RansomSnub: RansomHub’s Affiliate Confusion

RansomSnub: RansomHub’s Affiliate Confusion

Executive Summary Since RansomHub’s emergence in early 2024, the group has become the most prolific Ransomware-as-a-Service group operating today. In […] ...
Breaking Basta: Insights from Black Basta’s Leaked Ransomware Chats

Breaking Basta: Insights from Black Basta’s Leaked Ransomware Chats

Key Takeaways During the period covered by the Black Basta leaked chat logs (18 September 2023 – 28 September 2024), […] ...
Snail Mail Fail: Fake Ransom Note Campaign Preys on Fear

Snail Mail Fail: Fake Ransom Note Campaign Preys on Fear

In early March 2025, GRIT received reports from multiple organizations regarding suspicious physical letters delivered by mail from US addresses […] ...
GRIT’s 2025 Report: Ransomware Group Dynamics and Case Studies

GRIT’s 2025 Report: Ransomware Group Dynamics and Case Studies

Ransomware threats continue evolving, with the most successful groups refining their tactics to maximize impact over the last year. Understanding […] ...
GRIT’s 2025 Report: Annual Vulnerability Analysis and Exploitation Trends

GRIT’s 2025 Report: Annual Vulnerability Analysis and Exploitation Trends

2024 saw an unprecedented surge in vulnerability disclosures, with over 39,000 vulnerabilities published. While this reflects the industry’s commitment to […] ...
Ongoing report: Babuk2 (Babuk-Bjorka)

Ongoing report: Babuk2 (Babuk-Bjorka)

Editor’s note: We will continue to provide updates as further information is forthcoming. On January 27th, 2025, GuidePoint’s Research and […] ...
GRIT 2025 Report: Post-Compromise Detection Strategies

GRIT 2025 Report: Post-Compromise Detection Strategies

This blog marks the beginning of a series based on the findings in the GRIT 2025 Ransomware and Cyber Threat […] ...
RansomHub Affiliate leverages Python-based backdoor

RansomHub Affiliate leverages Python-based backdoor

In an incident response in Q4 of 2024, GuidePoint Security identified evidence of a threat actor utilizing a Python-based backdoor […] ...
Best of 2024: So-Phish-ticated Attacks

Best of 2024: So-Phish-ticated Attacks

August 27, 2024 Authors: Rui Ataide, Hermes Bojaxhi The GuidePoint Research and Intelligence Team (GRIT) has been tracking a highly […] ...
To Pay or Not to Pay: The Ransomware Dilemma

To Pay or Not to Pay: The Ransomware Dilemma

Disclaimer: In the majority of cases, the determination of whether or not to pay a ransom is a business decision, […] ...