<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Blog</title>
    <link>https://www.cybereason.com/blog</link>
    <description>Get the latest research, expert insights, and security industry news.</description>
    <language>en</language>
    <pubDate>Tue, 03 Feb 2026 11:35:56 GMT</pubDate>
    <dc:date>2026-02-03T11:35:56Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>Fake Installer: Ultimately, ValleyRAT infection</title>
      <link>https://www.cybereason.com/blog/fake-installer-valleyrat</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.cybereason.com/blog/fake-installer-valleyrat" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.cybereason.com/hubfs/BLOG_Images_Template_v2%20%2837%29.png" alt="Fake Installer: Ultimately, ValleyRAT infection" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="text-align: left;"&gt;Cybereason Security Services issue Threat Analysis reports to inform on impacting threats. The Threat Analysis reports investigate these threats and provide practical recommendations for protecting against them.&lt;/p&gt; 
&lt;p style="text-align: left;"&gt;In this Threat Analysis report, Cybereason Security Services investigates a fake installer attack we recently observed multiple times. We identified some findings that have not been documented in previous reports and obtained new threat intelligence insights from the malwares.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.cybereason.com/blog/fake-installer-valleyrat" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.cybereason.com/hubfs/BLOG_Images_Template_v2%20%2837%29.png" alt="Fake Installer: Ultimately, ValleyRAT infection" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="text-align: left;"&gt;Cybereason Security Services issue Threat Analysis reports to inform on impacting threats. The Threat Analysis reports investigate these threats and provide practical recommendations for protecting against them.&lt;/p&gt; 
&lt;p style="text-align: left;"&gt;In this Threat Analysis report, Cybereason Security Services investigates a fake installer attack we recently observed multiple times. We identified some findings that have not been documented in previous reports and obtained new threat intelligence insights from the malwares.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=3354902&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.cybereason.com%2Fblog%2Ffake-installer-valleyrat&amp;amp;bu=https%253A%252F%252Fwww.cybereason.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Ransomware</category>
      <category>Research</category>
      <category>Threat Alerts</category>
      <pubDate>Tue, 03 Feb 2026 11:35:56 GMT</pubDate>
      <guid>https://www.cybereason.com/blog/fake-installer-valleyrat</guid>
      <dc:date>2026-02-03T11:35:56Z</dc:date>
      <dc:creator>Cybereason Security Services Team</dc:creator>
    </item>
    <item>
      <title>License to Encrypt: “The Gentlemen” Make Their Move</title>
      <link>https://www.cybereason.com/blog/the-gentlemen-ransomware</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.cybereason.com/blog/the-gentlemen-ransomware" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.cybereason.com/hubfs/dam/images/images-web/blog-images/TheGentlemen/The%20Gentlemen%20Blog.png" alt="License to Encrypt: “The Gentlemen” Make Their Move" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Cybereason Threat Intelligence Team recently conducted an analysis of "The Gentlemen" ransomware group, which emerged around July 2025 as a ransomware threat actor group with relatively advanced methodologies. The Gentlemen group employs a dual-extortion strategy, not only encrypting sensitive files but also exfiltrating critical business data and threatening to publish it on dark web leak sites unless a ransom is paid. The group has demonstrated a unique approach by combining established ransomware techniques with newer strategies, making them quick to adapt to new attack vectors, allowing them to remain a persistent to evolving threat to organizations worldwide.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.cybereason.com/blog/the-gentlemen-ransomware" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.cybereason.com/hubfs/dam/images/images-web/blog-images/TheGentlemen/The%20Gentlemen%20Blog.png" alt="License to Encrypt: “The Gentlemen” Make Their Move" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Cybereason Threat Intelligence Team recently conducted an analysis of "The Gentlemen" ransomware group, which emerged around July 2025 as a ransomware threat actor group with relatively advanced methodologies. The Gentlemen group employs a dual-extortion strategy, not only encrypting sensitive files but also exfiltrating critical business data and threatening to publish it on dark web leak sites unless a ransom is paid. The group has demonstrated a unique approach by combining established ransomware techniques with newer strategies, making them quick to adapt to new attack vectors, allowing them to remain a persistent to evolving threat to organizations worldwide.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=3354902&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.cybereason.com%2Fblog%2Fthe-gentlemen-ransomware&amp;amp;bu=https%253A%252F%252Fwww.cybereason.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Ransomware</category>
