Sources
Documents used in the initial library; each article cites relevant sources within its content.
TUNGTEK — Public Ticket #1355 record
Information published by the unit receiving the case; not independently verified.
03/10/2026 · Archived reference source; see its scope in the related articleCISA — #StopRansomware Guide
Guidance on prevention, response and recovery.
See the update date at the source · Archived reference source; see its scope in the related articleCISA and partners — AA24-109A: Akira Ransomware
Reference documentation on Akira, IOCs and TTPs. See the update date at the source.
Initially published 18/04/2024 · Archived reference source; see its scope in the related articleMicrosoft Threat Intelligence — CVE-2024-37085
Analysis of ESXi exploitation observed by Microsoft.
29/07/2024 · Archived reference source; see its scope in the related articleBroadcom — VMSA-2024-0013
Vendor advisory; check affected versions and mitigations.
2024 · Archived reference source; see its scope in the related articleCISA — Understanding Ransomware Threat Actors: LockBit
Observed activity and defensive recommendations.
14/06/2023 · Archived reference source; see its scope in the related articleMITRE ATT&CK — Qilin, S1242
Sourced behavioral profile. Does not attribute an individual case to Qilin.
See the update date at the source · Archived reference source; see its scope in the related articlePalo Alto Networks Unit 42 — Mallox Ransomware
Sample research and intrusion chain analysis by Unit 42.
2023 · Archived reference source; see its scope in the related articleVeeam — Protect: the 3-2-1-1-0 backup rule
The vendor's backup design guidance.
See the update date at the source · Archived reference source; see its scope in the related articleNIST SP 800-86 — Forensics in incident response
Foundational guidance on collecting, examining, analyzing and reporting digital evidence.
2006 · Archived reference source; see its scope in the related articleMITRE ATT&CK — Enterprise Tactics
A behavioral reference framework; attacks do not necessarily follow one sequence.
See the update date at the source · Archived reference source; see its scope in the related articleMITRE ATT&CK — T1486: Data Encrypted for Impact
Reference for encryption of data to cause disruption.
See the update date at the source · Archived reference source; see its scope in the related articleTUNGTEK / No.Ransomware.VN — .PIZ 2026 record
Publication by the case-receiving unit, preserved from No.Ransomware.VN source code. Eight tickets are internal observations, not independently verified.
26/09/2026 · Source reviewed: 10/09/2026CyRadar — MSSQL campaign, three backdoor layers and fileless malware
Reviewed primary source. It does not confirm the .PIZ, AnyDesk or Safe Mode chain attributed to it in the old No.Ransomware.VN article.
08/09/2026 · Source reviewed: 10/09/2026Cyble — The Ransomware Brief, Aug 2026
Statistics within Cyble's collection scope. Victim claims are not equivalent to incidents independently verified by Ransomware.VN.
August 2026 · Source reviewed: 10/09/2026Check Point Research — The State of Ransomware, Q2 2026
Source cited in the original article; read figures within the researcher's period and methodology.
Q2/2026 · Archived reference source; see its scope in the related articleSophos — State of Ransomware
Official report page; surveys and leak-site claims are different datasets.
See the update date at the source · Archived reference source; see its scope in the related articleNo.Ransomware.VN — Original Backup 3-2-1-1-0
The original date is retained in source code. The consolidated article preserves immutability, retention, administrator permissions and recovery tests.
12/09/2026 · Source reviewed: 10/09/2026No.Ransomware.VN — Awareness and response resources
Content from the source homepage and categories. Guidance passages have no separate publication dates; no invented historical dates are assigned.
See the update date at the source · Source reviewed: 10/09/2026VnExpress · Hanoi Police — Hanoi Police warn about RedHook and StormEncryptor
A reference link retained on No.Ransomware.VN. The date and title come from the source record; they were not independently reviewed during consolidation. Do not treat this as a verified incident report.
26/08/2026 · Archived reference source; see its scope in the related articleMinistry of Public Security — Launch of Vietnam Cybersecurity Day 2026
A reference link retained on No.Ransomware.VN. The date and title come from the source record; they were not independently reviewed during consolidation. Do not treat this as a verified incident report.
06/08/2026 · Archived reference source; see its scope in the related articleBáo Đầu tư — “Digital insiders” make ransomware pressure more dangerous
A reference link retained on No.Ransomware.VN. The date and title come from the source record; they were not independently reviewed during consolidation. Do not treat this as a verified incident report.
28/05/2026 · Archived reference source; see its scope in the related articleBleepingComputer · Zimperium — Mantax Otax encrypts files, steals data and harasses victims
A reference link retained on No.Ransomware.VN. The date and title come from the source record; they were not independently reviewed during consolidation. Do not treat this as a verified incident report.
10/09/2026 · Archived reference source; see its scope in the related articleBleepingComputer · CISA — WatchGuard Firebox exploited to deploy ransomware
A reference link retained on No.Ransomware.VN. The date and title come from the source record; they were not independently reviewed during consolidation. Do not treat this as a verified incident report.
10/09/2026 · Archived reference source; see its scope in the related articleBleepingComputer · SEC — Veradigm warns of data exposure following The Gentlemen's claim
A reference link retained on No.Ransomware.VN. The date and title come from the source record; they were not independently reviewed during consolidation. Do not treat this as a verified incident report.
09/09/2026 · Archived reference source; see its scope in the related articleTUNGTEK — Ransomware overload, reference case documentation
Archived documentation has its own canonical URL on t.tungtek.com; the reference link is retained without duplicating the full article into a competing version.
30/09/2026 · Archived reference source; see its scope in the related articleIDC Frontier — Thông báo số 2
The operator confirms ransomware as the cause and dates the disruption.
07/10/2026 · Source reviewed: 10/10/2026IDC Frontier — Thông báo số 3
Four affected zones and the operator's recovery assessment at publication.
08/10/2026 · Source reviewed: 10/10/2026IDC Frontier — Thông báo số 4
Response coordination update; it does not announce complete restoration.
09/10/2026 · Source reviewed: 10/10/2026Báo điện tử Chính phủ — Cảnh báo của Công an TP Hà Nội
Public warning mentions StormEncryptor and RMM abuse; no victim case is established here.
29/08/2026 · Source reviewed: 10/10/2026N-able — N-central 2026.3 Hotfix 2
Vendor notice on CVE-2026-18577 and the August HF2 release; not a claim that it is today's latest release.
06/08/2026 · Source reviewed: 10/10/2026Symantec & Carbon Black — Threat Hunter Team
Research-team observations and attribution; not confirmation of a new incident in Vietnam.
01/10/2026 · Source reviewed: 10/10/2026Citing a reference does not endorse every statement on the website. Read conclusions within the document's scope and timeframe.