Reynolds side-loaded-loader and GotoHTTP ransomware campaign
Campaign
Summary
Hide ▲
Show ▼
The Reynolds ransomware operation now shows pre-deployment staging and post-deployment access tooling, increasing the likelihood of persistent compromise on the target network. A side-loaded loader appeared weeks before ransomware deployment, and GotoHTTP was later deployed after the ransomware event. That sequence indicates a coordinated intrusion path rather than a single isolated payload drop.
Related Happenings
Medusa ransomware post-compromise deployment
Malware Activity
First: 07.04.2026 09:35
Last: 07.04.2026 09:35
Sources 1
About this happening:
**Medusa ransomware** is being deployed rapidly after initial access, turning intrusions into fast-moving extortion events and shrinking defenders' response time. The malware acti...
Medusa ransomware post-compromise deployment
Malware ActivityAbout this happening: **Medusa ransomware** is being deployed rapidly after initial access, turning intrusions into fast-moving extortion events and shrinking defenders' response time. The malware acti...
Storm-1175 high-velocity zero-day and N-day intrusion campaign
Campaign
First: 07.04.2026 09:35
Last: 07.04.2026 09:35
Sources 1
About this happening:
**Storm-1175** is running a **high-velocity intrusion campaign** that chains **zero-day** and **N-day vulnerabilities** to gain initial access to exposed systems, raising the risk...
Storm-1175 high-velocity zero-day and N-day intrusion campaign
CampaignAbout this happening: **Storm-1175** is running a **high-velocity intrusion campaign** that chains **zero-day** and **N-day vulnerabilities** to gain initial access to exposed systems, raising the risk...
Beast ransomware group’s RaaS model and shared TTPs exposed through an open server
Threat Actor Meta
First: 20.03.2026 18:31
Last: 20.03.2026 18:31
Sources 1
About this happening:
An exposed **Beast ransomware group** server now shows its **RaaS operating model** and reusable toolset, complicating attribution across ransomware crews. The recovered materials...
Beast ransomware group’s RaaS model and shared TTPs exposed through an open server
Threat Actor MetaAbout this happening: An exposed **Beast ransomware group** server now shows its **RaaS operating model** and reusable toolset, complicating attribution across ransomware crews. The recovered materials...
2025 Ransomware trend toward built-in Windows tooling and lower ransom payment rates
Target Trend
First: 17.03.2026 23:41
Last: 17.03.2026 23:41
Sources 1
About this happening:
**Ransomware operators** are increasingly leaning on **built-in Windows tooling** while **ransom payment rates** continue to decline across **2025**, weakening extortion returns f...
2025 Ransomware trend toward built-in Windows tooling and lower ransom payment rates
Target TrendAbout this happening: **Ransomware operators** are increasingly leaning on **built-in Windows tooling** while **ransom payment rates** continue to decline across **2025**, weakening extortion returns f...
Hive0163 extortion and ransomware campaign using ClickFix and malvertising
Campaign
First: 12.03.2026 19:02
Last: 12.03.2026 19:02
Sources 1
About this happening:
Hive0163 is running an **active extortion and ransomware campaign** that expands access and raises the risk of **large-scale data exfiltration**. The operation uses **ClickFix**,...
Hive0163 extortion and ransomware campaign using ClickFix and malvertising
CampaignAbout this happening: Hive0163 is running an **active extortion and ransomware campaign** that expands access and raises the risk of **large-scale data exfiltration**. The operation uses **ClickFix**,...
Timeline
-
10.02.2026 16:36 2 articles · 3mo ago
Reynolds campaign pairs a side-loaded loader with GotoHTTP access
Campaign Scope UpdateReynolds ransomware activity included a suspicious side-loaded loader on the affected target network several weeks before ransomware deployment, followed by GotoHTTP on the target network a day after deployment, indicating a coordinated intrusion path and an apparent attempt to maintain persistent access after encryption.
Show sources
- Reynolds Ransomware Embeds BYOVD Driver to Disable EDR Security Tools — thehackernews.com — 10.02.2026 16:36
- Reynolds Ransomware Embeds BYOVD Driver to Disable EDR Security Tools — thehackernews.com — 10.02.2026 16:36