      <category>Research</category>
      <category>Threat Alerts</category>
      <pubDate>Tue, 18 Nov 2025 13:59:59 GMT</pubDate>
      <guid>https://www.cybereason.com/blog/the-gentlemen-ransomware</guid>
      <dc:date>2025-11-18T13:59:59Z</dc:date>
      <dc:creator>Cybereason Security Services Team</dc:creator>
    </item>
    <item>
      <title>Tycoon 2FA Phishing Kit Analysis</title>
      <link>https://www.cybereason.com/blog/tycoon-phishing-kit-analysis</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.cybereason.com/blog/tycoon-phishing-kit-analysis" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.cybereason.com/hubfs/dam/images/images-web/blog-images/Tycoon%20Phishing%20Kit/BLOG_Images_Template_v2%20(27).png" alt="Tycoon 2FA Phishing Kit Analysis" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;The &lt;span style="font-weight: bold;"&gt;Tycoon 2FA phishing kit&lt;/span&gt; is a sophisticated Phishing-as-a-Service (PhaaS) platform that emerged in August 2023, designed to bypass two-factor authentication (2FA) and multi-factor authentication (MFA) protections, primarily targeting Microsoft 365 and Gmail accounts. Utilizing an Adversary-in-the-Middle (AiTM) approach, it employs a reverse proxy server to host deceptive phishing pages that mimic legitimate login interfaces, capturing user credentials and session cookies in real-time. According to the Any.run malware trends tracker, Tycoon 2FA leads with over 64,000 reported incidents this year.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.cybereason.com/blog/tycoon-phishing-kit-analysis" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.cybereason.com/hubfs/dam/images/images-web/blog-images/Tycoon%20Phishing%20Kit/BLOG_Images_Template_v2%20(27).png" alt="Tycoon 2FA Phishing Kit Analysis" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;The &lt;span style="font-weight: bold;"&gt;Tycoon 2FA phishing kit&lt;/span&gt; is a sophisticated Phishing-as-a-Service (PhaaS) platform that emerged in August 2023, designed to bypass two-factor authentication (2FA) and multi-factor authentication (MFA) protections, primarily targeting Microsoft 365 and Gmail accounts. Utilizing an Adversary-in-the-Middle (AiTM) approach, it employs a reverse proxy server to host deceptive phishing pages that mimic legitimate login interfaces, capturing user credentials and session cookies in real-time. According to the Any.run malware trends tracker, Tycoon 2FA leads with over 64,000 reported incidents this year.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=3354902&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.cybereason.com%2Fblog%2Ftycoon-phishing-kit-analysis&amp;amp;bu=https%253A%252F%252Fwww.cybereason.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Ransomware</category>
      <category>Research</category>
      <category>Threat Alerts</category>
      <pubDate>Mon, 03 Nov 2025 17:42:04 GMT</pubDate>
      <guid>https://www.cybereason.com/blog/tycoon-phishing-kit-analysis</guid>
      <dc:date>2025-11-03T17:42:04Z</dc:date>
      <dc:creator>Cybereason Security Services Team</dc:creator>
    </item>
    <item>
      <title>From Scripts to Systems: A Comprehensive Look at Tangerine Turkey Operations</title>
      <link>https://www.cybereason.com/blog/tangerine-turkey</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.cybereason.com/blog/tangerine-turkey" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.cybereason.com/hubfs/dam/images/images-web/blog-images/From%20Scripts%20to%20Systems-%20A%20Comprehensive%20Look%20at%20Tangerine%20Turkey%20Operations/BLOG_Images_Template_v2%20(28).png" alt="From Scripts to Systems: A Comprehensive Look at Tangerine Turkey Operations" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Cybereason Security Services issue Threat Analysis reports to inform on impacting threats. The Threat Analysis reports investigate these threats and provide practical recommendations for protecting against them.&lt;/p&gt; 
