> ransomware group tracker
Live profiles of active ransomware operations. Tracking TTPs, targets, victim counts, and law enforcement actions across the ransomware ecosystem.
Qilin Agenda
Dominant RaaS operation and the most active ransomware group of 2026 for most of the year, responsible for nearly 20% of global ransomware activity at its peak. NOTABLE (June-July 2026): The Gentlemen overtook Qilin as the single most active group by monthly victim count in June 2026 (94-117 victims vs. Qilin's ~78 that month per multiple trackers), ending Qilin's five-plus-month run atop the monthly leaderboard — Qilin remains the leader by lifetime cumulative victim count and stays firmly in the top two. Posted 338 victims in Q1 2026 — outpacing the bottom 50 ransomware groups combined — and continued at-pace into May 2026. Recent May 2026 victims include AppDirect (US, posted 2026-05-11), Keller Williams Real Estate – Exton (US), International Customer Care Services, Pangolin Editions, Lindabury (US legal services), The Gravity Group (2026-05-12), Sysco (US food distribution giant, 2026-05-05), Seagate Capital Construction (US, 2026-05-05), Ahorramas (Spanish consumer services, 2026-05-05), Standard-Examiner (US news, 2026-05-02), and LSM Lee (Singapore, 2026-05-02). Top targeted sectors year-to-date: Manufacturing (276), Business Services (219), Technology (166), Healthcare (158), Financial Services (115); United States is by far the most targeted country (~803 victims). Absorbed many former RansomHub affiliates after that group collapsed in April 2025. Deploys EDR-killing DLL (msimg32.dll) capable of disabling 300+ security drivers via BYOVD; technique now also seen in Warlock ransomware. KELA assessed Qilin as the single most active operation for January-May 2026, accounting for roughly 17% of all publicly claimed ransomware attacks worldwide; ransomware.live tracked 1,863 Qilin leak-site victims by May 26, 2026 (the group continued at-pace through the late-May window with new posts almost daily). A Qilin-attributed intrusion at Covenant Health was confirmed in May 2026 to have exposed personal data on nearly 480,000 individuals. Late-May 2026 victims include Semgrep (US, posted 2026-05-22), Ridge Law Firm (US, attack estimated 2026-05-12), and Gestordes (attack estimated 2026-05-03). Activity continued into early June 2026 (2026-06-02 leak-site victims include Clinica Maitenes and Nova Medical Products); ransomware.live/RansomLook tracking put Qilin at roughly 1,883 total leak-site victims by early June 2026, with cumulative sector impact led by Manufacturing (~291), Business Services (~245), and Healthcare (~168). In June 2026 a Qilin affiliate was tied to active exploitation of a critical Check Point VPN zero-day, CVE-2026-50751 (CVSS 9.3) — an IKEv1 authentication-bypass flaw in Remote Access/Mobile Access VPN that lets unauthenticated attackers establish a VPN session without a valid password; exploitation ran quietly from May 7, 2026 and accelerated in early June before CISA added the bug to its Known Exploited Vulnerabilities catalog on June 9, 2026 with a June 11 federal patch deadline. Check Point also disclosed a secondary flaw, CVE-2026-50752 (IKEv1 certificate-validation issue enabling MITM on site-to-site VPN), found during the same investigation. Qilin kept up a high leak-site tempo into mid-June 2026, claiming 15 victims across nine countries between June 2-5 (healthcare, hospitality, manufacturing, consumer services and critical infrastructure) — including Nova Medical Products (US), Clinica Maitenes (Chile), JNP ENG (South Korea), MarketJoy (US), Eat Salad (Brazil) and MEISA-Sines (Portugal, energy) — and posted roughly five more on June 9. Analysts expect Qilin to close Q2 2026 as the single most active ransomware collective globally, extending an unbroken run as the #1 threat actor since Q2 2025. In mid-June 2026 Qilin claimed Q Link Wireless (US major telecom provider, 2026-06-16) and BTX Global Logistics (US, 2026-06-17) as further victims, maintaining a near-daily leak-site tempo through the end of the quarter. Late-June 2026 leak-site claims include Lam Soon (Singapore food & beverage, 2026-06-29), Metal Sur Famin (Peru, manufacturing, 2026-06-29), Hemmersbach GmbH & Co. KG (Germany, IT services, 2026-06-30), and Chamco (Canada, manufacturing, 2026-06-30), with 18 victims claimed across manufacturing and energy in a single 24-hour period around 2026-06-11 — keeping Qilin on track to close Q2 2026 as the single most active ransomware operation globally for a twelfth consecutive month. Activity carried straight into July 2026: on 2026-07-06 Qilin posted a fresh batch of victims including Precision Steel Services (US manufacturing), Wood Ellis & Wood CPA (US accounting), Max Fordham (UK architecture/engineering/design firm), Keystone Homes, and Answer Precision Tool. ransomware.live tracking put Qilin's cumulative leak-site victim count at roughly 1,980 by 2026-07-06, keeping it the single most active ransomware operation globally into Q3 2026. Qilin continued its high-tempo leak-site posting through mid-July 2026, claiming Next Clinics (German healthcare provider, internal files exfiltrated, posted 2026-07-07) and Hilo (Canada-based technology firm, posted 2026-07-10) among its latest victims; Infosecurity Magazine separately reported Qilin had posted 500+ new victims across 2026 to date, reaffirming its position as the dominant ransomware operation of the year. Qilin affiliates were also confirmed exploiting a second VPN zero-day in July 2026: CVE-2026-0257, a PAN-OS/GlobalProtect authentication-bypass flaw (CVSS 7.8) patched by Palo Alto on May 13, 2026, used to gain unauthorized VPN access ahead of domain-wide encryption; the same actor was separately observed probing Fortinet and F5 VPNs in parallel. Qilin claimed further US victims PP+K (advertising firm) and Synergy Products (technology company) on 2026-07-19, keeping its near-daily leak-site tempo through mid-July. Qilin claimed EFU Life Assurance, a major Pakistani insurer, as a victim on 2026-07-22, threatening to leak corporate data absent negotiation. Qilin affiliates continued exploiting the Palo Alto PAN-OS/GlobalProtect auth-bypass flaw (CVE-2026-0257) for initial access, per renewed Arctic Wolf-sourced reporting around 2026-07-21. Black Kite/Help Net Security reporting published 2026-07-24 described Qilin locked in a month-long, back-and-forth rivalry with The Gentlemen for the #1 most-active-group spot through the second half of July 2026, with leadership swapping hands multiple times. Qilin continued high-tempo leak-site activity into early August 2026, claiming Infina Health (US healthcare, 2026-07-22), Stryker (US medical-device manufacturer, claimed 2026-07-24 — Stryker publicly disputed any ransomware/malware compromise, stating it found no indication of ransomware or malware and that a non-propagating malicious file was used), Savills France (real estate services, breach discovered 2026-07-27), Wilbert's (US retail, discovered 2026-07-27), and Freedom Claims Management (US insurance, 2026-08-03). MOXFIVE assessed Qilin's lifetime total at roughly 1,500+ victims (500+ in 2026 alone) as the year's most active operation overall, while quarterly snapshots show more volatility — ReliaQuest recorded Qilin still leading Q2 2026 with 289 victims (13% share) before slipping to third place in June 2026 (71 victims) as The Gentlemen and Akira gained ground; Black Kite separately measured a 443% YoY victim increase (250 to 1,358 victims) across an April 2025-March 2026 window. Qilin's leak-site tempo carried through early-to-mid August 2026, with new claims against Wire Products (US manufacturing, 2026-08-02), Service Electric (US telecommunications, 2026-08-03), Depona (posted ~2026-08-07), Université Libre de Bruxelles (Belgium, 2026-08-09), Naval Interior Team (Finland business services, 2026-08-09), the City of Winchester (US municipality, Kentucky, 2026-08-10), and HIGEN MOTOR (South Korea automotive manufacturer, 2026-08-10). ransomware.live tracked Qilin's cumulative leak-site total at roughly 2,133 victims as of 2026-08-10 (135 in the preceding 30 days) across 101 countries, with cumulative sector impact led by Manufacturing (21%), Professional Services (18%), and Technology (11%) — keeping Qilin the single most active ransomware operation of 2026 to date.
