Chinese Courts Hand Down 16-Year and 32-Year Sentences to Ransomware Operators
Chinese courts have imposed significant prison sentences on two ransomware operators, marking a notable escalation in the prosecution of cyber extortion cases. One defendant received a 16-year term while the second was sentenced to 32 years, reflecting the severity of their respective roles in ransomware campaigns.
The longer sentence was linked to more extensive criminal activity, including the deployment of ransomware that caused substantial financial losses and operational disruption. Authorities emphasized that the cases demonstrate a firm stance against ransomware groups targeting organizations or individuals within China.
These verdicts are part of a wider pattern of increased enforcement actions against ransomware actors. Chinese law enforcement has intensified investigations into encryption-based extortion schemes, leading to multiple high-profile prosecutions in recent years.
Related articles
VantaCore Ransomware Group Targets Russian Businesses with Custom Toolkit and Triple Extortion
Security researchers at F6 have identified a new ransomware operation called VantaCore that is actively attacking small and medium-sized Russian companies. The group employs a custom set of tools including VantaCoreLoader, VantaCoreRAT, and its own encryption malware to conduct double and triple extortion campaigns. Initial access is gained through poorly secured RDP and VPN services, vulnerable public applications, and compromised partner accounts. Once inside the network, attackers move laterally using SMB and RDP with legitimate credentials, deploy Tactical RMM, and install their backdoor before disabling security products with an AV/EDR killer. Victims face data theft, backup destruction, and encryption, followed by threats to publish or sell stolen information if ransom demands in the millions of dollars are not met. F6 assesses that VantaCore may be a rebranded version of the previously known pro-Ukrainian group Thor, based on similar Tor negotiation chat design and a THOR rune icon on the leak site that appeared no later than June 7, 2026.
Boston Scientific Hit by Cyber Attack: Global IT Outage Disrupts Orders and Shipments, Shares Drop
On August 25, Boston Scientific detected a cyber attack that compromised parts of its IT infrastructure, leading to widespread network interruptions across its global operations. The medical device giant, which generates over $16 billion in annual revenue and operates in more than 130 countries, saw customer order processing and product shipments halted in multiple regions. Wall Street Journal and Reuters reported the incident on August 26, after which the company's stock declined. While China operations remained unaffected due to regional system isolation, the company stated that full global recovery timelines remain unknown. The attack's specific methods, including any potential ransomware involvement or data exfiltration, have not been disclosed as third-party investigators continue their work. The event underscores the severe operational and patient-care risks when healthcare supply chains face cyber disruptions.
Aurora Ransomware Affiliate Uses AI Assistant Cursor to Compromise Active Directory and VMware ESXi Servers
An affiliate of the Aurora ransomware group employed the AI-powered coding assistant Cursor to plan and execute targeted attacks against corporate environments, focusing on Active Directory and VMware ESXi servers. The campaign impacted more than 20 organizations between April and July 2026. The operator used Cursor to generate commands, refine exploitation techniques, and build attack sequences aimed at Windows infrastructure, particularly Active Directory Certificate Services (ADCS). Techniques included noPac exploitation combined with NTLM relay attacks leveraging PetitPotam, PrinterBug, and DFSCoerce to escalate privileges up to domain administrator level. After gaining access, the attackers collected and compressed large volumes of data for exfiltration before deploying the Aurora ransomware on Windows, Linux, and ESXi systems. The ESXi variant stops virtual machines prior to encryption to maximize impact on virtualized environments.
7 Core Rules for Responding to Ransomware and Infrastructure Breaches
The article outlines practical first-response steps for organizations facing ransomware encryption or infrastructure compromise for the first time. It stresses isolating affected systems from the network without powering them down, preserving volatile data and logs, and avoiding premature cleanup or backup restoration. The guidance covers closing obvious compromised access paths, documenting observed facts and actions, and stopping further ad-hoc changes once containment is achieved. These measures help retain forensic artifacts that investigators need to determine the initial access vector and attacker movement. The rules are presented as a starting point for teams without formal incident response procedures.