#Ransomexx
Ejército del Perú 2 (711.39 GB)

Over 130,000 documents and other files from Ejército del Perú (Peruvian Army).

ddosecrets.org/article/ejer...

Help us keep publishing: donorbox.org/ddosecrets
Ejército del Perú 2 - Distributed Denial of Secrets
Over 130,000 documents and other files from Ejército del Perú (Peruvian Army). The data was originally hacked and released by the ransomware group RansomEXX. Reference Peruvian Army (Wikipedia…
ddosecrets.org
May 16, 2026 at 7:02 PM
Microsoft says the RansomEXX ransomware gang has been exploiting a high-severity zero-day flaw in the Windows Common Log File System to gain SYSTEM privileges on victims' systems.
Microsoft: Windows CLFS zero-day exploited by ransomware gang
Microsoft says the RansomEXX ransomware gang has been exploiting a high-severity zero-day flaw in the Windows Common Log File System to gain SYSTEM privileges on victims' systems.
www.bleepingcomputer.com
April 8, 2025 at 7:05 PM
Microsoft Windows Vulnerability Exploited to Deploy PipeMagic RansomExx Malware
Microsoft Windows Vulnerability Exploited to Deploy PipeMagic RansomExx Malware
thehackernews.com
August 18, 2025 at 8:14 PM
Microsoft says the RansomEXX ransomware gang has been exploiting a high-severity zero-day flaw (CVE-2025-29824) in the Windows Common Log File System to gain SYSTEM privileges on victims' systems.

www.bleepingcomputer.com/news/securit...
Microsoft: Windows CLFS zero-day exploited by ransomware gang
Microsoft says the RansomEXX ransomware gang has been exploiting a high-severity zero-day flaw in the Windows Common Log File System to gain SYSTEM privileges on victims' systems.
www.bleepingcomputer.com
April 8, 2025 at 7:12 PM
🚨 Ransomexx Ransomware Alert 🚨

Makesworth Accountants 🇬🇧

Makesworth Accountants, a UK-based firm specialising in providing expert accounting and business service, falls victim to Ransomexx Ransomware.

#UK
#Ransomware #Ransomexx #Infosec #DarkWeb
February 9, 2025 at 2:58 PM
Microsoft Windows Vulnerability Exploited to Deploy PipeMagic RansomExx Malware ift.tt/CwK9ksL
Microsoft Windows Vulnerability Exploited to Deploy PipeMagic RansomExx Malware
PipeMagic exploits CVE-2025-29824 in Windows, enabling RansomExx attacks in Saudi Arabia and Brazil.
buff.ly
August 18, 2025 at 10:12 PM
🚨 Ransomexx Ransomware Alert 🚨

Lakeshore Title Agency 🇺🇸

Lakeshore Title Agency, a real estate company , based in USA, has fallen victim to Ransomexx Ransomware. The group claims to have obtained 341 GB of organization's data.
January 31, 2025 at 5:17 PM
📢 Ransomware Alert:

ADDA.io (adda.io), a software development company, based in USA, has been listed as a victim of the Ransomexx Ransomware.

Key Details:

📅 Published Date: March 7, 2025
🛡Threat Actor: Ransomexx
March 7, 2025 at 5:26 PM
SEO poisoning ➡️ Fake RVTools ➡️ Python backdoor ➡️ PipeMagic ➡️ CVE-2025-29824 ➡️ #Ransomexx — domain-wide in <19 hrs.

The Python backdoor connected to azure-secure-agent[.]com (87.251.67[.]241), enabling cmd/PowerShell exec, payload download, screenshots, and IP discovery.
February 19, 2026 at 2:51 PM
#Microsoft Windows Vulnerability Exploited to Deploy PipeMagic RansomExx Malware

Researchers have lifted the lid on the threat actors' exploitation of a now-patched security flaw in #Windows to deploy the PipeMagic #malware in RansomExx #ransomware attacks!

thehackernews.com/2025/08/micr...
Microsoft Windows Vulnerability Exploited to Deploy PipeMagic RansomExx Malware
PipeMagic exploits CVE-2025-29824 in Windows, enabling RansomExx attacks in Saudi Arabia and Brazil.
thehackernews.com
August 18, 2025 at 9:08 PM
Pipemagic: troyano que explota una vulnerabilidad ZeroDays en Windows para implementar el ransomware RansomExx
Pipemagic: troyano que explota una vulnerabilidad ZeroDays en Windows para implementar el ransomware RansomExx
blog.segu-info.com.ar
August 19, 2025 at 4:54 AM
#RansomExx is a ransomware family that targeted multiple companies starting in mid-2020. It shares commonalities with Defray777.

