Archive for NordStellar

Guest Post: Ransomware attacks up 20% year-over-year as The Gentlemen and Qilin battle for dominance

Posted in Commentary with tags on July 15, 2026 by itnerd

The latest findings from NordStellar, a threat exposure management platform, reveal that ransomware attack volumes remained high from April to June 2026, sustaining the elevated baseline. The analysis also points to an intensifying fight for dominance between the two most active ransomware groups, The Gentlemen and Qilin, as well as a notable shift in victim targeting.

According to findings from NordStellar, 2,581 ransomware incidents were recorded during April-June 2026. The number reflects a slight 4% decrease from 2,676 incidents recorded in Q1 2026. However, the attacks remain at a heightened baseline, indicating sustained threat activity.

“The slight decrease in attacks shouldn’t be a sign to relax just yet,” says Vakaris Noreika, cybersecurity expert at NordStellar. “Ransomware accelerated in the last quarter of 2025, reaching record highs, and although the number of attacks has been slightly decreasing every quarter this year, we are now seeing a new alarming baseline of about 2,500 attacks per quarter.”

A total of 5,257 ransomware attacks were recorded during January-June 2026. This marks a 20% increase from the 4,387 attacks recorded during the same period last year, signaling that the ransomware threat is growing despite quarterly fluctuations.

Rivalry between Qilin and The Gentlemen intensifies

Qilin emerged as the most active ransomware group in Q2 2026 with 299 attacks, followed closely by The Gentlemen with 284 attacks. Activity from other groups trailed significantly, with DragonForce ranking third at 147 attacks.

“While Qilin’s activity declined slightly from the previous quarter, The Gentlemen accelerated its operations with a 39% increase in attacks, further deepening the rivalry between the two groups,” says Mantas Sabeckis, senior threat intelligence researcher at Nord Security. “Even though DragonForce remains significantly less active than the top two, it is steadily scaling up — last quarter’s attack volume marked an all-time high for the group.”

According to Sabeckis, the fact that Qilin and The Gentlemen have managed to establish themselves as the two dominant ransomware groups and more or less maintain their positions highlights a concerning trend — the ransomware threat landscape is stabilizing and maturing.

“Established ransomware groups have refined tools, affiliate networks, and negotiation infrastructures. The more sophisticated and established a group becomes, the greater the threat it poses,” explains Sabeckis. “This competition between Qilin and The Gentlemen could potentially drive an even higher baseline of activity. Each group is likely ramping up operations and casting a wider net to come out on top, and as affiliates move between groups, the balance of power could shift in the coming months.”

He adds that in a landscape like this, smaller groups such as DragonForce are under growing pressure to scale. They’re more likely to accelerate their operations to prove themselves among more dominant players, further inflating the overall threat landscape.

Q2 ransomware victims: SMBs dominate, but attackers are shifting their gaze to enterprises

NordStellar findings reveal that small and medium-sized businesses (SMBs) — those with up to 200 employees and revenues under $25 million — bore the brunt of ransomware activity. However, attacks against large enterprises with revenues exceeding $1 billion surged by 74%, rising from 23 incidents in the first quarter to 40 incidents during the second.

“Ransomware actors historically target SMBs because these organizations often lack comprehensive defenses, which can increase the likelihood of a successful attack. This recent spike in enterprise targeting is unusual and may be a temporary fluctuation,” says Noreika. “This shift likely stems from the rivalry between dominant threat actors — a successful hit on a major corporation is a badge of honor that boosts a group’s reputation within the cybercriminal underground.”

The data also reveals that ransomware actors continue to primarily target companies in the US, with 769 recorded ransomware cases in Q2 2026. The US was followed by Canada with 97 cases, then Germany with 83 cases, the United Kingdom with 74 cases, and France with 51 cases.

As seen in previous quarters, companies in manufacturing were hit the hardest, making up for 19.5% of all attacks. The information technology sector came second (10.7% of attacks), followed by professional, scientific, and technical services (8.3%), construction (7%), and healthcare (6.2%).

“Companies in the US experienced a slight decline in attacks compared to the previous quarter, while attacks on companies in Canada increased by 13%, suggesting that attackers might be shifting their geographical focus,” says Noreika. “Businesses operating in the manufacturing and information technology sectors continue to be hit hardest by the attacks. However, the healthcare industry recorded the smallest quarterly decline among major sectors, signaling that ransomware actors continue to prioritize it due to its high-value data and the operational sensitivity of critical services, where even limited downtime can create intense pressure to restore systems quickly.”

Safeguarding against ransomware in a sophisticated threat landscape

According to Noreika, the increasing maturity of the current ransomware landscape calls for companies to stay on high alert. Businesses can expect more refined and complex attacks, making it critical to identify and patch vulnerabilities before attackers can exploit them.