TTPs
Akira GOLD SAHARA
Prolific RaaS group with over 1,500 total victims since 2023 and $245M+ in collected ransoms. Q1 2026 victim count was 176, down 22% from 226 in Q4 2025, reflecting the declining yield of the late-2025 SonicWall SSL-VPN campaign as more organisations patched. Still drives an estimated 40% of cyber-insurance claims year-to-date and SonicWall devices remain present in ~86% of Akira-related incidents. Average ransom demand is now ~$1.2M. Can move from initial access to full network encryption in under four hours, with documented sub-hour smash-and-grab cases. A new SonicWall firewall-bypass vulnerability (CVE-2026-0204) continues to be weaponized in the same playbook. In April 2026 Qilin overtook Akira as the single most active group of the month; Akira held second place at roughly its March activity level. GreyNoise telemetry recorded a sharp SonicWall SonicOS API scanning surge between May 9-18, 2026, with a May 12 peak of ~597,000 sessions in 24 hours — roughly 46x the prior 30-day baseline — interpreted as Akira affiliates aggressively re-enumerating exposed appliances ahead of the next exploit wave. The campaign's original root cause remains SonicWall CVE-2024-40766 (improper access control in SonicOS), still being re-exploited on unpatched or credential-reused Gen5/6/7 appliances alongside the newer CVE-2026-0204 bypass. Akira kept posting through late May 2026 (US construction, legal, woodworking and marine SMBs on 2026-05-27 and 2026-05-29). Through mid-2026 Akira remained the second most active ransomware operation globally behind only Qilin. Leo International (US) was claimed as a victim on June 23, 2026, and a leak-site post on June 12, 2026 confirmed Akira's continued high operational tempo. Akira remained the second most active operation globally through end of June 2026, with a claim against Advanced Business Systems, Inc. (US office-solutions provider) posted 2026-06-30 threatening to leak roughly 31GB of data. On 2026-06-29 The DFIR Report published a detailed technical writeup of an Akira intrusion showing initial access via Bing malvertising impersonating the ManageEngine OpManager download page, delivering BumbleBee malware and an AdaptixC2 beacon, followed by creation of a fake local admin account, an Active Directory database dump, exfiltration of 75GB+ of data, and full-network encryption — illustrating the group's continued reliance on malvertising as an access vector alongside its SonicWall exploitation playbook. Akira claimed a further US victim, Ironmark (marketing/communications firm), on 2026-07-13, threatening to publish roughly 190GB of stolen data; cumulative lifetime victim count is now assessed above 1,400. Akira kept up its pace through mid-late July 2026, claiming Excalibur Rentals (2026-07-07, ~45GB threatened), Westcoast Communication Services (2026-07-17, ~20GB threatened), and L&A Transport, a US trucking company (2026-07-20). On 2026-07-14 SonicWall disclosed two additional undisclosed zero-days in its SMA 1000 series appliances — not yet formally attributed to Akira, but the same vendor/product family the group has repeatedly weaponized, and worth continued monitoring. Akira also continues expanding its Linux encryptor to target Nutanix AHV virtual-machine disks (first observed mid-2025), typically gained via the same SonicWall footholds or Veeam backup-server flaws (CVE-2023-27532, CVE-2024-40711). Akira claimed further US victims Kruse Construction (petroleum-sector mechanical contractor, 2026-07-22, ~10GB of data threatened) and Franz Krause artworksgroup (2026-07-28), keeping a steady leak-site cadence through late July 2026. Akira claimed two further US victims in early August 2026: Belasco Electric (Muskegon, MI electrical services, 2026-08-03, ~16GB of employee/financial/contract data threatened) and Albers Mechanical Contractors (HVAC/fabrication, 2026-08-03, ~30GB threatened). SonicWall confirmed it was investigating a fresh wave of ransomware activity against its firewall devices tied to Akira, with fewer than 40 confirmed cases as of early August 2026 — a smaller renewed wave following the earlier CVE-2024-40766/CVE-2026-0204 campaigns. Akira's SonicWall/VPN campaign continued through early-to-mid August 2026, with fresh leak-site claims against Basic Grain Products (US, 2026-08-06, ~104GB of employee/financial/client data threatened) and i4 Solutions (US web-development firm, 2026-08-10, ~170GB threatened). ransomware.live tracked Akira's cumulative leak-site total at roughly 1,564 victims as of 2026-08-10, with Manufacturing (430), Professional Services (368), and Technology (154) the top-hit sectors and the United States accounting for 857 of all victims.
