Why pure extortion is replacing traditional ransomware

2026-05-23T14:51:45Z6a2ac9c6c4efcbbc5904100d62e9fe962cdfc40b1fc01907ca1f9568987063c0
APTApp-Store-fraudAppleC2-infrastructureCISACisco-Secure-WorkloadCobalt-StrikeDDoSFirst-VPNGhostwriterHunt.ioKimwolfKnown-Exploited-VulnerabilitiesMFA-bypassSonicWallUAC-0057UNC1151botnetdata-theftextortionhostinglaw-enforcementphishingpure-extortionransomware

What happened

Feed roundup: ransomware groups are shifting from system encryption to ‘pure extortion’ (data theft and leak threats). Belarus-linked APT Ghostwriter (UAC-0057 / UNC1151) resumed phishing against Ukrainian government targets using a legitimate e-learning service as bait, delivering malware and Cobalt Strike. Law enforcement seized First VPN and disrupted criminal infrastructure; a 23‑year‑old alleged Kimwolf botnet operator was arrested. Hunt.io mapped concentrated C2 hosting in the Middle East. CISA added multiple flaws to its Known Exploited Vulnerabilities catalog (including CVE-2025-34291)

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
6a2ac9c6c4efcbbc5904100d62e9fe962cdfc40b1fc01907ca1f9568987063c0
Enrichment time
2026-05-23T14:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Why pure extortion is replacing traditional ransomware · Baitaphish