“The current ransomware ecosystem is growing and expanding. Groups like Qilin and The Gentlemen don’t operate like amateur hackers — they operate like well-structured organizations,” says Noreika. “They have extensive resources that allow them to scale their operations, broaden their victim pool, invest in more efficient initial-access methods, and escalate pressure tactics such as double and triple extortion.”

Previous findings from NordStellar reveal that ransomware actors utilize various schemes to coerce victims into payment, with 76.8% of ransomware negotiations including threats to publish or leak the data, and limited-time price discounts being offered in 45.5% of the negotiations.

“As leading ransomware groups compete for dominance and scale their operations, no company is immune. Abandoning the ‘it won’t happen to us’ mindset has never been more critical,” says Noreika. “Companies should strengthen their defenses by focusing on basic cyber hygiene, which is too often overlooked. This includes enforcing multi-factor authentication, implementing strong password management policies, regularly patching systems and applications, and adopting a zero trust approach to limit lateral movement.”

Noreika emphasizes the importance of early threat prevention and detection — ransomware actors can use data leaked on the dark web to gain initial access, and catching these leaks early alerts the organization to take action by resetting passwords and revoking access keys before it’s too late. He adds that backing up critical data is crucial to reduce downtime in the event of a successful ransomware attack, while having a recovery plan in place is essential to speed up incident mitigation.

Methodology

NordStellar continuously monitors over 200 blogs run by ransomware groups. Analyzing the listings published by attackers, NordStellar discovered 2,581 ransomware attacks during April-June 2026. The full methodology can be found in the report, located here: https://nordlayer.com/intelligence/ransomware-statistics/.

Guest Post: Dark web analysis: Deepfakes as a service discussions soar by 39%

Posted in Commentary with tags on June 23, 2026 by itnerd

Findings from the dark web reveal that discussions surrounding deepfakes as a service have exploded in 2026, already surpassing 2025’s totals and potentially paving the way for a new wave of business email compromise attacks

The latest findings from NordStellar, a threat exposure management platform, reveal that dark web discussions surrounding cybercrime as a service are trending upward in 2026. Deepfakes as a service is proving especially popular, with posts surging 39% in the first five months of 2026 — already surpassing the total volume recorded in 2025 and potentially giving cybercriminals new tools for “fake boss” scams.

According to data analyzed by NordStellar, 9,234 dark web posts discussed cybercrime as a service (CaaS) in 2025. Between January and May 2026 alone, that number has already reached 6,866 — representing 74% of last year’s total.

The analysis reveals that discussions about deepfakes as a service (DFaaS) are growing the fastest. In just the first five months of 2026, there were 924 posts — marking a 39% increase compared to the 663 posts recorded for all of 2025.

“The rapid growth in popularity of deepfakes as a service is likely accelerated by advancements in generative AI, which help cybercriminals in two ways — by speeding up the creation of deepfakes and making them hyper-realistic,” says Vakaris Noreika, cybersecurity expert at NordStellar. “Ultimately, this service lowers the barrier to entry for deepfake technology, enabling threat actors to deploy highly deceptive attacks at a larger scale, regardless of their personal technical skill set.”

Deepfakes for business email compromise attacks

Noreika highlights that the growing popularity of DFaaS is a key concern for businesses. Cybercriminals can leverage deepfakes not only to target individuals with sophisticated social engineering but also to amplify business email compromise (BEC), otherwise commonly known as “fake boss” scams. In these attacks, bad actors impersonate vendors, colleagues, or executives to manipulate employees.

The FBI reports that business email compromise was the second costliest cybercrime of 2025, with company losses exceeding $3 billion. This marks an 11% increase over $2.7 billion reported in 2024.

The real-life case covered by the World Economic Forum involving engineering firm Arup highlights the stakes: An employee was tricked into transferring $25 million after attending a video call where all other participants were AI-generated deepfakes.

“Deepfakes can be used to elevate business email compromise attacks to make them even harder to spot — instead of receiving fake payment instructions in an email, employees can now be targeted via highly realistic video and voice calls impersonating partners or managers asking them to transfer funds,” says Noreika. “As AI tools grow more sophisticated, deepfakes are evolving rapidly. It is now easier than ever to create convincing video or audio that lacks the usual telltale signs of AI generation, making it extremely challenging for users to spot the deception — especially when a sense of urgency is involved.”

He explains that cybercriminals usually deploy these attacks to obtain fake payments or confidential documents or to infiltrate the company’s network to launch a larger-scale attack. Advanced BEC attacks usually involve gathering extensive intel on the target to ensure that the attack itself contains convincing details, is context-appropriate, and is delivered at the right time — for example, when the recipient is already waiting for an incoming invoice.