TTPs
Law Enforcement Actions
- Latvian national Deniss Zolotarjovs — who operated across Conti, Karakurt, Royal, TommyLeaks/SchoolBoys and Akira ransomware brands — sentenced to 102 months (8.5 years) in US federal prison on 2026-07-14 for his role in a Conti-leadership-linked ransomware organization that hit 54+ companies, including at least 13 victims that together lost $56M+; among the extortions cited was a pediatric healthcare provider targeted using stolen children's health data
LockBit LockBit 3.0 / LockBit Green / LockBit 5.0
Taken down by Operation Cronos in February 2024 but launched LockBit 5.0 in September 2025 with more modular encryption and improved defense evasion. Has posted 200+ victims on its new leak site since December 2025, targeting Windows, Linux, and ESXi across the Americas, Europe, and Asia. Together with Qilin, Akira, and The Gentlemen claimed 41% of all Q1 2026 victims — posting 163 victims in Q1 2026, fourth place globally. In late 2025 LockBit formalized a cartel alliance with Qilin and DragonForce, pooling affiliate pipelines, attack infrastructure, and target intelligence, and inviting additional e-crime actors to join. LockBit 5.0's cumulative victim count reached roughly 311 by around 2026-06-20, an ~87% jump month-over-month, while its geographic mix shifted away from the US (down to ~21% of victims in Q1 2026, from ~23% previously) toward Italy (~8.6%), Brazil (~8.6%), and Turkey (~5.1%) — consistent with continued affiliate avoidance of US targets under sustained law-enforcement pressure. Activity continued into June 2026. Separately, on 2026-06-24 Europol and Microsoft's coordinated 'Operation Endgame' action dismantled 326 servers and seized 142 domains tied to the SocGholish, Amadey, and StealC infostealer/loader infrastructure that has historically fed initial access to LockBit and other ransomware operations — a disruption to the broader access-broker ecosystem LockBit affiliates draw on, not a LockBit-specific takedown. LockBit 5.0 continued at a steady pace into mid-July 2026, claiming Bancroft Engineering (US, automated welding equipment), RAVAGNAN GROUP (Italy, industrial), and Magna Dominicana (Dominican Republic, vehicles) in a single batch on 2026-07-10, followed by SIRSA S.p.A. (Italy, plastics processing) and Gies Dienstleistungen GmbH (Germany) on 2026-07-13, and Briggs of Burton PLC (UK engineering firm) on 2026-07-18. On 2026-07-14 the DOJ unsealed a 13-count indictment in the Northern District of Ohio against three Russian nationals (Alexander Alexandrovich Volosovik, Kirill Andreevich Zatolokin, Yulia Vladimirovna Pankova) and two companies, Media Land LLC and ML.Cloud LLC, for operating bulletproof hosting infrastructure that knowingly served LockBit, BlackSuit, and Play ransomware operations, contributing to $62M+ in US losses across 20+ states; a coordinated US/EU/UK sanctions package targeting the same hosting operators (among other cybercrime infrastructure) was announced 2026-07-13. LockBit 5.0 kept up a steady pace into early August 2026, claiming Setic Pourtier (French industrial machinery, 2026-08-02), Microphase Corporation (US electronics supplier, 2026-08-02), Grupo Rái (Brazilian communications company, 2026-08-02), Pioneer Coldstore & Cladding Pvt. Ltd. (Indian insulated-panel manufacturer, 2026-08-02), HGS WirtschaftsTreuhand GmbH, and VP Brands International.
TTPs
Law Enforcement Actions
- Operation Cronos takedown (Feb 2024)
- Multiple affiliate arrests (2024)
- Leader 'LockBitSupp' identified as Dmitry Khoroshev (May 2024)
- DOJ indictment of Media Land LLC / ML.Cloud LLC bulletproof-hosting operators (Volosovik, Zatolokin, Pankova) for knowingly hosting LockBit, BlackSuit, and Play infrastructure, tied to $62M+ in US losses (unsealed 2026-07-14); coordinated US/EU/UK sanctions package against the same hosting operation (2026-07-13)
Clop Cl0p / TA505
Specializes in mass exploitation of file-transfer software zero-days. Responsible for MOVEit (2023), GoAnywhere (2023), Cleo (2024), and the Oracle E-Business Suite campaign of late 2025/early 2026 (CVE-2025-61882). Has now publicly named 100+ alleged Oracle EBS victims on its leak site — including Harvard University, Wits University, Envoy Air, The Washington Post, Schneider Electric, Emerson, Logitech, Cox Enterprises, Pan American Silver, LKQ Corporation, Copeland, Humana, Bechtel Corporation, Fruit of the Loom, Abbott, University of Phoenix, and Entrust — with analyst estimates suggesting 100+ organisations were ultimately impacted. Approximately 40% of victims in technology and 30% in manufacturing; 80% of victims are US-based. Clop's leak site published a fresh wave of ~29 newly-named victims around 2026-06-26, including Michelin, Canon, Mazda, Estée Lauder, and Broadcom (Mazda has publicly disputed any data leakage or operational impact); 77 victim datasets were already posted via torrent/magnet links by that point, with roughly 18 of the 29 new names US-based. Separately, a new and distinct Oracle EBS flaw — CVE-2026-46817 (CVSS 9.8, unauthenticated RCE via the File Transmission component of the Oracle Payments module, patched in Oracle's May 2026 Critical Patch Update) — was confirmed under active exploitation as of 2026-06-30, with Shadowserver tracking 450+ exposed EBS instances online (nearly 200 in the US). Exploitation of CVE-2026-46817 has not yet been formally attributed to Clop or any named group, though the targeting pattern is consistent with Clop's historic Oracle EBS/PeopleSoft playbook and is being watched closely. In early-to-mid July 2026 Clop opened a new campaign targeting internet-exposed Gladinet CentreStack file-sharing servers (and sister product Triofox) for data theft and extortion, exploiting CVE-2025-11371, CVE-2025-30406, and CVE-2025-14611; over 200 exposed CentreStack instances were identified, with at least three customers confirmed targeted as of mid-July though no proof-of-compromise had yet been published. Clop also claimed roughly 43 additional victims across two recent weekly batches (21, then 22), including a major hotel chain, an IT services firm, a UK payment-processing company, a workforce-management firm, and a Canada-based mining company, without disclosing technical proof or ransom deadlines. In late July 2026 Clop's established file-transfer-software playbook was linked (though not yet via public leak-site victim claims as of 2026-07-22) to active exploitation of a new PTC Windchill/FlexPLM RCE flaw, CVE-2026-12569 (CVSS 9.8), targeting manufacturing, automotive, aerospace, and retail/apparel organizations running the PLM software. Ransom-ISAC confirmed the Windchill/FlexPLM extortion campaign became active around 2026-07-20, with victims receiving mass extortion emails (subject line referencing a 'Windchill PDMLink module serious data leak') sent from hundreds of compromised internal accounts per victim, following the chained pre-auth WSDL info-disclosure and login-servlet exploitation of CVE-2026-12569. As of 2026-07-27 Clop's public leak site showed no newly named victims in the prior 30 days (cumulative claimed total holding around 1,254), consistent with the group's established pattern of delaying leak-site postings for months during private negotiation windows after a mass zero-day campaign. GuidePoint Security analysis of Clop's serial zero-day campaigns (GoAnywhere MFT ~20% pay rate, MOVEit ~2.5%, Cleo MFT ~0%) suggests declining ROI from the mass-exploitation extortion model even as the Windchill campaign continues. Clop's cumulative leak-site total climbed from roughly 1,254 victims (2026-07-27) to roughly 1,297 by 2026-08-07 per ransomware.live tracking, consistent with the group's established pattern of periodic bulk leak-site postings following the Windchill/FlexPLM (CVE-2026-12569) extortion campaign; no additional named victims specific to that campaign had been independently confirmed as of this update.
