<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>DarkWebSonar Blog</title>
    <link>https://darkwebsonar.io/blog</link>
    <description>Dark web threat intelligence, ransomware tracking, and cybersecurity insights.</description>
    <language>en-us</language>
    <lastBuildDate>Mon, 15 Jun 2026 10:00:00 GMT</lastBuildDate>
    <atom:link href="https://darkwebsonar.io/rss.xml" rel="self" type="application/rss+xml"/>
  <item>
    <title><![CDATA[Dark Web Most Wanted: Nova]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2026-nova</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2026-nova</guid>
    <pubDate>Mon, 15 Jun 2026 10:00:00 GMT</pubDate>
    <description><![CDATA[Nova ransomware has logged 129 victim postings across 45 countries since April 2025, with only 13% of victims in the United States. DarkWebSonar telemetry shows a May–June 2026 surge and a RaaS operation rebranded from RALord.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>ransomware</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: DimasHxR]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2026-dimashxr</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2026-dimashxr</guid>
    <pubDate>Sat, 02 May 2026 10:00:00 GMT</pubDate>
    <description><![CDATA[DimasHxR ranks second among all threat actors tracked by DarkWebSonar in the last 90 days with 508 incidents — yet carries zero open-source footprint. Weekly telemetry shows a surge peak of 150 incidents in April 2026 followed by a 61% decline, revealing a campaign lifecycle that makes continuous monitoring essential.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>defacement</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: Keymous+]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2026-keymous-plus</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2026-keymous-plus</guid>
    <pubDate>Tue, 24 Feb 2026 10:00:00 GMT</pubDate>
    <description><![CDATA[Keymous+ is a DDoS-specialist hacktivist group with over 1,400 incidents tracked by DarkWebSonar, heavily targeting Morocco, France, India, Egypt, and Israel. Government, technology, and financial sectors bear the brunt of their Telegram-driven operations.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>hacktivism</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: NoName057(16)]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2026-noname057</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2026-noname057</guid>
    <pubDate>Fri, 16 Jan 2026 10:00:00 GMT</pubDate>
    <description><![CDATA[NoName057(16) is the most active threat actor tracked by DarkWebSonar, with 894 incidents in the last 90 days and 5,500+ total incidents. Their campaigns are heavily concentrated in Europe, making them a sustained, high-tempo disruption threat for European organizations.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>hacktivism</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: MEDUSA]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2025-medusa</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2025-medusa</guid>
    <pubDate>Tue, 02 Dec 2025 10:00:00 GMT</pubDate>
    <description><![CDATA[MEDUSA has established itself as one of the most persistent ransomware groups of 2025, with 201 confirmed victim postings tracked by DarkWebSonar. With 61.7% of victims in the United States and strong targeting of construction, healthcare, and education sectors, MEDUSA represents a critical threat.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>ransomware</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: CL0P]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2025-cl0p</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2025-cl0p</guid>
    <pubDate>Thu, 20 Nov 2025 10:00:00 GMT</pubDate>
    <description><![CDATA[CL0P remains one of the most dangerous ransomware groups tracked by DarkWebSonar, with 635 victim postings since October 2024 and a sustained January–February 2026 campaign wave. With 68.5% of victims in the United States and heavy targeting of manufacturing, technology, and retail, CL0P represents a critical threat to organizations worldwide.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>ransomware</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: HEZI RASH]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2025-hezi-rash</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2025-hezi-rash</guid>
    <pubDate>Tue, 04 Nov 2025 10:00:00 GMT</pubDate>
    <description><![CDATA[HEZI RASH has rapidly emerged as one of the most prolific hacktivist groups of 2025, with 856 incidents tracked by DarkWebSonar in just over three months. Dominated by DDoS attacks, the group targets 38 countries across government, media, and education sectors.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>hacktivism</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: Sinobi Ransomware]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2025-sinobi</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2025-sinobi</guid>
