BKA Identifies REvil Leaders Behind 130 German Ransomware Attacks
2026-04-06T07:24:10Z•705dd93933394ea1e8e2e465323c749244bbfcbb8a6a9b1ae79557c42b80b196
CVE-2025-55182CVE-2026-20093CVE-2026-35616CVE-2026-5281ChromeCiscoDPRKFortiClient-EMSFortinetREvilUNC1069axioscookie-controlled-webshells','cron-persistencecredential-theftdriftlaw-enforcementmalicious-packagesnpmpersistent-implantphpransomwaresolanasupply-chainwebshellszero-day
What happened
A cluster of high-impact incidents and active campaigns was reported: German authorities identified alleged REvil/Sodinokibi leadership; a DPRK-linked, six‑month social‑engineering operation led to a $285M theft from Solana DEX Drift; multiple npm supply‑chain issues — including 36 malicious Strapi‑style packages and the Axios compromise attributed to UNC1069 — have enabled implants, credential theft and persistence; actively exploited high‑severity flaws were disclosed and patched (Fortinet FortiClient EMS pre‑auth privilege escalation, Cisco IMC/SSM remote auth bypass) and Google fixed a Web
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 705dd93933394ea1e8e2e465323c749244bbfcbb8a6a9b1ae79557c42b80b196
- Enrichment time
- 2026-04-06T07:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.