Why pure extortion is replacing traditional ransomware
2026-05-23T14:51:45Z•6a2ac9c6c4efcbbc5904100d62e9fe962cdfc40b1fc01907ca1f9568987063c0
APTApp-Store-fraudAppleC2-infrastructureCISACisco-Secure-WorkloadCobalt-StrikeDDoSFirst-VPNGhostwriterHunt.ioKimwolfKnown-Exploited-VulnerabilitiesMFA-bypassSonicWallUAC-0057UNC1151botnetdata-theftextortionhostinglaw-enforcementphishingpure-extortionransomware
What happened
Feed roundup: ransomware groups are shifting from system encryption to ‘pure extortion’ (data theft and leak threats). Belarus-linked APT Ghostwriter (UAC-0057 / UNC1151) resumed phishing against Ukrainian government targets using a legitimate e-learning service as bait, delivering malware and Cobalt Strike. Law enforcement seized First VPN and disrupted criminal infrastructure; a 23‑year‑old alleged Kimwolf botnet operator was arrested. Hunt.io mapped concentrated C2 hosting in the Middle East. CISA added multiple flaws to its Known Exploited Vulnerabilities catalog (including CVE-2025-34291)
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 6a2ac9c6c4efcbbc5904100d62e9fe962cdfc40b1fc01907ca1f9568987063c0
- Enrichment time
- 2026-05-23T14:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.