REvil or Sodinokibi ransomware operation is apparently resumes again. Its operation was shutdown by law enforcement agencies in October 2021. Their TOR website is resumed and a new sample is captured in the wild.
Black Basta ransomware encrypts user data using a combination of AES + RSA algorithms and then demands its victims to contact them via their tor site for ransom negotiations.
Nokoyawa Ransomware is a new malware but has strong similarities with Hive Ransomware. There attack chain, tools to penetrate and deploy and the order in which they execute various infection steps are similar.
CaddyWiper is the forth wiper detected that is targeting Ukraine infrastructure. It erases user data and partition information from attached drives.
Pandora Ransomware hits automotive spare parts manufacturing giant DENSO. Pandora targets corporate networks steals data for double extortion attacks. It is new ransomware actor so its tactics are unknown at this time.