BKA Identifies REvil Leaders Behind 130 German Ransomware Attacks

2026-04-06T07:24:10Z705dd93933394ea1e8e2e465323c749244bbfcbb8a6a9b1ae79557c42b80b196
CVE-2025-55182CVE-2026-20093CVE-2026-35616CVE-2026-5281ChromeCiscoDPRKFortiClient-EMSFortinetREvilUNC1069axioscookie-controlled-webshells','cron-persistencecredential-theftdriftlaw-enforcementmalicious-packagesnpmpersistent-implantphpransomwaresolanasupply-chainwebshellszero-day

What happened

A cluster of high-impact incidents and active campaigns was reported: German authorities identified alleged REvil/Sodinokibi leadership; a DPRK-linked, six‑month social‑engineering operation led to a $285M theft from Solana DEX Drift; multiple npm supply‑chain issues — including 36 malicious Strapi‑style packages and the Axios compromise attributed to UNC1069 — have enabled implants, credential theft and persistence; actively exploited high‑severity flaws were disclosed and patched (Fortinet FortiClient EMS pre‑auth privilege escalation, Cisco IMC/SSM remote auth bypass) and Google fixed a Web

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
705dd93933394ea1e8e2e465323c749244bbfcbb8a6a9b1ae79557c42b80b196
Enrichment time
2026-04-06T07:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.