TTPs
Law Enforcement Actions
- Multiple arrests in Ukraine (2021)
Play PlayCrypt
Closed ransomware group (not RaaS) targeting government agencies, police networks, and critical infrastructure primarily in Latin America and Europe. Uses custom encryption and double-extortion tactics. Posting cadence slowed notably in the second half of June 2026, with tracker snapshots showing no new confirmed leak-site victim between roughly 2026-06-17 and 2026-06-29 — a possible lull rather than a confirmed disruption. Activity resumed in late June/early July 2026 with a run of smaller victims: J&J Gaming (US gaming industry, posted 2026-06-27), Western Construction (posted 2026-06-30), Benchmark Inc. (breached 2026-06-29), Locati Architects and Silvestri & Associates Insurance (both posted 2026-07-04), and Preneed Funeral Programs and a further US victim (posted around 2026-07-07). Play claimed further victims Tax MT and Kreysler & Associates (US architecture firm) on 2026-07-21. On 2026-07-14 the DOJ unsealed an indictment against bulletproof-hosting operators Media Land LLC / ML.Cloud LLC that explicitly named Play (alongside LockBit and BlackSuit) as an operation the hosting service knowingly supported, tied to $62M+ in US losses — the first law-enforcement action to touch Play's infrastructure supply chain, though not the group's core operators directly. Play continued posting into late July 2026, claiming The DeBruler (Montana, US, 2026-07-23) and Record Go Alquiler (recordrentacar.com, Spain/Argentina car rental, 2026-07-23). Play resumed a more active posting cadence in early August 2026, claiming The Butcher Brothers (2026-08-01), Preferred Financial Group (US, 2026-08-04), Signature Services (US professional services, 2026-08-06), Platinum Group (Singapore, 2026-08-06), MIE Solutions (UK, 2026-08-09), and Rilpa Enterprises (Canada, 2026-08-09).
TTPs
Law Enforcement Actions
- Named (alongside LockBit and BlackSuit) in DOJ indictment of Media Land LLC / ML.Cloud LLC bulletproof-hosting operators, tied to $62M+ in US losses (unsealed 2026-07-14)
DragonForce
Operating as a ransomware cartel model, absorbing smaller groups like BlackLock/Mamona and spawning sub-brands like Devman. Offers white-label ransomware infrastructure to affiliates. Notably behind the Marks & Spencer attack (April 2025, ~£300M financial impact, online store offline for 46 days) deployed via Scattered Spider affiliates, along with Co-op and Harrods. Continues targeting retail, manufacturing, and pharma into May 2026, with the cartel now threatening 365+ companies on its leak site. May 2026 victims include Cult Wines (UK fine wine retailer, posted 2026-05-04). April 27, 2026 leak-site burst included MassDevelopment (US state agency), FAT Brands, IBS Website Solutions, and several mid-market US firms. May 25, 2026 saw another concentrated leak-site burst with Saver NV (Dutch waste-management operator), Veg-Fresh Farms (US agriculture), Alliance Adjustment Group (US public insurance adjusting, PA/NJ), and Xchange Technology Rentals (Germany, IT/AV equipment rental). On 2026-05-27 DragonForce ran one of its largest single-day bursts of the year — roughly 19 leak-site victims concentrated in US and Dutch real estate and healthcare — and continued into June 2026 (2026-06-01 victims include Taos Mountain Casino and Synex International), keeping it among the most active cartels globally. In June 2026 Symantec and Security Affairs reported DragonForce operators deploying Backdoor.Turn — a custom Go-based implant that routes C2 traffic through legitimate Microsoft Teams relay infrastructure by obtaining an anonymous Teams visitor token via Microsoft Skype-backed identity services and tunneling a QUIC session through a legitimate TURN relay, disguising attacker traffic as routine enterprise Teams communications. DragonForce has logged 579 confirmed victims since founding, up from 363 at the end of January 2026 — roughly 216 new victims added in under six months. In May 2026 DragonForce claimed over half of all Dutch ransomware victims that month, reflecting an active affiliate-recruitment push. Late-June 2026 claims include STNI Co., Ltd. (South Korea, virtual-technology company, attack estimated 2026-06-28, posted 2026-06-29) and Agroprime (Chile, agribusiness SaaS, posted 2026-06-29). Activity continued at pace into early July 2026 with additional claims against VIP Imaging (2026-06-30), Aptora (2026-06-29), and BITS Pilani (India, university, 2026-06-23), and on 2026-07-07 DragonForce publicly claimed HIVE360 (UK employment-administration/employee-benefits firm) as its latest victim. Activity continued at pace into mid-July 2026 with claims against STEP Oiltools (drilling waste-management services, posted 2026-07-12), Al-Saidi Factory (Saudi Arabia, breach discovered 2026-07-12), and Trans World Trading Company, Inc. (Philippines conglomerate, posted 2026-07-13); the cartel's leak/extortion infrastructure lists 363+ victim companies in total. DragonForce kept up its tempo through the second half of July 2026, claiming The Schuett Companies (US, posted 2026-07-10), Northeast Rescue Systems (US emergency-services/industrial-safety supplier, posted 2026-07-13), and Heritage Mechanical LLC (US, posted 2026-07-15). DragonForce claimed two further US victims in a single day on 2026-07-26: Syntron Bioresearch, Inc. (biotech) and Deluxe Medical Supply (healthcare distributor). DragonForce also claimed One Community FCU (US financial services/credit union, 2026-07-21, alleging exposure of client financial information and internal security assessments). Activity continued into early August 2026 with RUS Industrial (US heavy industrial construction, 2026-07-31), Baicizhan (Chinese language-learning platform, 2026-08-03), and TUI China (China unit of the travel company, 2026-08-03, reportedly exposing passport and financial documents). DragonForce claimed P. A. Inc. (Performance Alloys), a US distributor of high-nickel alloy and specialty stainless-steel piping products, as a victim around 2026-08-05. ransomware.live tracked DragonForce's cumulative leak-site total at roughly 631 victims as of 2026-08-03 (43 in the preceding 30 days), spanning Professional Services (23%), Manufacturing (22%), and Technology (12%) across 64 countries.
