Malware

Ransomlooker, a new tool to track and analyze ransomware groups’ activities

Ransomlooker monitors ransomware groups’ extortion sites and delivers consolidated feeds of their claims worldwide.

Cybernews presented Ransomlooker, a tool to monitor ransomware groups’ extortion sites and delivers consolidated feeds of their claims worldwide.

The researchers have created the tool to help cybersecurity experts in their daily jobs by providing real-time updates and actionable insights. It offers various statistical insights into data, the ability to determine attack perpetrators, and incorporates filtering by country, industries, time span, and other parameters for journalistic investigations.

Tool advantages:

  • It’s free of charge
  • The tool uses algorithms for continuous monitoring and analysis
  • This tool updates information at the same hour as new victims are leaked
  • The data is always fresh and carefully curated by the security and research team to ensure the utmost quality
  • It is designed for accessibility and ease of use for all

With a broad range of knowledge in various cyber security topics, the experienced Cybernews researchers team can give detailed comments on ransomware attacks and analyze different threat actors’ activities in-depth.

“Our ransomware monitoring tool, Ransomlooker, employs advanced algorithms to track and analyze ransomware groups’ activities continuously. It constantly scans the dark web and other hidden corners of the internet where ransomware operators tend to operate, identifying new extortion sites and monitoring their claims. By aggregating and consolidating this data, Ransomlooker provides real-time updates and actionable insights to its users, helping them stay one step ahead of potential threats.” reads the announcement. “With Ransomlooker, you can proactively safeguard your business or personal data from ransomware attacks. Our tool ensures you are promptly informed about emerging ransomware campaigns and the tactics used by attackers. By staying vigilant and informed, you can take timely measures to protect your systems and data, reducing the risk of falling victim to ransomware.”

You can access Ransomlooker here:

https://cybernews.com/ransomlooker/

 

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Ransomlooker)

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Check Point patches actively exploited SmartConsole authentication bypass flaw

Check Point addressed a critical authentication bypass flaw, tracked as CVE-2026-16232, in SmartConsole that is…

2 hours ago

CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections

Qualys disclosed CVE-2026-8933, a high-severity Ubuntu flaw that lets local attackers gain root privileges through…

12 hours ago

Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft

Adobe patched CVE-2026-48294, a flaw in Adobe Acrobat Chrome extension that could let attackers steal…

13 hours ago

U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds DD-WRT, Langflow, and WordPress flaws to its…

1 day ago

OpenAI AI models exploited zero-days to reach Hugging Face in benchmark test

OpenAI confirmed its AI models exploited zero-days during internal testing, reaching Hugging Face servers in…

1 day ago

Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522

Critical SharePoint RCE vulnerability CVE-2026-50522 is under active exploitation after the release of a PoC…

2 days ago

This website uses cookies.