Non-profit offers $22,000 bounty for INC ransomware group | #ransomware | #cybercrime


This newsletter is brought to you by application allow-listing software maker Airlock Digital. You can subscribe to an audio version of this newsletter as a podcast by searching for “Risky Business” in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here.

An international crime-fighting non-profit organization is offering a $22,000 bounty for any information on members of the INC ransomware group.

To be eligible for a payout, the provided information must lead to the identification, arrest, or disruption of the gang’s operations.

Crime Stoppers International is the international branch of Crime Stoppers, a US foundation that was established in the 70s to allow anonymous and private individuals to provide aid in US law enforcement investigations that may lack manpower or resources.

In a PDF file released this month, Crime Stoppers cited the ransomware group’s repeated attacks on healthcare and critical infrastructure organizations as the reason for its bounty.

“INC Ransom shows no restraint against hospitals, healthcare providers, or critical services,” the org wrote. “Their victims include organizations whose disruption puts real people at risk. This is not a victimless financial crime.”

The non-profit is specifically seeking information on INC members, their location, their movement, contacts, their crypto-wallets, money trail, server infrastructure, and information on the group’s internal structure and comms.

According to recent reports from the NCC Group and Point Wild, the INC ransomware group was the sixth most active ransomware group in the month of June and the sixth most active ransomware group in Q2.

It has also repeatedly ranked in the Top 10 most active ransomware group reports since its emergence back in 2023.

Last year, security firm Cyber Centaurs infiltrated an INC backup server, retrieved a stolen (unencrypted) files, and helped a dozen victims recover their data without paying ransoms.

via Point Wild

Risky Business Podcasts

The main Risky Business podcast is now on YouTube with video versions of our recent episodes. Below is our latest weekly show with Pat, James, and special guest co-host Pete Ranks at the helm!


Breaches, hacks, and security incidents

OpenAI-Hugging Face hack: Both OpenAI and Hugging Face have published more details about their hack, with Hugging Face releasing a web widget that reproduces the hack step-by-step. The most interesting tid-bit from the OpenAI report is that the rogue model used credentials to access accounts at four other services while trying to reach Hugging Face. One of them has been identified as Modal Labs. [OpenAI // Hugging Face // Reuters]

Adform hacked to spread malware: A hacker has compromised online advertising company Adform to deploy a cryptocurrency stealer. The malicious code has been live in one of Adform’s JavaScript files for at least a week. The code hijacks a user’s clipboard and browser to replace cryptocurrency addresses copy-pasted or entered in web forms. [DoublePulsar]

Post by @hacksilon@infosec.exchange

View on Mastodon

Unitel cyberattack: A cyberattack has disrupted mobile services and internet access at Angola’s largest telco. The attack hit Unitel hours before its IPO. The state-owned operator has more than 21 million customers, serving more than half the country’s population. [Reuters]

SplitVPN leak: A hacker is selling the data of SplitVPN (formerly NotVPN), a Russian VPN provider used by locals to bypass the Kremlin’s internet blocks. The stolen data includes details on more than 23 million customers. It also includes browsing data, something the company said it wouldn’t collect. [MysteriumVPN]

CubePilot DNS hijacking event: A DNS hijacking attack has CubePilot, an Australian company that makes flight controllers for drones and UAVs. The incident took place last week. CubePilot has urged all customers who authenticated recently on its websites to change passwords. The company is currently auditing the integrity of its drone controller firmware. [CubePilot // BleepingComputer]

KT fined for breach: South Korean authorities have fined telecom provider KT 54 billion won ($37.43 million) for 2024 and 2025 security incidents. Hackers planted malware on KT’s servers and stole the information of more than 16,000 subscribers. The fine was because the company tried to hide the breach from authorities. [SBS News]

Analog Devices hack: American semiconductor company Analog Devices has disclosed a security breach. The company says hackers breached its network at the end of June and stole sensitive files. Analog Devices’ name was briefly listed on the dark web leak site of a new group called ExfilSquad. [SEC filing // SecurityWeek]

CareCloud breach: US health tech giant CareCloud is notifying users that their medical records were stolen in a breach earlier this year. The breach took place in March and impacted more than 350,000 patients. The data was stolen from one of the company’s six electronic health record data storage servers. [TechCrunch]

Minnesota water hacks update: As it was widely expected, sources inside the US government have hinted that Iran may be behind the recent hack of more than 30 water utilities across Minnesota. [NYT]