TTPs
Medusa MedusaLocker
Prolific RaaS operation linked to Storm-1175 and Lazarus Group deployments. Weaponizes zero-day and N-day vulnerabilities for high-velocity attacks, often moving from initial access to ransomware deployment within 24 hours. Has exploited 16+ vulnerabilities across major enterprise software, including (most recently) CVE-2026-1731 in BeyondTrust Remote Support / Privileged Remote Access, CVE-2026-23760 in SmarterMail (exploited a week before public disclosure), and CVE-2025-10035 in GoAnywhere MFT (also pre-disclosure). Heaviest impact in healthcare, education, professional services, and finance across Australia, the UK, and the US. The Medusa leak site recorded no new victims after February 14, 2026 — 100+ days without a public claim as of late June 2026, suggesting the group has suspended public operations or transitioned fully to private negotiations. Storm-1175 and Lazarus Group continue to deploy Medusa payloads in isolated incidents independently of the core group's leak-site activity. Security Affairs reported on 2026-08-04 that the Lazarus Group deployed Medusa ransomware against a Middle East target and separately attempted an unsuccessful Medusa attack on a US healthcare organization — a continuation of the state-actor-uses-criminal-payload pattern rather than a resumption of the core group's own leak-site operations, which remain dormant. NOTABLE (August 2026): Microsoft Threat Intelligence identified Storm-1175 — the same China-based, financially motivated actor previously linked to Medusa deployments — beginning on 2026-08-02 to deploy a new, distinct ransomware strain dubbed StormEncryptor (written in C++, appends the .encrypted extension, drops a !!!README_FIRST!!!.txt ransom note), likely via exploitation of an authentication-bypass flaw in the N-able N-central RMM tool (CVE-2026-18577, disclosed the same day). The shift to a new payload family suggests Storm-1175 may be moving away from Medusa itself even as it continues the same rapid initial-access-to-exfiltration playbook; the core Medusa leak-site operation itself remains dormant with no new public victim postings since February 2026.
TTPs
NightSpire
Originally a closed group handling all operations in-house, NightSpire announced a RaaS affiliate program in April 2026 and began publicly recruiting affiliates. Go-based ransomware payload uses hybrid encryption for speed. Primarily targets SMBs with less mature security across 30+ countries. Posted 74 victims on its data leak site in Q1 2026 and another 15 in April 2026, reaching 259+ claimed victims by May 1, 2026 across 28 industries. Continued at pace into June 2026, reaching 283 claimed victims by June 12, 2026. Top sectors: Manufacturing (35), Business Services (25), Healthcare (22), Technology (21), Consumer Services (13). Top countries: United States (71), France (11), Spain (10), India (10), Turkey (9). Ransom demands range from $150K to $2M. Late-June 2026 victims include Grupo Riquelme (Paraguayan conglomerate, posted 2026-06-25, attack estimated 2026-06-13, alleging theft of financial/banking data, customer databases, and HR/ERP data) and Artistic Smiles (US consumer-services business, posted 2026-06-19). Tracker sightings on 2026-07-08 and 2026-07-13 (attacks estimated around 2026-07-06) confirmed continued rapid scale-up, with the group's cumulative total now assessed above 250 victims since its March 2025 debut. Further named victims surfaced through mid-July 2026: PCCC Realty LLC (US, breach discovered 2026-07-08) and Webosphere (India, technology firm; SQL databases and source code exposed, claimed 2026-07-13). Cumulative tracker estimates for July 2026 range 283-299 claimed victims depending on methodology. NightSpire claimed a cyberattack on MKS Transformator, a Turkish transformer manufacturer, in late July 2026. NightSpire claimed The Mountain Company (UK retail, 2026-07-27, alleging HR/financial/customer data access) and Akribis Systems Pte Ltd (Singapore, claimed 2026-07-27, attack estimated 2026-07-22). NightSpire's leak-site tempo continued into early August 2026 with further named victims OPTIDEA GmbH (Switzerland, internal documents/financial/HR/design data), Country Club of Darien (US), Red-Line, and GoHighLevel (US SaaS/marketing platform); ransomware.live tracked NightSpire's cumulative leak-site total at roughly 314 victims as of 2026-08-10 (7 in the preceding 30 days), with Manufacturing, Technology, and Professional Services the top-hit sectors and the United States (83), India (13), and France (12) the top countries.
TTPs
Handala Handala Hack
Iranian-linked hacktivist group affiliated with MOIS. Primarily targets Israeli organizations but expanded targeting after Operation Epic Fury in February 2026. Claimed 23 victims in March 2026 alone. Operations focus on disruption and influence rather than financial gain. Around 2026-06-24/25 an IRGC-linked Telegram channel publicly confirmed, for the first time, that Yahya Hosseini Panjaki (aka Yahya Hamidi) — Iran's deputy intelligence minister for Israel affairs, killed in an Israeli strike on 2026-02-28 — had served as Handala's commander, formally confirming the group as a MOIS front rather than an independent hacktivist collective. Handala also made several disputed claims in June 2026, including breach of FBI drone footage tied to World Cup security (no verifiable evidence presented, per SITE Intelligence Group), a breach of California Water Service exposing billing PII (~2026-06-11; technical assessment found the compromised systems do not control water treatment/distribution, contrary to the group's framing), and responsibility for a Tel Aviv car bombing (~2026-06-04) claiming the victim was a senior Mossad official — a claim sourced only to Iranian state media and not corroborated by Israeli authorities. Handala claimed a 2026-07-26 attack on SupraNet Communications, a Madison, Wisconsin-based ISP, causing internet outages for businesses, government networks, and municipal centers across the region — consistent with the group's continued shift toward destructive/disruptive infrastructure attacks beyond its original Israel-focused hacktivist targeting.
