- Services
- Products
-
-
- Online Training
- Information Security Awareness Training Course
- PCI DSS Compliance Bundle
- GLBA Awareness Training Course
- CMMC Training Course
- HIPAA Awareness Training Course
- Data Privacy Training Course
- Payments Security Training Course
- Phishing Awareness Training Course
- GDPR Training Course
- FERPA Training Course
- FACTA Training Course
- Online Training
-
- Compliance
- Markets
- Insights
- About
Threat Intel Update
This week’s reporting points to a clear trend: cybercriminals are scaling up and building in resilience. Ransomware remains dominant; Medusa’s victim count has grown from 300 to over 500 U.S. critical infrastructure organizations, while affiliate group Ransom Busters is now re-extorting victims after initial attacks.
Threat actors are also investing in infrastructure: some buy expired domains to inherit trust and hide malicious activity, while botnets like Kimwolf shift to blockchain- and Tor-based command channels to resist takedowns. Cloud identity is a prime target too. The alleged Azure/Entra data theft tied to “TheHatman” shows how stolen identity data fuels phishing, BEC, and privilege escalation.
The common thread: attackers abuse trusted platforms and identities while building redundancy, making them harder to detect and quicker to recover from takedowns.
Cybersecurity News
- Medusa Ransomware Surpasses 500 U.S. Critical Infrastructure Victims – CISA, the FBI, and HHS report that Medusa ransomware has hit over 500 U.S. critical infrastructure organizations as of April 2026, up from roughly 300 a year earlier. Hardest-hit sectors include healthcare, defense, manufacturing, government, IT, and finance. The group’s affiliate-based model lowers the barrier to entry, and its data-leak site adds extortion pressure on top of operational disruption. BleepingComputer
- “Ransom Busters” Runs Fake Rescue Scam on Ransomware Victims – A threat actor calling itself Ransom Busters is contacting ransomware victims, falsely posing as a third party who can delete their stolen data for a fee of $20,000–$60,000. Researchers believe it’s actually a ransomware affiliate exploiting insider access, meaning victims face a second extortion attempt with no real guarantee their data is deleted. The Hacker News
- Criminals Spend Millions Buying Expired Domains to Mask Malware – Threat actors are snapping up expired domains to inherit their trust and traffic, then repurposing them for scams, illegal streaming, and malware command-and-control. One actor alone has spent nearly $7 million on over 10,000 domains. Because these domains often host both legitimate-looking content and malicious infrastructure at once, blocking them risks disrupting real services too. The Hacker News
- Kimwolf Botnet Returns with Blockchain-Based, Takedown-Resistant Infrastructure – Rebuilt just weeks after a law enforcement takedown, the Kimwolf botnet now uses Ethereum-based command channels and a Tor fallback, making it far harder to disrupt through domain seizures. It also disguises attack traffic as Chrome browser activity, undermining traditional bot-detection methods. CyberScoop
- Stolen Azure Directory Data Tied to Major Global Enterprises – A threat actor known as “TheHatman” is selling Azure and Entra directory data allegedly stolen from at least nine Fortune 500 companies, including McDonald’s, TCS, and Vodafone. The leaked data, covering admin accounts, org structure, and employee IDs, could enable phishing, business email compromise, and privilege escalation against those organizations. SecurityWeek
Sign Up
To receive Threat Briefings by email.