UK DfE breach: Hackers have breached the UK Department of Education and are now trying to extort the agency. A group named ExfilSquad claims to be in possession of 600,000 records containing names, email addresses, and phone numbers. The data was allegedly stolen from two web portals, with one of them being the agency’s help desk. The group also claims to have breached the UK Police National Legal Database and even Microsoft. [The Record // The Guardian // CyFirma]

AI, general tech, and privacy

Anthropic claims it cracked encryption algorithms: Anthropic claims its Claude Mythos AI model cracked two cryptographic algorithms, AES and HAWK. [Anthropic // Matthew Green]

Frontier AI employees call for more oversight: More than 1,200 employees at major AI companies have signed an open letter urging the US government to support ​an international effort to regulate AI advancements. Signatories include high-ranking executives from Anthropic, OpenAI, Google, and Meta. Employees argue that safety and security are lagging behind new features and capabilities being shipped out. [Pacing the Frontier]

MCP update: The MCP protocol has received a new update after almost 9 months without any new development. [MCP blog]

Chrome 151: Google has released version 151 of its Chrome browser. See here for security patches and webdev-related changes. The biggest change in this release is the removal of support for macOS 12 and a new profile creation process.

WhatsApp Web Calling: Meta has added support for WhatsApp calling in the app’s web interface, meaning it’s now a valid and dangerous rival to Zoom and Google Meet. [Meta]

EU extends DSA to Roblox and ChatGPT: The EU says the Roblox video game and the ChatGPT AI service now fall under the provisions of the EU Digital Services Act. [TheNextWeb]

Australia to investigate Telegram: The Australian government has started a legal action against Telegram over its content moderation failures. Australia’s eSafety Commissioner claims Telegram failed to remove videos of violent extremists, mass shootings, and executions for weeks on end. If found guilty, the platform risks a fine of up to AU$54.6 million. [eSafety Commissioner]

Russia blocks Bip and KakaoTalk: Turkish messenger Bip and South Korean messenger KakaoTalk have stopped working in Russia about the same time authorities charged Durov. Something, something, ban all IM services until citizens use the state-owned MAX, bla bla. [CurrentTime]

Russia charges Telegram founder: The Russian government has charged and issued an international arrest warrant for Telegram founder Pavel Durov. Durov has been charged with “complicity in terrorism.” The FSB intelligence service says Telegram failed to remove channels used by Ukraine’s intelligence agencies to recruit saboteurs. It also failed to remove channels used by scammers and extremist organizations. Durov said the charges are politically motivated in order to ban the entire app inside Russia. The Russian Prosecutor General is also seeking to designate Telegram an extremist organization and have it banned in Russia. [FSB // Euronews]

Russian media report that the Russian Prosecutor General’s Office has filed a lawsuit with the Supreme Court seeking to have Telegram designated as an “extremist” platform and to ban its operations.

[image or embed]

— WarTranslated (Dmitri) (@wartranslated.bsky.social) July 30, 2026 at 3:14 PM

Government, politics, and policy

US bans foreign robots and power inverters: The US government has banned the import of foreign-made robots and power inverters on the grounds of national security. The ban applies to advanced humanoid and four-legged robots as well as power inverters used with solar panels and large-scale batteries. Most of these products are produced and imported from China. [FCC]

New ODNI chief: The US Senate confirmed Jay Clayton as the next Director of National Intelligence. Clayton replaces Tulsi Gabbard, who resigned in May. Trump ally Bill Pulte is currently serving as interim chief and recently announced a 30% cut to the ODNI staff. [The Record]

Saudi Arabia blocks Tinder: Early reporting seems to suggest that Saudi Arabia might have blocked dating app Tinder. [OONI]

‼️ Saudi Arabia just blocked Tinder
explorer.ooni.org/findings/305…

Today, OONI data shows that Tinder started being blocked on Mobily (AS35819) by means of TLS interference.

We were alerted of this block through our new Censorship Alert System, an internal prototype we’re testing. 🙏🐙

#ooni

[image or embed]

— OONI (@ooni.org) July 29, 2026 at 9:13 PM

In this Risky Business sponsor interview, James Wilson chats with Airlock Digital co-founders David Cottingham and Daniel Schell about how attackers are using LLMs to enumerate EDR detections. 