TTPs
SafePay
Emerged in late 2024, scaling aggressively through 2025-2026 with former Black Basta members among its ranks. Operates classic double-extortion — stealing data, encrypting systems, and publishing victims on Tor-based leak sites. Surpassed 483 claimed victims by May 25, 2026 and remained one of the most active groups globally. May 2026 victims include Energy Action (Australian energy management firm), Boots Transport (Canada, 2026-05-04), Maiadouro.pt (Portugal), Hokuyo 2006 Co. (Japan), and Dahlgrens Cement AB (Sweden). Over 90% of victims are small or mid-sized businesses; top sectors are Business Services (62), Manufacturing (61), Technology (48), Consumer Services (39), and Education (38). United States accounts for 198 victims, Germany 94, United Kingdom 30, Canada 29, Australia 15. Uses modified LockBit source code and runs ~24-hour encryption timelines. Remained one of the most active groups into June 2026 (6 new leak-site victims on 2026-06-02 across transportation/logistics and professional services in Germany and Italy); an April 2026 listing of Malaysian crane maker Favelle Favco included a claimed 237GB / ~140,000-file dump exposing Australian employee IDs and internal records. By June 2, 2026 cumulative victim count reached roughly 490 organisations; a German victim (hellmold-plank.de) was posted around 2026-06-27, keeping SafePay among the most active operations through the end of June. On 2026-07-06 SafePay posted a concentrated batch of German construction/services-sector victims — RTN GmbH, shw-fr.de, bmiprojects.de, knobel-bau.de, and caritas-koblenz.de — continuing the group's heavy focus on German SMBs; ransomware.live tracked SafePay's cumulative victim count at roughly 516 as of 2026-07-06. The same batch also included St. Edward's Catholic First School (UK), broadening the day's targeting beyond Germany. SafePay kept its German-SMB focus through 2026-07-20 with a further cluster of five victims: Mende Grundbesitz GmbH (real estate), LBB Treuhand GmbH (tax consulting), WDK Deutsche Herstellerverband (manufacturers' association), Jaecklin Industrial GmbH, and TimeTEX GmbH. Cumulative claimed victim count reached roughly 517 as of 2026-07-20. That same day SafePay also claimed Stroebel Gruppe (German industrial firm) and Cenesco GmbH (German IT solutions provider); a further US victim, bnpdist.com, was discovered/claimed around 2026-07-27, pushing the cumulative claimed-victim count to roughly 518. SafePay continued at high tempo through early August 2026: further victims moebelmayer.de (Germany, discovered 2026-07-27), hanan-hov.co.il (Israel, discovered 2026-08-03), Multiaqua Inc. (US HVAC industry, claimed 2026-08-03), and CPU AG (German software development, claimed 2026-08-03) were added. By 2026-08-03 SafePay had publicly claimed roughly 537 victims across 45 countries, including 27 in the preceding 30 days, with top sectors Professional Services (18%), Manufacturing (17%), and Retail & E-Commerce (11%). SafePay added further named victims through early-to-mid August 2026, including Nask Door Inc. (US construction, West Chester, PA, discovered 2026-08-03) and parsa-beauty.de (Germany).
TTPs
Black Basta Vanilla Tempest
Formerly one of the top-tier RaaS operations until its collapse in early 2025. Members have migrated to successor groups including SafePay. The group's alleged leader Oleg Nefedov was placed on EUROPOL Most Wanted and INTERPOL Red Notice lists.
TTPs
Law Enforcement Actions
- LE raids on two suspects in Ukraine and Germany (Jan 2026)
- Leader Oleg Nefedov placed on EUROPOL Most Wanted and INTERPOL Red Notice (Jan 2026)
- Conti 'loader' developer Oleksii Oleksiyovych Lytvynenko (Ukrainian, extradited from Ireland) pleaded guilty 2026-06-10 to wire-fraud conspiracy tied to Conti operations that extorted $150M+ from 1,000+ victims; sentencing set for 2026-09-10 as part of DOJ's Operation Riptide (Black Basta is a Conti-lineage successor brand)
- Armenian national Karen Serobovich Vardanyan — extradited from Ukraine to Portland, Oregon — pleaded guilty 2026-07-08 to conspiracy/computer-fraud charges tied to 2019-2020 Ryuk ransomware attacks (Ryuk is the direct predecessor brand that rebranded into Conti, the lineage Black Basta descends from); faces up to 15 years, agreed to $1.1M+ restitution, sentencing set for September 2026
The Gentlemen
Fast-scaling RaaS that emerged mid-2025 and climbed to the #2 spot by victim count in early 2026. Founded by a threat actor known as Hastalamuerte — an experienced Qilin affiliate who left after a dispute over a ~$48K unpaid commission, which explains the group's rapid operational capability and sophistication. Public leak-site count exceeded 365 by late April 2026; ReliaQuest documented a jump from 35 victims in Q4 2025 to 182 in Q1 2026, and the group added another ~82 victims in April 2026 alone. Check Point Research mapped an underlying SystemBC C2 botnet of 1,570+ likely corporate victims — well beyond what the group publicly claims, with Bitdefender now assessing actual victim count likely exceeds 1,500. FBI issued an official warning on March 15, 2026. Top targeted sectors: Manufacturing, Technology, Healthcare, Financial Services, and Transportation/Logistics; top geographies: US, Thailand, France, Brazil, India. MAJOR EVENT (May 2026): The group's own backend infrastructure was compromised. On May 4, 2026, a Breached forum post titled 'The Gentlemen - hacked data for sale' offered the full dataset for $10K in BTC; by May 8 the seller posted a free MediaFire download link. The breach is linked to a compromise of hosting provider 4VPS, which operated parts of the gang's infrastructure. Leaked data included internal chats, affiliate operations, ransom-negotiation correspondence, attack methods, and organizational structure — revealing a small but professional syndicate of ~9 core operators. Leaked negotiations show the group threatening to release data tied to companies under NDAs with Sony and Barclays. The Gentlemen publicly claimed no critical data was exposed. A May 2026 KELA analysis of the leaked backend ranked The Gentlemen second only to Qilin for January-May 2026, with 332 publicly claimed victims (~10% of global ransomware claims for the year), and found the gang had studied the Black Basta chat leak as a playbook for phishing, credential reuse, and internal reconnaissance. KELA's May 13, 2026 cut put The Gentlemen second behind Qilin