command-and-control and large-scale administration. #deVixor #IranianBanks

Read More
Amarillo College Panhandle Regional Law Enforcement Academy Allegedly Breached, Exposing 11,253 Event Registration Records

A threat actor named “zvezdanwastaken” has claimed to breach the Amarillo College Panhandle Regional Law Enforcement Academy, exposing over 11,000 event registration records. The compromised data includes personal information of law enforcement personnel from multiple Texas agencies. #zvezdanwastaken #DataBreach…

Read More
Best Ransomware Detection Tools

Intelligence-driven detection that combines endpoint/XDR, network detection, and threat intelligence enables earlier identification of ransomware precursor behaviors like reconnaissance, credential theft, and data staging before encryption occurs. Recorded Future and similar platforms strengthen detection by providing organization-specific, real-time context on active campaigns, attacker infrastructure, and vulnerabilities prioritized by what ransomware operators are actually exploiting. #LockBit #RecordedFuture

Read More
Horus Solucoes Integradas Breach Exposes Brazilian Municipal Tax Records

A major data breach involving Horus Soluções Integradas has leaked nearly 2 million records affecting municipal systems in Brazil, including personal and financial information. The leak targets the “ISS Web” service used by multiple cities, impacting taxpayers and local governments. #HorusSoluções #MinasGerais #ISSWeb #TaxDatabaseLeak #DarkWebThreats…

Read More