&lt;p&gt;In this Threat Analysis report, Cybereason Security Services investigates the flow of a Tangerine Turkey campaign observed in Cybereason EDR. Tangerine Turkey is a threat actor identified as a visual basic script (VBS) worm used to facilitate cryptomining activity.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.cybereason.com/blog/tangerine-turkey" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.cybereason.com/hubfs/dam/images/images-web/blog-images/From%20Scripts%20to%20Systems-%20A%20Comprehensive%20Look%20at%20Tangerine%20Turkey%20Operations/BLOG_Images_Template_v2%20(28).png" alt="From Scripts to Systems: A Comprehensive Look at Tangerine Turkey Operations" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Cybereason Security Services issue Threat Analysis reports to inform on impacting threats. The Threat Analysis reports investigate these threats and provide practical recommendations for protecting against them.&lt;/p&gt; 
&lt;p&gt;In this Threat Analysis report, Cybereason Security Services investigates the flow of a Tangerine Turkey campaign observed in Cybereason EDR. Tangerine Turkey is a threat actor identified as a visual basic script (VBS) worm used to facilitate cryptomining activity.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=3354902&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.cybereason.com%2Fblog%2Ftangerine-turkey&amp;amp;bu=https%253A%252F%252Fwww.cybereason.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Ransomware</category>
      <category>Research</category>
      <category>Threat Alerts</category>
      <pubDate>Wed, 29 Oct 2025 14:00:35 GMT</pubDate>
      <guid>https://www.cybereason.com/blog/tangerine-turkey</guid>
      <dc:date>2025-10-29T14:00:35Z</dc:date>
      <dc:creator>Cybereason Security Services Team</dc:creator>
    </item>
    <item>
      <title>Behind the Mask of Madgicx Plus: A Chrome Extension Campaign Targeting Meta Advertisers</title>
      <link>https://www.cybereason.com/blog/chrome-extension-campaign-madgicx</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.cybereason.com/blog/chrome-extension-campaign-madgicx" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.cybereason.com/hubfs/Chrome%20Extension%20Campaign.png" alt="Behind the Mask of Madgicx Plus: A Chrome Extension Campaign Targeting Meta Advertisers" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Cybereason Security Services recently analyzed an investigation into a broader malicious Chrome extension campaign, part of which had been previously documented by DomainTools. While earlier iterations of this campaign involved the impersonation a variety of services, the latest version shifts focus to Meta (Facebook/Instagram) advertisers through a newly crafted lure: “Madgicx Plus,” a fake AI-driven ad optimization platform. Promoted as a tool to streamline campaign management and boost ROI using artificial intelligence, the extension instead delivers potentially malicious functionalities capable of hijacking business sessions, stealing credentials, and compromising Meta Business accounts. Notably, several domains associated with earlier parts of the campaign have been repurposed to promote this new theme, highlighting the operators’ tendency to recycle infrastructure while adapting their social engineering strategy to new targets.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.cybereason.com/blog/chrome-extension-campaign-madgicx" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.cybereason.com/hubfs/Chrome%20Extension%20Campaign.png" alt="Behind the Mask of Madgicx Plus: A Chrome Extension Campaign Targeting Meta Advertisers" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Cybereason Security Services recently analyzed an investigation into a broader malicious Chrome extension campaign, part of which had been previously documented by DomainTools. While earlier iterations of this campaign involved the impersonation a variety of services, the latest version shifts focus to Meta (Facebook/Instagram) advertisers through a newly crafted lure: “Madgicx Plus,” a fake AI-driven ad optimization platform. Promoted as a tool to streamline campaign management and boost ROI using artificial intelligence, the extension instead delivers potentially malicious functionalities capable of hijacking business sessions, stealing credentials, and compromising Meta Business accounts. Notably, several domains associated with earlier parts of the campaign have been repurposed to promote this new theme, highlighting the operators’ tendency to recycle infrastructure while adapting their social engineering strategy to new targets.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=3354902&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.cybereason.com%2Fblog%2Fchrome-extension-campaign-madgicx&amp;amp;bu=https%253A%252F%252Fwww.cybereason.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Ransomware</category>
      <category>Research</category>
      <category>Threat Alerts</category>
