Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationendpoint-security-bypassphishing-campaign-intelligenceremote-access-implant

Recent Ransomware and Malware Campaigns Targeting Organizations and Individuals

Updated 3mo agoFirst seen Dec 10, 20256 sources

A surge in sophisticated cyberattacks has been observed, with threat actors employing a variety of tactics to compromise organizations and individuals. Notable incidents include the use of the BYOVD (Bring Your Own Vulnerable Driver) technique to deploy DeadLock ransomware, as well as targeted campaigns leveraging phishing emails with HR-related lures to distribute Remcos RAT malware. Additionally, attackers are exploiting popular movie torrents to spread Agent Tesla via layered PowerShell scripts, and Android users in Spain are being targeted by the DroidLock ransomware, which can hijack devices and demand ransom through full-screen overlays. These campaigns demonstrate a trend toward multi-stage infection chains, abuse of legitimate tools and drivers, and the use of social engineering to increase the likelihood of successful compromise.

Other significant developments include the targeting of Canadian organizations by the STAC6565/Gold Blade group using QWCrypt ransomware, and the emergence of new threat actor tactics such as disabling endpoint detection and response (EDR) systems to facilitate ransomware deployment. The threat landscape is further complicated by the activities of groups like Scattered Lapsus$ Hunters, who use social engineering and typosquatted domains to compromise Zendesk users, and the exposure of internal dynamics within ransomware groups like BlackBasta, revealing operational stress and internal mistrust. These incidents underscore the evolving nature of cyber threats, the blending of espionage and financial motives, and the increasing sophistication of both technical and social attack vectors.

Share:
Recent Ransomware and Malware Campaigns Targeting Organizations and Individuals
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Dec 10, 20256mo ago

CSO highlights BlackBasta leak and BlackLock recruitment as cybercrime case studies

CSO Online published case studies describing the BlackBasta internal chat leak as evidence of leadership conflict and operational dysfunction, and BlackLock's recruitment of traffers on Russian-language forums and Telegram as a sign of outsourced initial access in ransomware operations. The article framed these developments as examples of increasingly modular and specialized cybercrime ecosystems.

Bitdefender uncovers fake movie torrent campaign spreading Agent Tesla

Bitdefender researchers uncovered a campaign using a fake torrent for Leonardo DiCaprio's film 'One Battle After Another' to deliver Agent Tesla through a layered, fileless PowerShell chain. The attack hid malicious code in subtitle and image files, used legitimate Windows tools, and created a scheduled task for persistence.

Dec 9, 20257mo ago

Researchers detail STAC6565's shift to QWCrypt ransomware

Security researchers reported that STAC6565, overlapping with Gold Blade, had evolved from phishing-led commercial espionage into selective QWCrypt ransomware deployment. The campaign used weaponized resumes, custom tools such as RedLoader and Terminator, BYOVD attacks, sideloading, hypervisor targeting, and delayed encryption in some cases to monetize stolen data first.

Researchers observe layoff-themed phishing delivering Remcos RAT

Seqrite Labs reported a phishing campaign using fake internal HR layoff notices and a disguised RAR attachment to install Remcos RAT. The malware established persistence through the Run key and enabled keylogging, screenshot capture, clipboard monitoring, and C2 communication.

Actor uses new BYOVD loader in DeadLock ransomware intrusions

Talos observed a financially motivated actor deploying DeadLock ransomware in Windows environments using a previously unknown loader and a BYOVD technique exploiting Baidu Antivirus driver flaw CVE-2024-51324 to kill EDR processes. The intrusions also involved compromised accounts, RDP enablement, AnyDesk installation, discovery, lateral movement, and anti-forensics before encryption.

Dec 8, 20257mo ago

Scattered Lapsus$ Hunters targets Zendesk users with typosquatting and fake tickets

KnowBe4 reported that Scattered Lapsus$ Hunters was actively targeting organizations using Zendesk by registering more than 40 lookalike domains and hosting phishing pages such as fake SSO portals. The group also submitted fraudulent tickets to real Zendesk portals in an effort to infect help-desk staff with remote access trojans and steal data for extortion.

Jul 1, 20251y ago

DeadLock ransomware becomes active

Cisco Talos said the DeadLock ransomware operation has been active since at least July 2025. The malware appends a .dlock extension, changes file icons and wallpaper, and directs victims to negotiate over Session messenger rather than a leak site.

Mar 1, 20251y ago

Microsoft patches two Windows flaws reportedly disclosed by EncryptHub

Microsoft patched two Windows vulnerabilities in March 2025 that CSO Online says were responsibly disclosed by the actor known as EncryptHub. The case was highlighted as an example of a hybrid cybercriminal persona involved in both malicious activity and vulnerability reporting.

Feb 1, 20242y ago

STAC6565 begins focused campaign against Canadian organizations

A financially motivated threat cluster tracked as STAC6565 began a concentrated intrusion campaign in February 2024, primarily targeting organizations in Canada, with additional victims in the U.S., Australia, and the U.K. The activity affected sectors including services, manufacturing, retail, technology, NGOs, and transportation.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

51 LINKEDOpen in app
Affected products
6 linked
TelegramChatgptChatgptWinrarWinrarWindows
Organizations
26 linked
Microsoft CorporationBitdefenderShutterstockBlack BastaEncryptHubBlackLockSalesforceNullsoftVmwareSeqriteZendeskScattered Lapsus$ HuntersIndeedCloudflareeSentireKnowbe4ReliaQuest7-ZipAdobeHuntressGroup-IBSophosZemanaSTAC6565ADP WorkforceNowJazzHR
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Recent Ransomware and Malware Campaigns Targeting Organizations and Individuals | Mallory