Deepfake defense strategies in the era of AI

Noreika suggests that a deepfake-resistant cybersecurity strategy should focus on two main areas — prevention and employee education. While companies can’t control whether cybercriminals target them, robust security measures can make advanced BEC attacks much harder to execute.

“The more details and access attackers obtain, the easier it is for them to craft highly realistic, targeted attacks,” says Noreika. “Monitoring the dark web for leaked company information is a critical step in preventing cybercriminals from finding credentials to breach accounts or data to use as intel.”

He emphasizes that educating employees on BEC attacks is vital. However, he notes that fostering a positive cybersecurity culture is equally important.

“Attackers take advantage of their targets by creating a sense of urgency,” says Noreika. “Even if employees are aware of cybercriminals’ tactics, slowing down to double-check a request that’s coming from a person of authority can be daunting to most, especially if deadlines are tight. Efficiency shouldn’t come at the expense of possibly exposing the company to a cyberattack, and employees should feel safe and empowered to raise red flags when something is off, and take some time to inspect the request before diving headlong.”

Noreika stresses that having a robust cybersecurity strategy in place will help mitigate the aftermath of a BEC attack if threat actors succeed in tricking employees and gain access to the company’s network. He notes that security measures like network segmentation and multi-factor authentication can help prevent attackers from moving laterally inside the network as well as prevent them from accessing resources.

Methodology: The NordStellar platform was used to analyze underground discussions from dark web forums and monitored Telegram channels. NordStellar tracked 6 categories covering as-a-service offerings. For each category, NordStellar retrieved monthly post counts across both forums and Telegram for every month from January 2024 through May 2026. For more information, visit NordStellar’s blog post.

Disclaimer. This analysis is based on detected activity and is for informational purposes only; it does not constitute professional advice or a guarantee of security. All third-party trademarks and references remain the property of their respective owners and are used for identification purposes only.

NordStellar debuts MCP to accelerate and streamline threat intelligence analysis

Posted in Commentary with tags on May 19, 2026 by itnerd

Efficient threat intelligence analysis is key in order to stop cyber threats before they escalate. NordStellar, a next-generation threat exposure management platform, has launched a model context protocol (MCP) that connects with AI tools to quickly analyze threat intelligence findings and generate reports, helping security teams to rapidly identify and prioritize high-risk issues.

NordStellar users will find the MCP in NordStellar’s help center. After downloading the file or setting it up manually, they will be able to connect it to popular AI tools.

By connecting the NordStellar MCP to their existing AI tools, security teams will gain significant advantages, enabling them to:

  • Receive quick custom reports. They will be able to generate executive and weekly summaries, threat exposure reports to share with stakeholders and other team members, as well as generate dated summaries of NordStellar findings and monitoring activity to support internal reviews, audits, and compliance processes.
  • Stay informed and updated on the latest findings. Security teams will be able to ask questions about specific findings and receive plain‑English explanations of events, vulnerabilities, or leaked data, request clear summaries of what is being said about their company on the dark web, and, where supported by their AI workflows, receive recurring summaries of new or high‑risk findings.
  • Identify and prioritize risks. Users will see which leaked credentials, malware logs, cookies, or instances of employee exposure may need attention first, enabling security teams to quickly identify which incidents are of highest priority.

The MCP is now available to all NordStellar users. For more information, book a personalized demonstration here.

Ransomware playbook: “Special price” offers included in 45% of negotiations

Posted in Commentary with tags on May 14, 2026 by itnerd

The latest findings from NordStellar, a threat exposure management platform, reveal that the number of ransomware attacks in Q1 2026 remained high, with 2,283 recorded incidents. An analysis of leaked ransomware negotiation conversations uncovers tactics and tendencies used by ransomware actors. Key findings include:

  • In 76.8% of the conversations ransomware groups threatened to publish or leak the data.
  • They often use upselling practices, including special price offers (45.5%) and offers to purchase other services, like “security audits.
  • The median discount in ransomware payments is 57%, with the highest recorded discount reaching as high as 96.2%.

The full report for the analysis of leaked ransomware negotiation conversations can be found here: Ransomware negotiations report

NordStellar upgrades its attack surface management feature

Posted in Commentary with tags on February 25, 2026 by itnerd

The new attack surface management feature upgrade is designed to help combat alert fatigue by focusing on validated vulnerabilities, allowing security teams to cut through the noise and tackle critical issues first

As companies’ attack surfaces expand, security teams are finding it increasingly difficult to monitor all exposed assets and swiftly address critical vulnerabilities. To help security teams cut through the noise, NordStellar, a next-generation threat exposure management platform, has upgraded its attack surface management (ASM) feature to provide even more extensive coverage of exposed assets while prioritizing critical vulnerabilities first.

Companies’ attack surfaces are constantly expanding due to digital transformation, scaling, unmanaged devices, and user error. This growing complexity makes it challenging to monitor all exposed assets, often leading to alert fatigue as critical threats are buried under a flood of less urgent alerts.

