BoletimSecAugust 11, 2026🇵🇹Translated from Portuguese

Ransomware Groups Disable EDR, Backups and Windows Telemetry Before Encryption

Ransomware groups are prioritizing the disablement of security tools, backup systems, and Windows telemetry mechanisms before beginning encryption. The goal is to reduce organizations' ability to detect, contain, and recover from attacks.

An analysis of the ten families with the lowest prevention rates in 2026 showed that Play performed worst, blocking only 13 percent of attacks. BlackByte followed with 25 percent blocked, while LockBit achieved 30 percent blocked.

Among the most common techniques is the interruption or modification of defensive tools. BabLock, for example, uses a legitimate uninstaller to remove endpoint protection and terminates processes related to antivirus, EDR, backup, and database applications. After these steps, the ransomware deletes the Security and System event logs, eliminating critical records for incident response teams and complicating reconstruction of attacker activity.

LockBit 5.0 takes a different approach by interfering with Event Tracing for Windows, the mechanism used by many security solutions to collect events. This change prevents certain information from being recorded and reduces visibility for monitoring tools.

Other families rely on process injection, direct in-memory code execution, registry alterations, file disguise, and abuse of legitimate Windows utilities to conceal their operations.

Related articles

BoletimSecRansomware & Extortion

Ransomware Group TITAN Deploys Local AI on AMD EPYC Servers to Accelerate Stolen Data Analysis

The TITAN ransomware group has announced the integration of an on-premises artificial intelligence platform designed to process up to 700 GB of exfiltrated data per hour. Operating as a ransomware-as-a-service model since May 2026, TITAN combines file encryption with data theft and has already published 24 victims across 10 countries. Manufacturing and professional services firms account for 29 percent of the targeted organizations. The AI system runs locally on AMD EPYC servers with GPU acceleration and automatically classifies financial documents, legal records, personal data, trade secrets, and intellectual property. It further identifies information with high reputational or regulatory impact, maps corporate and personal relationships, and estimates potential penalties under data-protection laws. The group also claims the platform can generate automated notifications to regulators and media outlets to intensify extortion pressure.

AntiMalwareRansomware & Extortion

VantaCore Ransomware Group Targets Russian Businesses with Custom Toolkit and Triple Extortion

Security researchers at F6 have identified a new ransomware operation called VantaCore that is actively attacking small and medium-sized Russian companies. The group employs a custom set of tools including VantaCoreLoader, VantaCoreRAT, and its own encryption malware to conduct double and triple extortion campaigns. Initial access is gained through poorly secured RDP and VPN services, vulnerable public applications, and compromised partner accounts. Once inside the network, attackers move laterally using SMB and RDP with legitimate credentials, deploy Tactical RMM, and install their backdoor before disabling security products with an AV/EDR killer. Victims face data theft, backup destruction, and encryption, followed by threats to publish or sell stolen information if ransom demands in the millions of dollars are not met. F6 assesses that VantaCore may be a rebranded version of the previously known pro-Ukrainian group Thor, based on similar Tor negotiation chat design and a THOR rune icon on the leak site that appeared no later than June 7, 2026.

安全客Ransomware & Extortion

Boston Scientific Hit by Cyber Attack: Global IT Outage Disrupts Orders and Shipments, Shares Drop

On August 25, Boston Scientific detected a cyber attack that compromised parts of its IT infrastructure, leading to widespread network interruptions across its global operations. The medical device giant, which generates over $16 billion in annual revenue and operates in more than 130 countries, saw customer order processing and product shipments halted in multiple regions. Wall Street Journal and Reuters reported the incident on August 26, after which the company's stock declined. While China operations remained unaffected due to regional system isolation, the company stated that full global recovery timelines remain unknown. The attack's specific methods, including any potential ransomware involvement or data exfiltration, have not been disclosed as third-party investigators continue their work. The event underscores the severe operational and patient-care risks when healthcare supply chains face cyber disruptions.

BoletimSecRansomware & Extortion

Aurora Ransomware Affiliate Uses AI Assistant Cursor to Compromise Active Directory and VMware ESXi Servers

An affiliate of the Aurora ransomware group employed the AI-powered coding assistant Cursor to plan and execute targeted attacks against corporate environments, focusing on Active Directory and VMware ESXi servers. The campaign impacted more than 20 organizations between April and July 2026. The operator used Cursor to generate commands, refine exploitation techniques, and build attack sequences aimed at Windows infrastructure, particularly Active Directory Certificate Services (ADCS). Techniques included noPac exploitation combined with NTLM relay attacks leveraging PetitPotam, PrinterBug, and DFSCoerce to escalate privileges up to domain administrator level. After gaining access, the attackers collected and compressed large volumes of data for exfiltration before deploying the Aurora ransomware on Windows, Linux, and ESXi systems. The ESXi variant stops virtual machines prior to encryption to maximize impact on virtualized environments.