<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>DarkWebSonar Blog</title>
    <link>https://darkwebsonar.io/blog</link>
    <description>Dark web threat intelligence, ransomware tracking, and cybersecurity insights.</description>
    <language>en-us</language>
    <lastBuildDate>Sat, 02 May 2026 10:00:00 GMT</lastBuildDate>
    <atom:link href="https://darkwebsonar.io/rss.xml" rel="self" type="application/rss+xml"/>
  <item>
    <title><![CDATA[Dark Web Most Wanted: DimasHxR]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2026-dimashxr</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2026-dimashxr</guid>
    <pubDate>Sat, 02 May 2026 10:00:00 GMT</pubDate>
    <description><![CDATA[DimasHxR ranks second among all threat actors tracked by DarkWebSonar in the last 90 days with 508 incidents — yet carries zero open-source footprint. Weekly telemetry shows a surge peak of 150 incidents in April 2026 followed by a 61% decline, revealing a campaign lifecycle that makes continuous monitoring essential.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>defacement</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: Keymous+]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2026-keymous-plus</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2026-keymous-plus</guid>
    <pubDate>Tue, 24 Feb 2026 10:00:00 GMT</pubDate>
    <description><![CDATA[Keymous+ is a DDoS-specialist hacktivist group with over 1,400 incidents tracked by DarkWebSonar, heavily targeting Morocco, France, India, Egypt, and Israel. Government, technology, and financial sectors bear the brunt of their Telegram-driven operations.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>hacktivism</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: NoName057(16)]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2026-noname057</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2026-noname057</guid>
    <pubDate>Fri, 16 Jan 2026 10:00:00 GMT</pubDate>
    <description><![CDATA[NoName057(16) is the most active threat actor tracked by DarkWebSonar, with 894 incidents in the last 90 days and 5,500+ total incidents. Their campaigns are heavily concentrated in Europe, making them a sustained, high-tempo disruption threat for European organizations.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>hacktivism</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: MEDUSA]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2025-medusa</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2025-medusa</guid>
    <pubDate>Tue, 02 Dec 2025 10:00:00 GMT</pubDate>
    <description><![CDATA[MEDUSA has established itself as one of the most persistent ransomware groups of 2025, with 201 confirmed victim postings tracked by DarkWebSonar. With 61.7% of victims in the United States and strong targeting of construction, healthcare, and education sectors, MEDUSA represents a critical threat.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>ransomware</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: CL0P]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2025-cl0p</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2025-cl0p</guid>
    <pubDate>Thu, 20 Nov 2025 10:00:00 GMT</pubDate>
    <description><![CDATA[CL0P has re-emerged as one of the most dangerous ransomware groups of 2025, with a massive 1,028% surge in activity. With 480 incidents tracked by DarkWebSonar and a strategic focus on U.S. enterprises, CL0P represents a critical threat to organizations worldwide.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>ransomware</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: HEZI RASH]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2025-hezi-rash</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2025-hezi-rash</guid>
    <pubDate>Tue, 04 Nov 2025 10:00:00 GMT</pubDate>
    <description><![CDATA[HEZI RASH has rapidly emerged as one of the most prolific hacktivist groups of 2025, with 856 incidents tracked by DarkWebSonar in just over three months. Dominated by DDoS attacks, the group targets 38 countries across government, media, and education sectors.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>hacktivism</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: Sinobi Ransomware]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2025-sinobi</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2025-sinobi</guid>
    <pubDate>Sat, 25 Oct 2025 10:00:00 GMT</pubDate>
    <description><![CDATA[Sinobi ransomware resurged in October 2025 after a brief lull, recording 61 new incidents targeting U.S. construction, healthcare, and manufacturing sectors. DarkWebSonar data reveals its evolution from the Lynx codebase into a mature RaaS operation.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>ransomware</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: NOTCTBER404]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2025-notctber404</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2025-notctber404</guid>
    <pubDate>Mon, 13 Oct 2025 10:00:00 GMT</pubDate>
    <description><![CDATA[NOTCTBER404 surged onto the scene in late 2025, launching over 100 DDoS attacks primarily across Southeast Asia and forming an alliance with HEZI RASH. DarkWebSonar data reveals how fast this new hacktivist group is expanding.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>hacktivism</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: Akira]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2025-akira</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2025-akira</guid>
    <pubDate>Sun, 28 Sep 2025 10:00:00 GMT</pubDate>
    <description><![CDATA[Akira has surged to become one of the top ransomware groups of 2025, with over 570 incidents tracked by DarkWebSonar and a disproportionate focus on U.S. enterprises.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>ransomware</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: DarkStorm Team]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2025-darkstorm-team</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2025-darkstorm-team</guid>
    <pubDate>Mon, 15 Sep 2025 10:00:00 GMT</pubDate>
    <description><![CDATA[DarkStorm Team surged with over 800 tracked incidents in 2025, dominated by large-scale DDoS campaigns targeting Israel, the U.S., and NATO allies—making them one of the most disruptive hacktivist groups this year.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>hacktivism</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: Qilin]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2025-qilin</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2025-qilin</guid>
    <pubDate>Fri, 29 Aug 2025 10:00:00 GMT</pubDate>
    <description><![CDATA[Qilin tops DarkWebSonar's Dark Web Most Wanted list with 442 victims in 2025, targeting industries from construction to healthcare with aggressive double-extortion tactics.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>ransomware</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Monitoring for MSPs]]></title>
    <link>https://darkwebsonar.io/blog/darkweb-monitoring-for-msps</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/darkweb-monitoring-for-msps</guid>
    <pubDate>Fri, 22 Aug 2025 17:23:00 GMT</pubDate>
    <description><![CDATA[For MSPs, offering this as a service means not just reacting to breaches, but proving measurable value by detecting exposures before they become full incidents.]]></description>
    <author>Security Research Team</author>
    <category>msp</category>
    <category>threat-intelligence</category>
    <category>cybersecurity</category>
  </item>
  <item>
    <title><![CDATA[DarkWebSonar API Integration Best Practices]]></title>
    <link>https://darkwebsonar.io/blog/api-integration-best-practices</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/api-integration-best-practices</guid>
    <pubDate>Fri, 01 Aug 2025 09:15:00 GMT</pubDate>
    <description><![CDATA[Learn how to effectively integrate DarkWebSonar's API into your security operations workflow with practical examples and best practices.]]></description>
    <author>Engineering Team</author>
    <category>api</category>
    <category>integration</category>
    <category>tutorial</category>
  </item>
  <item>
    <title><![CDATA[What Is Dark Web Monitoring? Meet DarkWebSonar]]></title>
    <link>https://darkwebsonar.io/blog/introducing-darkwebsonar</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/introducing-darkwebsonar</guid>
    <pubDate>Thu, 29 May 2025 10:00:00 GMT</pubDate>
    <description><![CDATA[What is dark web monitoring and why does it matter? DarkWebSonar tracks ransomware groups, dark web forums, and data leaks in real time — so security teams can act fast.]]></description>
    <author>DarkWebSonar Team</author>
    <category>announcement</category>
    <category>threat-intelligence</category>
    <category>cybersecurity</category>
  </item>
  </channel>
</rss>
