Emulating the Gentlemen Ransomware

Emulating the Gentlemen Ransomware

AttackIQ has released two new assessments that emulate the behaviors of The Gentlemen ransomware, a cross-platform threat that emerged around July 2025. The group employs a double-extortion model, combining file encryption with ...
Emulating the Persuasive NightSpire Ransomware

Emulating the Persuasive NightSpire Ransomware

AttackIQ has released a new attack graph that emulates the behaviors of NightSpire Ransomware, a financially motivated ransomware and data extortion group that emerged in early 2025 and quickly evolved into a ...
Emulating the Concealed Sinobi Ransomware

Emulating the Concealed Sinobi Ransomware

AttackIQ has released a new attack graph that emulates the behaviors of Sinobi ransomware, a ransomware strain that has been active since mid 2025. Sinobi is suspected to be a rebrand of ...
Defenseless Defenders: Exploring Endpoint Detection and Response (EDR) Inhibitors

Defenseless Defenders: Exploring Endpoint Detection and Response (EDR) Inhibitors

Learn how adversaries are shifting from evasion to systematically dismantling endpoint defenses to eliminate visibility, enforcement, and response. Explore how modern EDR inhibition techniques abuse legitimate system features and vulnerable drivers to ...
Emulating the Systematic LokiLocker Ransomware

Emulating the Systematic LokiLocker Ransomware

AttackIQ has released a new attack graph that emulates the behaviors of LokiLocker ransomware, a .NET based strain active since at least mid-August 2021. The malware combines defense evasion and impact techniques, ...
The “Analog Panic Button”: What The Pitt Gets Right (and Wrong) About Hospital Cyber Resilience

The “Analog Panic Button”: What The Pitt Gets Right (and Wrong) About Hospital Cyber Resilience

When ransomware hits a hospital, shutting everything down isn’t resilience. Learn how healthcare CISOs prevent hospital-wide outages with identity security, network segmentation validation, and CTEM. The post The “Analog Panic Button”: What ...
Emulating the Mutative BlackByte Ransomware

Emulating the Mutative BlackByte Ransomware

AttackIQ has released a new attack graph that emulates the behaviors exhibited by BlackByte ransomware, a strain operated under the Ransomware-as-a-Service (RaaS) model that emerged in July 2021. Since its emergence, BlackByte ...
Emulating the Elusive Cephalus Ransomware

Emulating the Elusive Cephalus Ransomware

AttackIQ has released a new attack graph that emulates the behaviors of Cephalus ransomware, a Go-based strain active since June 2025 that combines defense-evasion and anti-analysis techniques, such as secure memory handling ...
Emulating the Elegant BlackSuit Ransomware

Emulating the Elegant BlackSuit Ransomware

AttackIQ has released a new attack graph that emulates the behaviors exhibited by BlackSuit ransomware, a ransomware strain that has been active since at least May 2023. It represents the evolution of ...

React2Shell (CVE-2025-55182): Critical Remote Code Execution (RCE) in React Server Components

AttackIQ released a new assessment template that compiles the Tactics, Techniques, and Procedures (TTPs) associated with the exploitation of the critical CVE-2025-55182 (React2Shell) Remote Code Execution (RCE) vulnerability affecting React Server Components ...