Nokoyawa Ransomware is a new malware but has strong similarities with Hive Ransomware. There attack chain, tools to penetrate and deploy and the order in which they execute various infection steps are similar.
B1txor20 is assembling its army of bot on Linux machines. It is exploiting the Log4j vulnerable systems to gain access and maintain foothold.
CaddyWiper is the forth wiper detected that is targeting Ukraine infrastructure. It erases user data and partition information from attached drives.
Pandora Ransomware hits automotive spare parts manufacturing giant DENSO. Pandora targets corporate networks steals data for double extortion attacks. It is new ransomware actor so its tactics are unknown at this time.
RURansom Wiper is targeting Russian assets, which appear to be a direct retaliation of Russian invasion on Ukraine. The malware is written in .net and is using AES-CBC with hard coded salt.