in the Jan 1-May 13 window during which all ransomware groups together posted 3,349 claimed victims globally (a ~14.5% rise vs the same period in 2025). Despite the backend leak the group stayed fully operational: on 2026-05-16 a newer BreachForums instance announced The Gentlemen as an official forum partner (granting advertising plus infrastructure and operational support), and the gang kept posting at a high tempo into June 2026 — 4 victims on 2026-05-29 and 14 on 2026-06-01, heavily weighted to healthcare and retail across North America and Asia. NOTABLE (June 2026): On June 18, 2026 ESET published detailed analysis of the group's mature, operator-maintained EDR-killer toolset — branded 'GentleKiller' — confirming The Gentlemen curates multiple EDR killers for adaptive defense evasion and has distinguished itself through this capability since early 2026. GentleKiller ships in 8+ distinct variants, each impersonating a different legitimate product (including spoofed Kaspersky, Valorant anti-cheat, Javelin, and WatchDog binaries) while abusing a different vulnerable/malicious kernel driver via BYOVD, together targeting 400+ processes across 48 security products from vendors including Microsoft Defender, CrowdStrike, SentinelOne, Sophos, and Bitdefender; the suite also incorporates third-party/leaked tools such as HexKiller, ThrottleBlood, and HavocKiller. A separate Expel investigation of an April 2026 incident found the group had used a genuine zero-day driver exploit not present on public vulnerable-driver blocklists. A Microsoft Security Blog report on May 28, 2026 dissected a self-propagating variant of the Go encryptor. On 2026-06-10 a Gentlemen-attributed attack on Mackay Sugar, Australia's second-largest raw sugar producer, forced a physical shutdown of its Farleigh and Racecourse mills during peak crushing season by crippling IT-side scheduling and historian databases without directly manipulating PLCs or variable-speed drives; the group formally claimed the attack on its leak site on 2026-06-15. By mid-June 2026 The Gentlemen's leak site listed 483 victims across 66 countries, ranking it the #2 most active ransomware operation globally by victim count. The group offers affiliates 90% revenue share — well above the 70–80% standard at competing RaaS operations — which has driven accelerated recruitment of experienced operators throughout 2026. NOTABLE (late June/July 2026): Kaspersky (GReAT) published a report on 2026-06-29 warning that The Gentlemen have further expanded their toolkit with a new custom backdoor for pre-ransomware reconnaissance and control, plus a new C-based, Windows-focused ransomware variant distinct from their existing Go cross-platform encryptor. On 2026-06-30 the group posted a claim against Indra Group, a Spanish defense/aerospace contractor with NATO ties, giving a 9-day extortion deadline (~2026-07-09); Indra activated its CSIRT and assessed the intrusion as localized with no spread across subsidiaries. By 2026-07-10 The Gentlemen's leak site listed 478-483 total victims; June 2026 was the group's highest-volume month yet with 94-117 victims claimed depending on tracker — briefly overtaking Qilin as the single most active group by monthly volume for the first time, a roughly 4x increase since January 2026, cementing its position as one of the two most active RaaS operations of 2026. In June 2026 Krebs on Security, drawing on the May 2026 backend infrastructure leak, publicly named the group's alleged lead operator/founder as Alexander Andreevich Yapaev (aliases hastalamuerte, LARVA-368), the first public attribution of a real identity behind the group; no arrest or indictment has followed as of this update. New victims claimed through mid-July 2026 include MakoLab (Polish IT firm) and EMAS Group (Czech Republic) on 2026-07-01, Triquesta Pte. Ltd. (Singapore fintech) on 2026-07-10, and BRAC (Bangladesh NGO), Terry P Moosmann CPA PC (US), and Gallant (Finnish advisory firm) on 2026-07-16. Black Kite/Help Net Security reporting published 2026-07-24 showed The Gentlemen briefly overtook Qilin as the single most active ransomware group multiple times during July 2026, cementing a month-long neck-and-neck rivalry between the two operations for the #1 spot by victim count. ReliaQuest and TheInsurer.com formally named The Gentlemen the single most active ransomware group of Q2 2026 overall, overtaking Qilin for the #1 named-victim spot that quarter. The group posted a large batch of new victims on 2026-07-30/31, including Promatrix Corp (NJ, US IT consulting), Clear Vision Signs (US architectural signage), Acosta Sons (NY, US appliance sales), Premier Fiduciary (Hong Kong, corporate/fiduciary services), Precision Concrete Pumping (US), Saturn Industries (Canadian trailer/lifting manufacturer), Hutch Paving (Michigan, US), Orsima (Algeria, IT services), World Wide Fittings Inc. (US, steel fittings), and Peachtree Group (US, discovered 2026-07-31). Salem Saleh Babgi (Saudi Arabian conglomerate) was claimed 2026-08-02. Cumulative claimed-victim tallies continued climbing through early August 2026, with some trackers citing roughly 580-655 total victims depending on methodology and cutoff date.
TTPs
Law Enforcement Actions
- FBI official warning issued (2026-03-15)
- Backend infrastructure breach via 4VPS hosting provider (2026-05-04); affiliate roster and negotiation logs leaked publicly on MediaFire (2026-05-08)
- Krebs on Security publicly identified alleged lead operator Alexander Andreevich Yapaev (aliases hastalamuerte, LARVA-368) using data from the May 2026 backend leak (June 2026); no arrest or indictment has followed as of this update
Sinobi
Financially motivated hybrid RaaS that emerged in late June 2025. Placed fourth globally with 56 claimed victims in January 2026 before cooling to 18 victims in February 2026, suggesting operational disruption or affiliate churn. Top activity sectors are Manufacturing, Healthcare, Construction, and Technology. Payload is concealed via legitimate driver abuse and defense-evasion tooling. Decline confirmed to have continued through Q2 2026: activity collapsed to just 7 victims in March 2026 with no new leak-site postings recorded in April 2026, and the group dropped out of Q1 2026 top-group rankings entirely, consistent with sustained law-enforcement or affiliate-attrition pressure. No new victims or law-enforcement action were identified through mid-July 2026.