    <pubDate>Sat, 25 Oct 2025 10:00:00 GMT</pubDate>
    <description><![CDATA[Sinobi has logged 277 leak-site postings since July 2025, with 80% of victims in the United States and manufacturing leading industry targets. After a March 2026 pause, six new victims appeared on May 5, 2026. DarkWebSonar telemetry tracks the Lynx-lineage RaaS operator through burst publication cycles and its current dormant status.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>ransomware</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: NOTCTBER404]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2025-notctber404</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2025-notctber404</guid>
    <pubDate>Mon, 13 Oct 2025 10:00:00 GMT</pubDate>
    <description><![CDATA[NOTCTBER404 surged onto the scene in late 2025, launching over 100 DDoS attacks primarily across Southeast Asia and forming an alliance with HEZI RASH. DarkWebSonar data reveals how fast this new hacktivist group is expanding.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>hacktivism</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: Akira]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2025-akira</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2025-akira</guid>
    <pubDate>Sun, 28 Sep 2025 10:00:00 GMT</pubDate>
    <description><![CDATA[Akira has surged to become one of the top ransomware groups of 2025, with over 570 incidents tracked by DarkWebSonar and a disproportionate focus on U.S. enterprises.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>ransomware</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: DarkStorm Team]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2025-darkstorm-team</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2025-darkstorm-team</guid>
    <pubDate>Mon, 15 Sep 2025 10:00:00 GMT</pubDate>
    <description><![CDATA[DarkStorm Team surged with over 800 tracked incidents in 2025, dominated by large-scale DDoS campaigns targeting Israel, the U.S., and NATO allies—making them one of the most disruptive hacktivist groups this year.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>hacktivism</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: Qilin]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2025-qilin</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2025-qilin</guid>
    <pubDate>Fri, 29 Aug 2025 10:00:00 GMT</pubDate>
    <description><![CDATA[Qilin has logged 1,666 victim postings across ~90 countries since October 2024, with 50% of targets in the United States and Manufacturing & Construction at 25%. DarkWebSonar telemetry shows October 2025 and April–June 2026 batch surges.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>ransomware</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Monitoring for MSPs: Build a Profitable Service]]></title>
    <link>https://darkwebsonar.io/blog/darkweb-monitoring-for-msps</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/darkweb-monitoring-for-msps</guid>
    <pubDate>Fri, 22 Aug 2025 17:23:00 GMT</pubDate>
    <description><![CDATA[Dark web monitoring for MSPs in 2026: how platforms work, what to look for in a provider, and how to turn early breach detection into recurring revenue without adding a SOC.]]></description>
    <author>Security Research Team</author>
    <category>msp</category>
    <category>threat-intelligence</category>
    <category>cybersecurity</category>
    <category>managed-services</category>
  </item>
  <item>
    <title><![CDATA[DarkWebSonar API Integration Best Practices]]></title>
    <link>https://darkwebsonar.io/blog/api-integration-best-practices</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/api-integration-best-practices</guid>
    <pubDate>Fri, 01 Aug 2025 09:15:00 GMT</pubDate>
    <description><![CDATA[Learn how to effectively integrate DarkWebSonar's API into your security operations workflow with practical examples and best practices.]]></description>
    <author>Engineering Team</author>
    <category>api</category>
    <category>integration</category>
    <category>tutorial</category>
  </item>
  <item>
    <title><![CDATA[What Is Dark Web Monitoring? Meet DarkWebSonar]]></title>
    <link>https://darkwebsonar.io/blog/introducing-darkwebsonar</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/introducing-darkwebsonar</guid>
    <pubDate>Thu, 29 May 2025 10:00:00 GMT</pubDate>
    <description><![CDATA[What is dark web monitoring and why does it matter? DarkWebSonar tracks ransomware groups, dark web forums, and data leaks in real time — so security teams can act fast.]]></description>
    <author>DarkWebSonar Team</author>
    <category>announcement</category>
    <category>threat-intelligence</category>
    <category>cybersecurity</category>
  </item>
  </channel>
</rss>
