Unidentified ransomware
Type of ransomware remains unidentified
Type of ransomware remains unidentified
Vishing, or voice phishing, is a form of social engineering where cybercriminals use voice calls to impersonate trusted individuals or organizations to trick victims into revealing sensitive information, such as passwords or financial details.
Gunra ransomware, first identified in April 2025, has already compromised companies in the pharmaceutical, industrial and real estate sectors in countries including Japan, Egypt, Panama, Italy and Argentina. The program uses a double extortion strategy, in which sensitive data is extracted before encryption. If the victim refuses to pay the ransom, the operators threaten to publish the stolen data on underground forums.
Gunra is derived from the Conti ransomware code , but features significant improvements in evasion and persistence. After infection, it collects information about the environment, deletes shadow copies via WMI, scans the system, and injects code into trusted processes.
A ClickFix attack relies on malicious code on a webpage to display a prompt to the user, asking them to fix an error or perform a reCAPTCHA challenge, to prove they are human. When the user clicks on the prompt, a malicious command is copied to the clipboard, and the user is also instructed to perform keyboard combinations that open the Windows Run prompt, paste the copied command into the prompt, and execute it.
The social engineering technique has been used for a couple of years, but started gaining popularity among cybercriminals and APTs last year
ClickFix attacks have been adopted by a wide range of threat actors: Interlock and other ransomware gangs and North Korean hackers.
Fuxnet is malware designed to impact the industrial network infrastructure managing control system sensors for utility operations in Moscow.