GRIT Blog

RansomSnub: RansomHub’s Affiliate Confusion
Executive Summary Since RansomHub’s emergence in early 2024, the group has become the most prolific Ransomware-as-a-Service group operating today. In […] ...

Breaking Basta: Insights from Black Basta’s Leaked Ransomware Chats
Key Takeaways During the period covered by the Black Basta leaked chat logs (18 September 2023 – 28 September 2024), […] ...

Snail Mail Fail: Fake Ransom Note Campaign Preys on Fear
In early March 2025, GRIT received reports from multiple organizations regarding suspicious physical letters delivered by mail from US addresses […] ...

GRIT’s 2025 Report: Ransomware Group Dynamics and Case Studies
Ransomware threats continue evolving, with the most successful groups refining their tactics to maximize impact over the last year. Understanding […] ...

GRIT’s 2025 Report: Annual Vulnerability Analysis and Exploitation Trends
2024 saw an unprecedented surge in vulnerability disclosures, with over 39,000 vulnerabilities published. While this reflects the industry’s commitment to […] ...

Ongoing report: Babuk2 (Babuk-Bjorka)
Editor’s note: We will continue to provide updates as further information is forthcoming. On January 27th, 2025, GuidePoint’s Research and […] ...

GRIT 2025 Report: Post-Compromise Detection Strategies
This blog marks the beginning of a series based on the findings in the GRIT 2025 Ransomware and Cyber Threat […] ...

RansomHub Affiliate leverages Python-based backdoor
In an incident response in Q4 of 2024, GuidePoint Security identified evidence of a threat actor utilizing a Python-based backdoor […] ...

Best of 2024: So-Phish-ticated Attacks
August 27, 2024 Authors: Rui Ataide, Hermes Bojaxhi The GuidePoint Research and Intelligence Team (GRIT) has been tracking a highly […] ...

To Pay or Not to Pay: The Ransomware Dilemma
Disclaimer: In the majority of cases, the determination of whether or not to pay a ransom is a business decision, […] ...