ASM is a feature that automatically discovers security gaps by continuously monitoring and evaluating all of the organization’s internet-exposed assets. The upgraded feature now gives organizations an attacker’s view of their company, providing comprehensive coverage of their external perimeter and going beyond passive scans to actively test for exploitable vulnerabilities.

NordStellar’s ASM feature combines continuous asset discovery with active risk validation. NordStellar maps the organization’s infrastructure by identifying all internet-exposed assets, like web applications, network services, and DNS configurations, and performs “outsider-style” testing.

To ensure vulnerabilities are mitigated as soon as possible, each identified instance is accompanied by AI-powered insights that offer remediation guidance.

Key upgrades:

  • Increased coverage. The enhanced ASM feature implements scans across all key vectors — web applications, network services, and DNS configurations — to provide complete external perimeter visibility and eliminate critical security blind spots.
  • Heightened accuracy. ASM actively discovers and tests vulnerabilities across more sources, delivering prioritized alerts.
  • Enhanced flexibility. The upgraded feature allows teams to run scans on demand for immediate insights or schedule them for automated monitoring.

The enhanced ASM feature is now available to all NordStellar users. More information here.

Guest Post – 73% of exposed OpenClaw servers remain public: Expert urges businesses to act now

Posted in Commentary with tags on February 5, 2026 by itnerd

The AI agent OpenClaw’s popularity has skyrocketed over recent weeks, but so have concerns about its cybersecurity risks. New findings reveal that roughly 73% of OpenClaw servers exposed this week remain publicly accessible to this day, creating a significant threat to users and an even greater risk to businesses — a single employee using OpenClaw could potentially expose sensitive information or corporate credentials.

openclaw.ai (formerly Clawdbot or Moltbot) is a self-hosted AI agent and assistant created by developer Peter Steinberger. Recently, it took the internet by storm with the promise of an AI agent that not only responds but also takes independent action — OpenClaw can instantly execute commands, such as scheduling meetings, editing files, or browsing the internet, among many other use cases.

Although deemed revolutionary by some users, OpenClaw’s functionalities come with a hefty cost — with extensive access to local and web-based applications, passwords, and other sensitive information, the responsibility of securing the environment in which the AI agent is deployed falls on the user, and failure to do so poses a high risk of leaking data to the open web. Labeled as a “hobby project” by its creators, OpenClaw doesn’t sugarcoat its cybersecurity risks and recommends that users who are not familiar with basic security and access control avoid the AI agent or seek guidance from professionals.

A senior threat intelligence researcher from NordStellar, a threat exposure management platform, analyzed findings from network observability tools that revealed about 21,000 (21,356) servers running OpenClaw or its prerequisites were accessible on the public internet this week.

As of Thursday, February 5th, nearly 16,000 (15,578) of those servers were still accessible, highlighting that not only does OpenClaw pose significant cybersecurity risks, but users are slow to take the necessary security measures to make these servers inaccessible, leaving them publicly exposed, and further illustrating that the majority of them lack the technical knowledge to mitigate the security risks of deploying OpenClaw.

And that’s only part of the story — a recently documented high severity vulnerability in OpenClaw allows an attacker to gain remote code execution just by tricking a user into clicking a single malicious link. Users have also been flocking to GitHub to report vulnerabilities. While not all of them have been validated, the number of identified security issues has been growing rapidly and has already surpassed 100 reports.

Having already garnered over 145,000 GitHub stars and 20,000 forks, users are nevertheless quick to adopt the new agent. Andrius Buinovskis, a cybersecurity expert at NordLayer, a toggle-ready network security platform for businesses, warns that OpenClaw’s growing popularity should be a cause for concern among businesses.

“OpenClaw introduces significant security risks for users, but they’re even more dangerous for organizations. Businesses handle extremely sensitive data, and a single employee using OpenClaw could unknowingly jeopardize the organization’s security,” says Buinovskis.

He explains that the AI agent stores passwords, API keys, and OAuth tokens in plaintext — without encryption — so leaked corporate credentials will be easily accessible and usable by anyone who manages to get their hands on them. This sensitive data, along with chat history with the AI bot, is stored on a local web server that could accidentally be exposed to the public internet.

“With the ability to automate some everyday work tasks, it’s understandable why employees could be eager to deploy OpenClaw. The software is primarily designed for a more tech-savvy audience, such as developers and vibe-coders. However, the sheer number of exposed servers proves that even experienced users overlook basic security hygiene when a tool is easy to misconfigure,” says Buinovskis.

Mitigating OpenClaw security risks in a business environment

According to Buinovskis, while there are many cybersecurity concerns surrounding OpenClaw, businesses can take key preventive measures to mitigate some of the main risks. He highlights that full system access, autonomy, and complex setups are key risks security teams should keep in mind and aim to address.