Newest entry:

"TUV Rheinland AG Post will be available soon… Leaked data size: 650GB."
#Ransomware #TÜV
www.ransomlook.io/group/ransom...
July 2, 2024 at 8:51 PM
Microsoft Windows Vulnerability Exploited to Deploy PipeMagic RansomExx Malware #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
August 18, 2025 at 9:05 PM
Microsoft Windows Vulnerability Exploited to Deploy PipeMagic RansomExx Malware

Cybersecurity researchers have lifted the lid on the threat actors' exploitation of a now-patched security flaw in Microsoft Windows to deploy the PipeMagic malware in RansomExx ransomware…

#hackernews #microsoft #news
Microsoft Windows Vulnerability Exploited to Deploy PipeMagic RansomExx Malware
Cybersecurity researchers have lifted the lid on the threat actors' exploitation of a now-patched security flaw in Microsoft Windows to deploy the PipeMagic malware in RansomExx ransomware attacks. The attacks involve the exploitation of CVE-2025-29824, a privilege escalation vulnerability impacting the Windows Common Log File System (CLFS) that was addressed by Microsoft in April 2025,
thehackernews.com
August 19, 2025 at 1:11 PM
Why is Microsoft now calling the RansomExx ransomware group Storm-2460 (the name of a snowblower), when they previously called it Tomato Tempest? www.bleepingcomputer.com/news/securit...
Microsoft: Windows CLFS zero-day exploited by ransomware gang
Microsoft says the RansomEXX ransomware gang has been exploiting a high-severity zero-day flaw in the Windows Common Log File System to gain SYSTEM privileges on victims' systems.
www.bleepingcomputer.com
April 9, 2025 at 2:14 PM
🇮🇹CYBERSEC

La région de Lazio en Italie a subi une attaque par ransomware RansomEXX qui a désactivé les systèmes informatiques de la région, y compris le portail d'enregistrement de la vaccination COVID-19.

bleepingcomputer.com/news/security/…
November 30, 2024 at 2:39 AM
Microsoft says the RansomEXX ransomware gang has been exploiting a high-severity zero-day flaw in the Windows Common Log File System to gain SYSTEM privileges on victims' systems.
Microsoft: Windows CLFS zero-day exploited by ransomware gang
www.bleepingcomputer.com
April 9, 2025 at 5:26 PM
🚨 Ejército del PerU
🌍 ransomfeed.it/index.php?pa...

🚨 Ministry of Defense of Peru
🌍 ransomfeed.it/index.php?pa...

Same country 🇵🇪, different groups.
#incransom claimed to have exfiltrated 502GB (Ejército) while #ransomexx stated they stole 763.8GB (Ministry).
March 26, 2024 at 8:44 PM
SPURR, aka Gold Dupont, Sprite Spider, Hive-0091; operators of Vatet loader, PyXie, Shifu, and Defray777, aka RansomExx. But I can't seem to find where the SPURR name or its association came from, apart from some cached online threat actor lists that seem to have dropped it.
April 9, 2025 at 2:45 PM
AI has shrunk exploit development from months to hours, making patch-first defense too slow. TTP-chain validation and control-aware testing can prove real exposure even when no exploit exists. #PicusSecurity #OpenBSD #CVE202529824
The Exploit Doesn't Exist. You Can Still Prove It Works Against You
AI has collapsed the disclosure-to-exploit window from months to hours, making traditional vulnerability management and patch-first approaches too slow to keep up. The article argues for TTP-chain validation and control-aware testing to determine what is actually exploitable in an environment, with Picus Security positioning this as a better way to prove risk than live exploitation alone. #PicusSecurity #CVE-2025-29824 #OpenBSD #Storm2460 #RansomEXX #Anthropic #Mythos
www.hendryadrian.com
June 23, 2026 at 3:15 PM
Notícia da BleepingComputer

"Microsoft: Windows CLFS zero-day exploited by ransomware gang" #bolhasec
Microsoft: Windows CLFS zero-day exploited by ransomware gang
Microsoft says the RansomEXX ransomware gang has been exploiting a high-severity zero-day flaw in the Windows Common Log File System to gain SYSTEM privileges on victims' systems.
www.bleepingcomputer.com
July 3, 2025 at 2:30 AM