Indicators are what attackers leave behind. Stolen credentials are what they arrive with.
critical threatRansomwareMalware Family
Historical
BlackCat
Critical severity
15
IOCs Tracked
—
First Seen
—
Last Seen
0
YARA Rules
Associated IOCs15 total · showing 15
IP12
192.42.116.972026-09-22High
192.42.116.502026-09-22High
104.164.55.462026-09-22High
192.42.116.522026-09-22High
104.28.162.2282026-09-22High
37.19.210.122026-09-22High
149.102.229.1542026-09-22High
64.190.76.142026-09-22High
104.28.163.1622026-09-22High
192.42.116.122026-09-22High
192.42.116.562026-09-22High
146.70.117.2392026-09-22High
CVE1
CVE-2026-201312026-08-11High
Related Reports6 shown
Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
SecurelistSep 21, 2026
BlackCat Ransomware: Tactics, Techniques & Mitigation Strategies
Group-IB
The Branding and Attribution Behind Cybercrime
Check Point BlogJul 27, 2026
Typosquatting: When Your Domain Is Used Against You
TruesecJun 11, 2026
IT threat evolution in Q1 2026. Non-mobile statistics
SecurelistMay 18, 2026
How to Recover from a Ransomware Attack Without Paying the Ransom
SeqriteMay 25, 2026
Threat Profile
TypeRansomware
StatusHistorical
IOCs tracked15