“The first key objective is to mitigate the shadow IT problem OpenClaw poses for organizations by avoiding uncontrolled and decentralized deployments,” says Buinovskis. “This calls for clear policies surrounding approved software enforcement mechanisms, like endpoint detection, to prevent employees from running unapproved instances in the first place.”

He highlights that while OpenClaw is dangerous, security teams would benefit from getting ahead of the problem. Since employees might go rogue and use it anyway, it’s better for them to do so in a secure, controlled environment.

“In reality, even extensive cybersecurity awareness training does not guarantee that users will refrain from risky behaviour, despite knowing the threats that may follow. While it might seem counterintuitive, allowing employees who are interested in using OpenClaw to deploy it centrally would eliminate any risks that could arise from poor misconfiguration,” says Buinovskis.

He explains that centralized deployment provides a single point of control for security teams, allowing them to configure a single instance correctly rather than relying on numerous employees to do it right. This approach also establishes consistent security settings throughout — ensuring that authentication, firewalls, and encryption are applied, and allowing easier monitoring of logs and access attempts.

“Even if OpenClaw is deployed centrally, users still need a safe way to access it. For this, they need a secure, encrypted tunnel that they could access with authorization,” says Buinovskis. “Secure tunnels ensure that the server containing sensitive data is isolated from the public internet, and setting up a VPN or private network allows only authorized users to have access to OpenClaw.”

Bunovskis continues that creating remote access via secure tunnels prevents the server containing sensitive data from becoming publicly accessible, safeguarding it from attackers. This approach also encrypts the traffic, mitigating the risk of data exposure during transit.

Guest Post: 2025 saw a 45% increase in ransomware attacks

Posted in Commentary with tags on January 21, 2026 by itnerd

Ransomware attacks soared in 2025, with 9,251 recorded cases compared to 6,395 cases in 2024

The latest findings from NordStellar, a threat exposure management platform, reveal that the number of ransomware incidents in 2025 soared compared to 2024. The data shows that in 2025, 9,251 ransomware cases were recorded on the dark web, marking a significant 45% increase compared to 6,395 cases recorded in 2024.

The number of ransomware cases rose significantly in the last quarter of 2025. December set a two‑year record, with a substantial 1,004 recorded incidents.

“In the last quarter of 2025, ransomware groups deliberately exploited end-of-year cybersecurity gaps caused by reduced staffing and monitoring,” says Vakaris Noreika, cybersecurity expert at NordStellar. “However, there has been an upward trajectory the whole year. Ransomware actors are growing increasingly aggressive — given the surge in 2025, the number of ransomware incidents in 2026 is likely to exceed 12,000.”

According to Noreika, the number of ransomware groups has also been increasing. The recorded ransomware incidents in 2025 could be traced back to 134 different groups — a 30% increase from the 103 groups linked to recorded ransomware incidents in 2024.

SMBs in the US were affected the most

Companies in the US remained the primary targets, with 3,255 recorded ransomware cases in 2025 (a 28% increase from 2,544 incidents in 2024), accounting for 64% of all cases. The US was followed by Canada with 352 cases (a 46% increase from 2024), then Germany with 270 cases (a 97% increase), the United Kingdom with 233 cases (a 2% increase), and France with 155 cases (a 46% increase).

Small and medium-sized businesses (SMBs) with up to 200 employees and revenues up to $25 million experienced the most ransomware attacks. This data aligns with th

“SMBs are attractive targets for ransomware attacks because they often lack security staff and tools and operate within limited cybersecurity budgets — all of which are essential to safeguard their systems,” says Noreika. “Smaller organizations are also more likely to rely on outdated software, have limited security monitoring, and  rely on external vendors for IT support. Consequently, when attacked, they’re more likely to pay ransoms quickly to avoid business disruptions, which is why ransomware groups keep targeting them.”

The most-targeted ransomware-victim company profile in 2025

As in 2024, companies in the manufacturing industry continued to bear the brunt of ransomware attacks, with 1,156 incidents in 2025 (a 32% increase from the previous year), accounting for 19.3% of all cases (a 0.3% increase from 2024). 

The manufacturing industry was followed by the IT industry, with 524 recorded cases (a 35% increase from 2024), professional, scientific, and technical services (494 incidents, a 30% increase), the construction industry (443 incidents, a 24% increase), and healthcare, with 339 attacks (a 6% decrease from 2024).

Experts from NordStellar analyzed the ransomware attacks on companies in the manufacturing industry. They found that SMBs (those with up to 200 employees and $25M in revenue) operating in the general manufacturing industry were the most targeted. They were followed by other smaller businesses operating in the machinery manufacturing sector (10% of all attacks on the manufacturing industry), and SMBs operating in the appliances, electrical, and electronics manufacturing sector, accounting for 9.9% of all ransomware attacks on the manufacturing industry.

