Find notable cyber news and cases, enriched with sources, timelines, and signals.

Reynolds side-loaded-loader and GotoHTTP ransomware campaign

Campaign
First reported
Last updated
Happening score
H score 40
1 unique sources, 1 articles

Summary

Hide ▲

The Reynolds ransomware operation now shows pre-deployment staging and post-deployment access tooling, increasing the likelihood of persistent compromise on the target network. A side-loaded loader appeared weeks before ransomware deployment, and GotoHTTP was later deployed after the ransomware event. That sequence indicates a coordinated intrusion path rather than a single isolated payload drop.

Related Happenings

Medusa ransomware post-compromise deployment

Malware Activity
First: 07.04.2026 09:35 Last: 07.04.2026 09:35 Sources 1

About this happening: **Medusa ransomware** is being deployed rapidly after initial access, turning intrusions into fast-moving extortion events and shrinking defenders' response time. The malware acti...

Storm-1175 high-velocity zero-day and N-day intrusion campaign

Campaign
First: 07.04.2026 09:35 Last: 07.04.2026 09:35 Sources 1

About this happening: **Storm-1175** is running a **high-velocity intrusion campaign** that chains **zero-day** and **N-day vulnerabilities** to gain initial access to exposed systems, raising the risk...

Beast ransomware group’s RaaS model and shared TTPs exposed through an open server

Threat Actor Meta
First: 20.03.2026 18:31 Last: 20.03.2026 18:31 Sources 1

About this happening: An exposed **Beast ransomware group** server now shows its **RaaS operating model** and reusable toolset, complicating attribution across ransomware crews. The recovered materials...

2025 Ransomware trend toward built-in Windows tooling and lower ransom payment rates

Target Trend
First: 17.03.2026 23:41 Last: 17.03.2026 23:41 Sources 1

About this happening: **Ransomware operators** are increasingly leaning on **built-in Windows tooling** while **ransom payment rates** continue to decline across **2025**, weakening extortion returns f...

Hive0163 extortion and ransomware campaign using ClickFix and malvertising

Campaign
First: 12.03.2026 19:02 Last: 12.03.2026 19:02 Sources 1

About this happening: Hive0163 is running an **active extortion and ransomware campaign** that expands access and raises the risk of **large-scale data exfiltration**. The operation uses **ClickFix**,...

Timeline

  1. 10.02.2026 16:36 2 articles · 3mo ago

    Reynolds campaign pairs a side-loaded loader with GotoHTTP access

    Campaign Scope Update

    Reynolds ransomware activity included a suspicious side-loaded loader on the affected target network several weeks before ransomware deployment, followed by GotoHTTP on the target network a day after deployment, indicating a coordinated intrusion path and an apparent attempt to maintain persistent access after encryption.

    Show sources