      <pubDate>Tue, 09 Sep 2025 14:37:51 GMT</pubDate>
      <guid>https://www.cybereason.com/blog/chrome-extension-campaign-madgicx</guid>
      <dc:date>2025-09-09T14:37:51Z</dc:date>
      <dc:creator>Cybereason Security Services Team</dc:creator>
    </item>
    <item>
      <title>BlackSuit: A Hybrid Approach with Data Exfiltration and Encryption</title>
      <link>https://www.cybereason.com/blog/blacksuit-data-exfil</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.cybereason.com/blog/blacksuit-data-exfil" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.cybereason.com/hubfs/BLOG_Images_Template_v2%20%2823%29.png" alt="BlackSuit: A Hybrid Approach with Data Exfiltration and Encryption" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Cybereason Security Services issue Threat Analysis reports to inform on impacting threats. The Threat Analysis reports investigate these threats and provide practical recommendations for protecting against them.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.cybereason.com/blog/blacksuit-data-exfil" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.cybereason.com/hubfs/BLOG_Images_Template_v2%20%2823%29.png" alt="BlackSuit: A Hybrid Approach with Data Exfiltration and Encryption" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Cybereason Security Services issue Threat Analysis reports to inform on impacting threats. The Threat Analysis reports investigate these threats and provide practical recommendations for protecting against them.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=3354902&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.cybereason.com%2Fblog%2Fblacksuit-data-exfil&amp;amp;bu=https%253A%252F%252Fwww.cybereason.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Ransomware</category>
      <category>Research</category>
      <category>Threat Alerts</category>
      <pubDate>Fri, 11 Jul 2025 14:56:03 GMT</pubDate>
      <guid>https://www.cybereason.com/blog/blacksuit-data-exfil</guid>
      <dc:date>2025-07-11T14:56:03Z</dc:date>
      <dc:creator>Cybereason Security Services Team</dc:creator>
    </item>
    <item>
      <title>Deploying NetSupport RAT via WordPress &amp; ClickFix</title>
      <link>https://www.cybereason.com/blog/net-support-rat-wordpress-clickfix</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.cybereason.com/blog/net-support-rat-wordpress-clickfix" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.cybereason.com/hubfs/BLOG_Images_Template_v2%20%2821%29.png" alt="Deploying NetSupport RAT via WordPress &amp;amp; ClickFix" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;In May 2025, Cybereason Global Security Operations Center (GSOC) detected that threat actors have been hosting malicious WordPress websites to deliver malicious versions of the legitimate NetSupport Manager Remote Access Tool (RAT).&amp;nbsp;&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.cybereason.com/blog/net-support-rat-wordpress-clickfix" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.cybereason.com/hubfs/BLOG_Images_Template_v2%20%2821%29.png" alt="Deploying NetSupport RAT via WordPress &amp;amp; ClickFix" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;In May 2025, Cybereason Global Security Operations Center (GSOC) detected that threat actors have been hosting malicious WordPress websites to deliver malicious versions of the legitimate NetSupport Manager Remote Access Tool (RAT).&amp;nbsp;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=3354902&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.cybereason.com%2Fblog%2Fnet-support-rat-wordpress-clickfix&amp;amp;bu=https%253A%252F%252Fwww.cybereason.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Ransomware</category>
      <category>Research</category>
      <category>Threat Alerts</category>
      <pubDate>Mon, 07 Jul 2025 13:35:49 GMT</pubDate>
      <guid>https://www.cybereason.com/blog/net-support-rat-wordpress-clickfix</guid>
      <dc:date>2025-07-07T13:35:49Z</dc:date>
      <dc:creator>Cybereason Security Services Team</dc:creator>
    </item>
    <item>
      <title>Ransomware Gangs Collapse as Qilin Seizes Control</title>
      <link>https://www.cybereason.com/blog/threat-alert-qilin-seizes-control</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.cybereason.com/blog/threat-alert-qilin-seizes-control" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.cybereason.com/hubfs/BLOG_Images_Template_v2%20%2819%29.png" alt="Ransomware Gangs Collapse as Qilin Seizes Control" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;The ransomware landscape is undergoing a turbulent realignment, marked by collapses, takeovers, and unexpected internal betrayals.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.cybereason.com/blog/threat-alert-qilin-seizes-control" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.cybereason.com/hubfs/BLOG_Images_Template_v2%20%2819%29.png" alt="Ransomware Gangs Collapse as Qilin Seizes Control" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;The ransomware landscape is undergoing a turbulent realignment, marked by collapses, takeovers, and unexpected internal betrayals.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=3354902&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.cybereason.com%2Fblog%2Fthreat-alert-qilin-seizes-control&amp;amp;bu=https%253A%252F%252Fwww.cybereason.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Ransomware</category>