“Cybercriminals prioritize choosing targets that offer the biggest payoff for the least amount of effort, and SMBs in the manufacturing industry fit this perfectly — they generate enough revenue to pay large ransoms but usually don’t have the capacity to implement strong security measures or fast recovery options,” says Noreika.

According to Noreika, manufacturing companies are in a difficult position — their production lines can’t stop for long periods, so even short disruptions can cause significant financial losses. Consequently, they’re pressured to do anything it takes to continue their operations — even if it means giving in to the attackers’ demands.

“Machinery and industrial equipment manufacturers were also heavily targeted — this could be the result of expanded digitalization and remote connectivity in production environments,” says Noreika. “Meanwhile, appliance and electronics manufacturers are facing a higher risk of experiencing a cyberattack due to complex supplier integration and cloud-based operations.”

According to Noreika, interconnected environments increase the likelihood of lateral compromise, which can occur through shared networks or third‑party access.

The ransomware group landscape: Qilin takes the lead

Data reveals that the ransomware group Qilin carried out the most attacks in 2025, with 1,066 cases (a 408% increase compared to 2024). It was followed closely by Akira, with 947 recorded ransomware cases (a 125% increase), then the-remerged Cl0p leaks (594 cases, a 525% increase), the relatively new, rapidly growing ransomware threat actor Safepay (464 cases, a 775% increase), and INC ransom, with 442 recorded cases (an 83% increase compared to 2024).

“The changes in the ransomware threat actor landscape reflect how competitive the ransomware-as-a-service world has become,” says Noreika. “Groups like Qilin experienced significant growth because many affiliates joined their operations after other platforms were shut down or became less profitable. Affiliates choose which ransomware to use based on better payment structure, support, the reliability of the tools provided, or reputation of success.”

He underscores that Akira could have expanded for similar reasons. According to Noreika, the emergence of new ransomware names suggests that groups often rebrand or start fresh operations when facing law‑enforcement pressure. He notes that the activity of LockBit, one of the most active groups in 2024, witnessed a significant decline in 2025 due to successful law enforcement operations. 

Incidents peak, but targets remain the same: What’s next?

According to the findings, the number of ransomware cases peaked in the last quarter of 2025, with 2,910 recorded incidents, marking a 38% increase compared to the same period in 2024 (2,102 cases) and a 49% increase from the number of incidents recorded in the July-September period of 2025 (1,954 cases).

The data from the final quarter of 2025 mirrored the findings from throughout the year — small and medium-sized manufacturers remained the primary target. For more details on the findings on ransomware cases in 2025 Q4, read here.

“The success of end-of-year attacks is concerning — this will likely motivate the ransomware groups to repeat these timing patterns at the end of 2026 as well,” says Noreika. “Businesses, especially SMBs and those operating in industries where operational downtime is unacceptable, or that handle high-value data, should be on high alert and reassess their preparedness to combat ransomware.”

To increase their resilience against ransomware attacks, Noreika advises companies to strengthen their basic security hygiene. This includes updating and patching systems and applications, using multifactor authentication, implementing password management policies, and enforcing the zero trust framework to prevent malware from spreading laterally.

“For early threat prevention and detection, intelligence is key — it enables businesses to patch critical vulnerabilities and detect indicators of compromise as soon as possible,” says Noreika. “Data leaked onto the dark web may expose credentials or sensitive details that attackers can exploit to gain unauthorized access. An early alert enables organizations to reset passwords, revoke access keys, disable compromised accounts, and support faster incident response.”

Noreika explains that having a ransomware incident-response plan is crucial for reducing the scope of damage from an attack as soon as possible. He also emphasizes the importance of having a recovery plan as well as backing up critical data to minimize operational downtime.

Disclaimer: While the total number of 9,251 ransomware attacks in 2025 is accurate, the figures presented for each category (industry, company size, and country) may be slightly higher. This is because a number of incidents were missing data needed for categorization and thus were omitted.

Guest Post – Malicious employees for hire: How dark web criminals recruit insiders

Posted in Commentary with tags on January 6, 2026 by itnerd

Cybercriminals can use malicious insiders as a direct means to access sensitive company resources, stealing confidential data or using the access to deploy a devastating cyberattack. Experts from NordStellar, a threat exposure management platform, have discovered that dark web actors are actively seeking insiders from specific organizations to recruit for their operations.

Researchers at NordStellar found 25 unique dark web posts from users who claim that they are searching for employees from specific organizations over the past year. A significant part of these posts focuses explicitly on insiders who work for social media or cryptocurrency platforms.

Real‑world incidents highlight how these threats can translate into actual breaches — for instance, in 2025, the cryptocurrency exchange platform Coinbase revealed that cybercriminals bribed its employees to leak user information.

