Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-06-22
Ransomware·2026-06-22

Ransomware Watch · Jun 22, 2026

Data source: RansomLook /api/posts?days=1 (public endpoint, direct connection succeeded). Window covers the past ~24h (discovered 2026-06-20 → 2026-06-21).
No overlap with the 2026-06-21 brief (window 06-18 → 06-19) — this issue is all net-new posts. RansomLook days=1 returns only group_name / post_title / discovered, with no structured victim sector/geo fields; sector/geography is inferred manually from titles.

Overview

  • Total new posts: 6 (net-new relative to the 06-21 brief: 6)
  • Groups involved: 4 (nova ×2, inc ransom ×2, icarus ×1, nightspire ×1)
  • Watchlist hits: 2 (both inc ransom; watchlist-group hit inc)
  • Most active groups: nova(2), inc ransom(2)

Watchlist Hits (read first)

GroupVictimSectorGeoHitDiscovered
inc ransomNewspaper Media GroupMedia/publishing 📰—group:inc2026-06-20
inc ransomjktornelGeneral business—group:inc2026-06-21

INC Ransom continues its steady 2025–2026 activity, with two listings in a single day this issue; one clearly targets a media/publishing organization (Newspaper Media Group), consistent with INC's long-standing preference for media and local institutions.

All New Posts

GroupVictimSectorGeoDiscovered
icarusDEADLINE MONDAY (countdown post, no named victim)——2026-06-20
inc ransomNewspaper Media GroupMedia/publishing 📰—2026-06-20
novaNhà Thành PhốReal estate/constructionVN2026-06-21
nightspireArtistic SmilesHealthcare/dental 🩺—2026-06-21
novaLockers ITIT services—2026-06-21
inc ransomjktornelGeneral business—2026-06-21

📰/🩺 = sector-sensitive (media / healthcare-dental); not a literal watchlist keyword hit, but high-attention sectors, flagged manually.

Anomalies / Trend Notes

  • icarusposted a "DEADLINE MONDAY"-style countdown — a classic double-extortion pressure tactic (publicly ratcheting up pressure near the payment deadline), continuing the thread from the previous issue where icarus listed Klue.com — this group's activity level warrants continued monitoring.
  • novaposted twice in one day and, for the first time, hit a Vietnamese (VN) target (Nhà Thành Phố) — its geographic coverage is spreading.
  • nightspirehit another dental clinic (Artistic Smiles), forming a streak with 06-21's "dean cosmetic dentistry" — this group shows a clear preference for small/mid-size healthcare/dental practices, a low-barrier opportunistic attack pattern.
  • Only inc ransomfrom the watchlist made the board this issue; qilin (most active last issue) had no new posts in this window.
← Prev
Ransomware Watch · Jun 21, 2026
Next →
Ransomware Watch · Jun 23, 2026