      <category>Research</category>
      <category>Threat Alerts</category>
      <pubDate>Tue, 17 Jun 2025 14:05:32 GMT</pubDate>
      <guid>https://www.cybereason.com/blog/threat-alert-qilin-seizes-control</guid>
      <dc:date>2025-06-17T14:05:32Z</dc:date>
      <dc:creator>Cybereason Security Services Team</dc:creator>
    </item>
    <item>
      <title>Copyright Phishing Lures Leading to Rhadamanthys Stealer Now Targeting Europe</title>
      <link>https://www.cybereason.com/blog/rhadamanthys-stealer-europe</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.cybereason.com/blog/rhadamanthys-stealer-europe" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.cybereason.com/hubfs/BLOG_Images_Template_v2%20%2818%29.png" alt="Copyright Phishing Lures Leading to Rhadamanthys Stealer Now Targeting Europe" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Cybereason issues Threat Alerts to inform customers of emerging impacting threats, critical vulnerabilities and attacker campaigns. Cybereason Threat Alerts summarize these threats and provide practical recommendations for protecting against them.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.cybereason.com/blog/rhadamanthys-stealer-europe" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.cybereason.com/hubfs/BLOG_Images_Template_v2%20%2818%29.png" alt="Copyright Phishing Lures Leading to Rhadamanthys Stealer Now Targeting Europe" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Cybereason issues Threat Alerts to inform customers of emerging impacting threats, critical vulnerabilities and attacker campaigns. Cybereason Threat Alerts summarize these threats and provide practical recommendations for protecting against them.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=3354902&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.cybereason.com%2Fblog%2Frhadamanthys-stealer-europe&amp;amp;bu=https%253A%252F%252Fwww.cybereason.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Ransomware</category>
      <category>Research</category>
      <category>Threat Alerts</category>
      <pubDate>Wed, 21 May 2025 19:26:05 GMT</pubDate>
      <guid>https://www.cybereason.com/blog/rhadamanthys-stealer-europe</guid>
      <dc:date>2025-05-21T19:26:05Z</dc:date>
      <dc:creator>Cybereason Security Services Team</dc:creator>
    </item>
    <item>
      <title>Genesis Market - Malicious Browser Extension</title>
      <link>https://www.cybereason.com/blog/threat-alert-genesis-market</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.cybereason.com/blog/threat-alert-genesis-market" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.cybereason.com/hubfs/BLOG_Images_Template_v2%20%2817%29.png" alt="Genesis Market - Malicious Browser Extension" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Cybereason GSOC has identified a malware infection exhibiting strong similarities to the previously reported Genesis Market malicious campaign that was dismantled by law enforcement in early 2023.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.cybereason.com/blog/threat-alert-genesis-market" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.cybereason.com/hubfs/BLOG_Images_Template_v2%20%2817%29.png" alt="Genesis Market - Malicious Browser Extension" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Cybereason GSOC has identified a malware infection exhibiting strong similarities to the previously reported Genesis Market malicious campaign that was dismantled by law enforcement in early 2023.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=3354902&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.cybereason.com%2Fblog%2Fthreat-alert-genesis-market&amp;amp;bu=https%253A%252F%252Fwww.cybereason.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Ransomware</category>
      <category>Research</category>
      <category>Threat Alerts</category>
      <pubDate>Wed, 21 May 2025 15:06:06 GMT</pubDate>
      <guid>https://www.cybereason.com/blog/threat-alert-genesis-market</guid>
      <dc:date>2025-05-21T15:06:06Z</dc:date>
      <dc:creator>Cybereason Security Services Team</dc:creator>
    </item>
  </channel>
</rss>