“Employees can grant cybercriminals access to critical data, such as personal customer information and confidential business agreements,” says Vakaris Noreika, cybersecurity expert at NordStellar. “This data can be utilized to deploy ransomware attacks, sell intel on  business agreements to competitors, or to  carry out sophisticated phishing scams on unsuspecting victims whose personal data they managed to get their hands on.”

According to Noreika, insider threats can be challenging to spot and, therefore, may go undetected by security teams for a significant amount of time. Employees are trusted members of the organization and have legitimate access to company resources. Consequently, it can be challenging to pinpoint any anomalies in their behavior.

“Unlike external threats, insiders may not trigger typical security alerts, such as unusual login attempts or data transfers,” says Noreika. “Insiders are also familiar with the organization’s internal security policies and weaknesses, allowing them to adjust their actions to avoid suspicion.”

Direct insider recruitment

Noreika emphasizes that although some cybercriminals are searching for insiders on the dark web, the recruitment process is usually carried out privately. Bad actors target specific employees within the organization, especially those with technical capabilities that aid in their operations or have access to highly sensitive company data.

Mantas Sabeckis, a senior threat intelligence researcher at Nord Security, home to NordStellar and other advanced cybersecurity solutions, shares that he has been contacted by cybercriminals for possible recruitment opportunities numerous times. He explains that in the past, bad actors have reached out to him on LinkedIn, most likely intrigued by his experience in cybersecurity, and notes that the process of cybercriminals recruiting insiders likely follows the same playbook.

“In my experience, after the first few messages, bad actors try to direct the communication to a different channel, such as Telegram or WhatsApp,” says Sabeckis. “One time, I was contacted by a recruitment specialist from Singapore searching for a candidate for a role in a large organization. She did not name the specific organization and asked to continue our conversation on WhatsApp, which is not an unusual request in itself, as different messaging platforms are popular in different countries.”

According to Sabeckis, after their conversation moved to WhatsApp, the recruiter started sharing more details — she explained that she was looking to recruit an individual to work for a wealthy and influential family in Singapore, without disclosing which one.

“The statement definitely raised red flags, but I was curious to hear what exactly they were looking for,” says Sabeckis. “She continued to explain that the role would be similar to a bug bounty. When asked for more details, the recruiter finally divulged that they were looking for an individual to take down websites containing very sensitive and illegal material, offering to provide compensation in cryptocurrency.”

Sabeckis explains that, by its nature, the role fell into a “gray area,” which is a common tactic used by bad actors to recruit individuals. After the recruited individuals have their foot in the door, the tasks eventually become more demanding. Evidence of the individuals completing the tasks is later used as leverage to blackmail the person into carrying out illegal activity or risk being compromised.

Safeguarding against insider threats

Noreika emphasizes that high observability into system and data usage is the foundation of an insider threat-resistant cybersecurity strategy. He explains that any unexpected system behavior or access patterns must be flagged, reported, and thoroughly examined.

“Patterns of unusual behaviour are the first indicator that the user might be an insider,” says Noreika. “Security teams should keep an eye out for employees who are frequently accessing sensitive information and make sure that they have the proper authorization. Data exfiltration to external parties or devices is another major red flag to look out for.”

He explains that data loss prevention tools are essential for reducing the possibility of data theft and transfer from within. Proper network segmentation and the implementation of strong access controls to prevent privilege drift, the accumulation of excess access rights, are other necessary security measures to stop insiders and attackers who have already infiltrated the network from acquiring sensitive data.

“Dark web monitoring for information leaks or posts looking for insiders at the company is also crucial,” says Noreika. “It can be the first warning sign that a company might be at greater risk of being exposed. After flagging such activity, it’s necessary to stay on high alert and ensure that all of the precautionary measures, as well as a recovery plan, are in place.”

According to Noreika, an incident recovery plan is a significant requisite in minimizing the fallout of a cyberattack caused by insider threats. An effective recovery plan should cover incident detection and outline the key steps the organization should take to contain the threat and mitigate damage.

These steps may include removing the malicious employee’s access to sensitive data and ensuring that an external attacker who has been working with the insider connection to the network has been terminated.

ABOUT NORDSTELLAR

NordStellar is a next-generation threat exposure management platform that enables companies to detect and respond to cyber threats before they escalate. It includes solutions like dark web and data breach monitoring, helping to prevent account takeovers, session hijacking, and other threats. NordStellar was created by Nord Security, a globally recognized company behind one of the world’s most popular digital privacy tools, NordVPN. For more information, visit nordstellar.com

Guest Post – Betrayal by employees: Dark web cybercriminals selling services built on insider data

Posted in Commentary with tags on December 9, 2025 by itnerd

New findings from the dark web reveal that cybercriminals are selling insider data-backed services

Malicious employees, also known as insider threats, can cause significant harm to businesses by leaking or selling sensitive data, altering systems, or collaborating with cybercriminals to launch large-scale cyberattacks. New findings from NordStellar, a threat exposure management platform, reveal that bad actors are now advertising and selling insider data-backed services on the dark web — profiting from employees of industry giants who have decided to go rogue.