Arrests, cybercrime, and threat intel

Romance scammer sentenced to 85 months: The US has sentenced a Ghanaian national to 85 months in prison for stealing more than $10 million via romance scams. Derrick van Yeboah stole $4.2 million just from two victims alone, two women from Delaware and Ohio. He also engaged in BEC schemes targeting businesses. [DOJ]

Applicant gets a second chance after hacking universities: An Indian teen hacked and defaced two Indian universities after he was denied admission to their cybersecurity programs. Defacement messages asking for a second chance were left on the homepages of the Kanpur and Madras institutes of technology. Instead of jail time, the Kanpur university has now invited the teen to a hackathon as part of a future admission process. [The Times of India]

New AUR supply chain attack: A new supply chain attack has hit the Arch Linux community and its AUR third-party package repository. A threat actor adopted dozens of abandoned packages to add malware to their code. The AUR repository disabled package adoption on Thursday to deal with the new attack. A similar attack hit the AUR repository in June when hackers hijacked almost 2,000 Arch Linux packages to deploy rootkits and infostealers. [IFIN // Arch Linux]

SonicWall cred-stuffing attacks: A credentials stuffing attack is targeting SonicWall VPN and firewall devices. The recent attack wave started on July 25. According to security firm Huntress, at least 30 organizations have had devices compromised so far. [Huntress]

Public exposure problem: The Aryon team has an interesting report on how threat actors are so good at finding exposed data that even if cloud security tools identify and help secure misconfigured items within 24 hours, the data is often stolen even before that. [Aryon]

Dangling DNS is everywhere: SilentPush analyzed 12,500 domains across four industry verticals and found 16,000 dangling subdomains, with more than 4,000 being susceptible to automated takeover. [SilentPush]

AI hacking campaign: Last week, Hunt Intelligence spotted a threat actor using AI to hack Thailand’s Ministry of Finance. Palo Alto’s security team has now published more details about that entire campaign, which is apparently the work of a threat actor going by knaithe and KnYuan. While several AI services were used, DeepSeek appears to have done most of the heavy duty work. [PAN]

Malware technical reports

SparkKitty: Check Point’s CyberInt looks at SparkKitty, the Android and iOS infostealer discovered by Kaspersky last year that uses OCR to extract crypto-wallet seed phrases from images. Per CyberInt, new samples have been discovered in the wild as recently as April this year. [CyberInt]

Vanta Stealer: There’s another new infostealer making the rounds. I think we have more infostealer strains active right now than any other kind of malware. [Point Wild]

“A notable characteristic of Vanta Stealer is its use of multiple PyArmor protection layers, combined with a PyInstaller-packaged executable, reflecting an emerging trend among Python-based malware families to adopt commercial software protection technologies as anti-analysis mechanisms. By introducing additional obfuscation layers, malware authors increase the effort required to inspect the underlying code, slowing reverse engineering efforts and delaying defensive response.”

NeedleStealer: The NeedleStealer is being deployed on systems previously infected with the CastleLoader malware. NeedleStealer is a desktop crypto wallet spoofer, and a malicious browser extension installer. [Arctic Wolf]

SilverFox is still active: Chinese e-crime group SilverFox is still active and working on new malware, despite the arrest of nearly 70 members and affiliates. [Cato Networks // AhnLab]

GenieLocker ransomware: Kaspersky looks at GenieLocker, a new ransomware strain that’s been used by the Toy Ghouls e-crime group (or Labubu, Bearlyfly) in attacks targeting Russia since March this year. [Kaspersky]

LogoKit PhaaS: Email security firm Barracuda has spotted a new phishing service named LogoKit that is being used to create custom phishing pages for individual corporate targets. [Barracuda]

“The toolkit dynamically builds phishing pages tailored to each victim, using commercially available tools to retrieve the company logo and capture a real-time screenshot of the victim’s legitimate website. In the attacks analyzed by Barracuda, LogoKit used the commercial Thum.io service to create full, legitimate website screenshots for the phishing background and Clearbit to add legitimate brand logos.”

ARToken PhaaS: The team at AbnormalAI looks at ARToken, a new phishing service that launched this month and appears to have specialized in targeting M365 accounts. [AbnormalAI]

In this product demo of the Airlock Digital application control and allowlisting solution, Patrick Gray speaks with Airlock Digital co-founders David Cottingham and Daniel Schell.

