Blog

What we see

Research from our own monitoring and analysis platform. First-party data, with the methodology behind it.

Research

We called it the encryptor. It was the decryptor.

Three Akira binaries, run through our own static analysis platform. All three came back malicious on the same evidence, and the third is the ESXi decryptor the operators send once you pay. Hashes and full analysis output in the post.

5 August 2026 · Read the post →

Research

721 victims in 30 days: what ransomware leak sites actually show

We crawl 25 ransomware leak sites nightly over Tor. In one month they posted 721 victims from 58 groups. Per-group counts, how much of that infrastructure is live at all, and where Greece came into the month.

25 July 2026 · Read the post → · Ελληνικά