The team at NordStellar has found 35 dark web posts claiming to sell services based on insider data so far this year. Some of the services for sale on the dark web claim to have direct connections to insiders from such well-known companies as Facebook, Instagram, and Amazon.

“The majority of the posts discovered by NordStellar’s team offer various look-up services, exposing sensitive user information, such as IP addresses,  full names, email addresses, phone numbers, and even physical addresses,” says Vakaris Noreika, a cybersecurity expert at NordStellar. “Aside from violating the user’s privacy, this information can be used to launch highly targeted phishing scams or to commit fraud — or even identity theft.”

The posts reveal that look-up services can start at $500, offering the user’s phone number and linked email address. Advanced packages, which contain even more sensitive user information, such as IP addresses, physical addresses, date of birth, and other confidential details, can be purchased for $1,000 or more.

“Other popular services include account recovery and unbanning. The former can be especially damaging to the brand because users are often banned for violating the company’s policies or engaging in fraudulent activity,” says Noreika. “As a result, individuals who have been using the company’s services for scams can continue to do so, acquiring more victims and damaging the brand’s reputation in the process.”

Spotting and stopping insider threats

Noreika explains that insider threats are complex, and to safeguard against malicious employees, companies must have a comprehensive cybersecurity strategy in place. He emphasizes high observability and behavioural analysis as the two main pillars for resilience.

“The first key step is to ensure high observability into user actions — once security teams achieve visibility, they can look for anomalies in employee behavior, triggering the first alarms about potential malicious activity,” Noreika says. “Security teams should assess whether there’s any potentially dangerous patterns in activity, for example, if a user is accessing sensitive information without justification or if there are any signs of them exfiltrating that information to external sources, like their own personal devices, accounts, or third parties.”

He underscores the importance of proper network segmentation and the principle of least privilege in general to prevent users from accessing sensitive information that isn’t necessary for their work. According to Noreika, to prevent employees from sharing and downloading unauthorized files, data loss prevention tools are also required.

“Consistent monitoring is another key asset — if prior security measures failed to stop the user from retrieving and exfiltrating the data, it’s crucial to mitigate the threat before it can escalate further,” says Noreika. “Monitoring the dark web for posts mentioning the company, especially those claiming to sell services fueled by insider data, should be prioritized. Once the potential threat is spotted, security teams can inspect its validity and, if the claims turn out to be legitimate, stop the employee from doing further damage and inform affected users to be on high alert before cybercriminals can deploy their attacks.”

To effectively mitigate the damage inflicted by malicious insiders, Noreika advises companies to prepare an incident response plan in advance. The plan should outline the detection and investigation process, as well as the steps for containing the threat, eradicating the user’s access to company data and recovering systems if attackers compromise them in the process.

ABOUT NORDSTELLAR

NordStellar is a next-generation threat exposure management platform that enables companies to detect and respond to cyber threats before they escalate. It includes solutions like dark web and data breach monitoring, helping to prevent account takeovers, session hijacking, and other threats. NordStellar was created by Nord Security, a globally recognized company behind one of the world’s most popular digital privacy tools, NordVPN. For more information, visit nordstellar.com

NordStellar introduces brand protection to help companies combat fraud and impersonation at large

Posted in Commentary with tags on October 28, 2025 by itnerd

Bad actors use fraud and impersonation tactics to trick customers into handing over their money or sensitive data while posing as trusted brands. NordStellar has introduced its new brand protection service that monitors the web, social media, and app stores for fraudulent activity, providing brands with actionable insights into fraud and impersonation cases to safeguard their reputation and protect their customers.

Earlier this year, NordStellar introduced its cybersquatting detection feature to help companies combat bad actors that use fake domain names to profit from trademarks belonging to legitimate businesses. The brand protection service takes it a step further by monitoring the publicly available internet to detect fraudulent websites and phishing sites, fake profiles and impersonators on social media platforms, as well as cloned or malicious apps on app stores. Once an incident of fraud or impersonation is detected, NordStellar initiates takedown processes to remove the threats.

How it works:

  • Continuously monitors the web, social media, and app stores for any fraudulent activity.
  • Analyzes the available data to detect anomalies, suspicious activity, or inputs from unauthorized sources.
  • Initiates takedown processes for detected fake websites, social media scams, app store counterfeits, and other forms of brand abuse.
  • Offers detailed monthly performance reports that provide businesses with a complete summary of all detected, resolved, and removed threats.

The brand protection service is now available to all NordStellar users. More information here.