APTs, cyber-espionage, and info-ops

BlueNoroff on npm: The AWS security team has linked several npm supply chain attacks to a North Korean group tracked as BlueNoroff (SAPPHIRE SLEET, STARDUST CHOLLIMA, CageyChameleon, and Alluring Pisces). [AWS]

New PolinRider attacks: Researchers have linked recent clusters of malicious npm and Go packages to a North Korean operation known as PolinRider. [OpenSourceMalware]

UNC5342’s ClickFix and EtherHiding: North Korean group UNC5342 is using fake browser updates, ClickFix, and EtherHiding to target macOS users with a Node.js RAT. [AllSecure]

Operation Double Barrel: A North Korean hacking group has been linked to a year-long watering hole campaign that deployed backdoors and ransomware on selected targets. The watering hole sites exploited a vulnerability in South Korean financial security software AnySign4PC to deploy the malware payloads. Fifteen sites were hacked to host the attack, which compromised at least 72 organizations. The ransomware used in some of the attacks was the Gunra strain. [AhnLab // ENKI // S2W // KR NCSC]

Insolent Hyena: Russian security firm BI.ZONE says a hacktivist group named Insolent Hyena is behind several recent intrusions. The group is promoting the hacks as publicity stunts but secretly works and hands over access to groups with “different motivations.” [BI.ZONE]

Laundry Bear linked to recent Exchange zero-day: Russian espionage group Laundry Bear is behind a Microsoft Exchange zero-day spotted in May. The zero-day was primarily used against US and European government entities. The vulnerability allowed hackers to plant malicious code in inboxes that executed when users read their emails. The hackers used the zero-day to execute a tool named OWAReaper that stole credentials and emails from its victims’ accounts. [Proofpoint // CVE-2026-42897]

The activity shows:

• That TA488 has greatly improved its operational security measures

• Is writing more subtle and capable malware

• Targets a wide range of sectors but still prioritizes collecting government/defense intelligence

— ThreatInsight (@threatinsight.proofpoint.com) July 29, 2026 at 11:34 PM

Vulnerabilities, security research, and bug bounty

Security updates: Adobe, Chrome, Cisco, Gitea, Mastodon, Ruby on Rails, VMware.

Cisco zero-day: Cisco has released a security update to patch an actively exploited zero-day in the Secure Firewall Management Center (FMC) software. The FMC software contained hardcoded credentials for a low-privileged account. Attackers logged into the account and then used other bugs to elevate privileges and take over the device. Security firm Horizon3 found the bug and the attacks. [Cisco]

MikroTik brute-force bug: A bug in MikroTik routers can allow attackers to bypass login rate-limiting and carry out brute-force attacks. The issue impacts both normal and cloud-hosted routers. Tracked as CVE-2026-16347, the vulnerability has been traced to a bug in the RouterOS authentication API. No patch is available. [CISA]

Volvo vulnerabilities: Volvo has patched a vulnerability in the My Eicher fleet management platform that could have allowed attackers to track enrolled Volvo cars deployed across India. [Eaton Zveare]

Copilot Word worm: Security researcher Håkon Måløy has developed a technique that abuses Copilot to power a Word-based worm. [En Klype Salt]

CosmosEscape vulnerability: Microsoft has rolled out global patches to fix a vulnerability in the Azure Cosmos DB database service. The patches fix a vulnerability named CosmosEscape that could have allowed threat actors to gain full read and write access to every Cosmos DB database on the Azure cloud. The vulnerability granted attackers access to a Cosmos DB master key, a platform-wide secret that could access any Azure-hosted Cosmos database. [Wiz]

Infosec industry

Threat/trend reports: BlackFog, Coveware, IBM, Kai Security, Point Wild, and Splunk have recently published reports and summaries covering various threats and infosec industry trends.

Acquisition news: Identity management provider Okta has entered into an agreement to acquire Permiso Security. [Okta]

New SBOM guidance: Cybersecurity agencies from almost a dozen countries have released a joint guide on implementing the most basic elements to support an SBOM program. [ACSC // CISA]

DEFCON bans smart glasses: Infosec conference DEFCON has banned attendees from wearing smart glasses with hidden recording capabilities. [DEFCON]

New tool—Codex Security CLI: OpenAI has open–sourced Codex Security CLI, a CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities in your code.

Risky Business podcasts

In this edition of Seriously Risky Business, Tom Uren and James Wilson talk about open-weight AI models and distillation. These topics have been subject to a lot of US government attention in recent weeks, but let’s not forget that America’s overriding goal is to remain ahead of China in the AI race.

In this episode of Risky Business Features, James Wilson looks beyond the US vs China AI race rhetoric and instead games out what the real world consequences of the US government slapping bans on AI models could be.



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW