<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>DarkWebSonar Blog</title>
    <link>https://darkwebsonar.io/blog</link>
    <description>Dark web threat intelligence, ransomware tracking, and cybersecurity insights.</description>
    <language>en-us</language>
    <lastBuildDate>Sat, 29 Aug 2026 10:00:00 GMT</lastBuildDate>
    <atom:link href="https://darkwebsonar.io/rss.xml" rel="self" type="application/rss+xml"/>
  <item>
    <title><![CDATA[Dark Web Most Wanted: The Gentlemen Ransomware]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2026-the-gentlemen</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2026-the-gentlemen</guid>
    <pubDate>Sat, 29 Aug 2026 10:00:00 GMT</pubDate>
    <description><![CDATA[The Gentlemen ransomware has claimed 610 victims across 75 countries. Manufacturing leads at 28%, with August 2026 batch drops keeping it spiked.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>ransomware</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: Miyako]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2026-miyako</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2026-miyako</guid>
    <pubDate>Fri, 24 Jul 2026 10:00:00 GMT</pubDate>
    <description><![CDATA[Miyako is an Initial Access Broker with 221 listings since November 2024 - 95% initial access, 42% U.S. targeting, selling firewall root and RCE.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>initial-access</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: Nova]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2026-nova</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2026-nova</guid>
    <pubDate>Mon, 15 Jun 2026 10:00:00 GMT</pubDate>
    <description><![CDATA[Nova ransomware has logged 129 victims across 45 countries since April 2025. A RaaS operation rebranded from RALord, now surging.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>ransomware</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: DimasHxR]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2026-dimashxr</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2026-dimashxr</guid>
    <pubDate>Sat, 02 May 2026 10:00:00 GMT</pubDate>
    <description><![CDATA[DimasHxR ranks second across all DarkWebSonar-tracked actors with 508 incidents in 90 days - yet has zero open-source coverage.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>defacement</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: Keymous+]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2026-keymous-plus</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2026-keymous-plus</guid>
    <pubDate>Tue, 24 Feb 2026 10:00:00 GMT</pubDate>
    <description><![CDATA[Keymous+ is a DDoS-specialist hacktivist group with 1,400+ incidents - targeting Morocco, France, India, Egypt, and Israel.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>hacktivism</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: NoName057(16)]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2026-noname057</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2026-noname057</guid>
    <pubDate>Fri, 16 Jan 2026 10:00:00 GMT</pubDate>
    <description><![CDATA[NoName057(16) is the most active DarkWebSonar-tracked actor - 894 incidents in 90 days, 5,500+ total, heavily targeting Europe.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>hacktivism</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: MEDUSA]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2025-medusa</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2025-medusa</guid>
    <pubDate>Tue, 02 Dec 2025 10:00:00 GMT</pubDate>
    <description><![CDATA[MEDUSA ransomware posted 201 victims in 2025 - 61.7% in the United States, targeting construction, healthcare, and education.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>ransomware</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: CL0P]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2025-cl0p</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2025-cl0p</guid>
    <pubDate>Thu, 20 Nov 2025 10:00:00 GMT</pubDate>
    <description><![CDATA[CL0P has logged 635 victim postings since October 2024. 68.5% U.S. targets across manufacturing, technology, and retail sectors.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>ransomware</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: HEZI RASH]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2025-hezi-rash</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2025-hezi-rash</guid>
    <pubDate>Tue, 04 Nov 2025 10:00:00 GMT</pubDate>
    <description><![CDATA[HEZI RASH hit 856 incidents across 38 countries in three months - DDoS-focused, targeting government, media, and education sectors.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>hacktivism</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: Sinobi Ransomware]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2025-sinobi</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2025-sinobi</guid>
    <pubDate>Sat, 25 Oct 2025 10:00:00 GMT</pubDate>
    <description><![CDATA[Sinobi has logged 277 leak-site postings since July 2025 - 80% U.S. victims, manufacturing leading. Tracking the Lynx-lineage RaaS through burst cycles.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>ransomware</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: NOTCTBER404]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2025-notctber404</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2025-notctber404</guid>
    <pubDate>Mon, 13 Oct 2025 10:00:00 GMT</pubDate>
    <description><![CDATA[NOTCTBER404 launched 100+ DDoS attacks across Southeast Asia in late 2025, allied with HEZI RASH. A fast-expanding hacktivist group.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>hacktivism</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: Akira]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2025-akira</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2025-akira</guid>
    <pubDate>Sun, 28 Sep 2025 10:00:00 GMT</pubDate>
    <description><![CDATA[Akira ransomware surged in 2025 with 570+ DarkWebSonar-tracked incidents and heavy U.S. enterprise targeting.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>ransomware</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: DarkStorm Team]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2025-darkstorm-team</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2025-darkstorm-team</guid>
    <pubDate>Mon, 15 Sep 2025 10:00:00 GMT</pubDate>
    <description><![CDATA[DarkStorm Team surged past 800 incidents in 2025 - large-scale DDoS campaigns targeting Israel, the U.S., and NATO allies.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>hacktivism</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Most Wanted: Qilin]]></title>
    <link>https://darkwebsonar.io/blog/dark-web-most-wanted-2025-qilin</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/dark-web-most-wanted-2025-qilin</guid>
    <pubDate>Fri, 29 Aug 2025 10:00:00 GMT</pubDate>
    <description><![CDATA[Qilin has logged 1,666 victim postings across ~90 countries. Manufacturing leads at 25%, with October 2025 and mid-2026 batch surges.]]></description>
    <author>DarkWebSonar Research Team</author>
    <category>ransomware</category>
    <category>dark-web-most-wanted</category>
    <category>threat-actor</category>
  </item>
  <item>
    <title><![CDATA[Dark Web Monitoring for MSPs: Build a Profitable Service]]></title>
    <link>https://darkwebsonar.io/blog/darkweb-monitoring-for-msps</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/darkweb-monitoring-for-msps</guid>
    <pubDate>Fri, 22 Aug 2025 17:23:00 GMT</pubDate>
    <description><![CDATA[Dark web monitoring for MSPs: how platforms work, what to look for, and how to turn breach detection into recurring revenue.]]></description>
    <author>Security Research Team</author>
    <category>msp</category>
    <category>threat-intelligence</category>
    <category>cybersecurity</category>
    <category>managed-services</category>
  </item>
  <item>
    <title><![CDATA[DarkWebSonar API Integration Best Practices]]></title>
    <link>https://darkwebsonar.io/blog/api-integration-best-practices</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/api-integration-best-practices</guid>
    <pubDate>Fri, 01 Aug 2025 09:15:00 GMT</pubDate>
    <description><![CDATA[Learn how to effectively integrate DarkWebSonar's API into your security operations workflow with practical examples and best practices.]]></description>
    <author>Engineering Team</author>
    <category>api</category>
    <category>integration</category>
    <category>tutorial</category>
  </item>
  <item>
    <title><![CDATA[What Is Dark Web Monitoring? Meet DarkWebSonar]]></title>
    <link>https://darkwebsonar.io/blog/introducing-darkwebsonar</link>
    <guid isPermaLink="true">https://darkwebsonar.io/blog/introducing-darkwebsonar</guid>
    <pubDate>Thu, 29 May 2025 10:00:00 GMT</pubDate>
    <description><![CDATA[What is dark web monitoring and why does it matter? DarkWebSonar tracks ransomware, forums, and data leaks in real time.]]></description>
    <author>DarkWebSonar Team</author>
    <category>announcement</category>
    <category>threat-intelligence</category>
    <category>cybersecurity</category>
  </item>
  </channel>
</rss>