TTPs
0APT 0APT Syndicate
Controversial RaaS that surfaced in late January 2026 and rapidly listed 253+ alleged victims by end of Q1 2026, but was widely assessed by GuidePoint and Halcyon as running a faux operation — leak samples were zero-byte files and the infrastructure was operated from an Android phone's SD card on AnLinux-Parrot. MAJOR EVENT (April–May 2026): in April 2026, 0APT breached rival group KryBit's RaaS panel and extracted staff names, credentials, cryptocurrency wallet addresses, location data, and ransom-negotiation correspondence, then attempted to extort KryBit for $2M with a threat to leak the affiliate list to the FBI. KryBit retaliated by breaching 0APT's own infrastructure, locking out its staff and dumping logs that publicly confirmed the operation was being run off a Droid phone with Parrot OS on an SD card. Leak-site download links were shown to be falsified — clicking an archive simply piped random data to a preset path. 0APT's site is now locked out and the group has gone silent; KryBit's reciprocal exposure has tarnished its own standing despite winning the feud.
TTPs
CoinbaseCartel Coinbase Cartel
Pure data-extortion crew (no encryptor) that emerged in September 2025 and has scaled aggressively through early 2026, claiming 118+ victims by April. Posted 22 victims in March 2026 alone and notably listed Cognizant and Aptim. Analyst assessments (Bitdefender, FortiGuard) suggest the group is composed of affiliates drawn from ShinyHunters, Scattered Spider, and Lapsus$. Operates a Tor leak site and uses staged disclosures — limited samples first, then full publication if the victim does not pay. Remained active into June 2026, with 2026-06-02 leak-site victims including Cambridge Mobile Telematics and Panasonic Avionics (Panasonic.aero). Added Axiom Global (US) as a new victim around 2026-07-14, keeping the group active into mid-July. Cumulative claimed-victim count has climbed to roughly 160-170 per recent analyst tracking (up from ~126), and the group added a 'partnerships' section to its leak site actively soliciting affiliate/partner collaboration. Claimed Caterpillar Inc. (US construction/mining-equipment manufacturer) as a victim on 2026-07-20. CoinbaseCartel claimed CEN and Cenelec (European standardization bodies, Belgium) and MIM Fertility (US) on 2026-08-01. Cumulative claimed-victim estimates vary widely by tracker (roughly 118-170+), with one analysis noting around 80% of claimed victims had prior infostealer-credential compromises.
TTPs
Everest
Russian-speaking financially motivated group active since December 2020. Originally a pure data-exfiltration crew, evolved to dual AES/DES encryption in 2021 and now also operates as an Initial Access Broker. Recruits corporate insiders for cash/profit-sharing. Approximately 360 total victims across at least 286 documented R&DE incidents; claimed at least 25 incidents YTD in 2026, ranking as the 10th most prominent extortion collective for the year. May 2026 saw high-profile financial-services victims, including Fiserv (US payment-processing giant, posted 2026-05-03) and TSYS (US payment solutions, 2026-05-02). Specifically targets medical-imaging providers with 24-hour deadlines, weaponising HIPAA pressure and patient-care urgency. In early May 2026 Everest began publishing what it claims is 108GB of Liberty Mutual data after an alleged failure to meet its demands; Liberty Mutual attributes the exposure to a third-party vendor incident. It sustained a healthcare- and utility-heavy tempo through late May 2026, ranking among the most active groups on 2026-05-28 with about 7 new victims (including Advanced Psychiatry Associates, Sidra Kuwait Hospital and Spedition Kern). Everest remained active through mid-2026: an AttackIQ technical analysis published 2026-07-02 dissected the group's ConfuserEx-protected .NET 4.0 encryptor, which falsely declares AES-256/RSA-4096 strength before silently downgrading to AES-128-CBC + RSA-1024 at runtime, and documented aggressive pre-encryption recovery sabotage (disabling Controlled Folder Access, re-enabling SMBv1, altering firewall rules) plus an unusual use of Wake-on-LAN broadcasts to force sleeping machines online for encryption. Everest claimed Rodschinson Investment (Belgium real-estate/M&A firm) on 2026-07-12, alleging roughly 1TB of stolen data. The group posted a burst of roughly 7 new victims within 24 hours around 2026-07-08, concentrated in healthcare, real estate, and technology, keeping it among the more active mid-tier operations through mid-July. Everest compromised Swiss train manufacturer Stadler Rail via a supplier breach and demanded CHF 10 million (~$12.3M) in ransom; Stadler publicly refused to pay, per reporting around 2026-07-23. Separately, a 2026-07-09 technical analysis found that an Everest claim of 1TB of stolen data was not supported by the deployed encryptor sample, which contained no exfiltration code — raising analyst doubts about the accuracy of some of the group's extortion claims. Everest posted a fresh batch of high-profile victims around 2026-08-05, including Al-Futtaim Group (UAE conglomerate), AKM Enterprises Inc. (US), Empresas Públicas de Medellín (Colombian public utility), Oasis Legal Group (US law firm), Allied Telesis (Japan-headquartered networking-solutions provider), and Keysight Technologies (US electronic test/measurement company) — sustaining the group's high-tempo targeting of large, brand-name organizations into Q3 2026.
TTPs
Lynx INC Ransom (predecessor)
RaaS operation widely assessed to be a rebrand of the INC ransomware group, active since July 2024. Highly organized with a structured affiliate program, exclusive affiliate panel, internal communications channels, and a polished technical arsenal. Has amassed 410+ confirmed victims by mid-May 2026, with the United States accounting for the largest share — a clear North American preference also extending to Canada, UK, Australia, and Germany. Top targeted sectors: Education and Technology, with significant activity also in Germany. In early 2026, Lynx executed high-volume burst campaigns including a January 5, 2026 wave that added 20 organisations to its leak site in a single day. Sustained that tempo into Q2 2026, becoming one of the two most active groups globally in the May 10 window (8 victims in 24 hours alongside Leak Bazaar). May 2026 victims include bayareaherbs.com, csb-battery.com, and funkychunky.com. Continues to be confused with INC Ransom on some leak-tracking platforms despite the operational separation. NOTABLE (June 2026): On June 24, 2026 researchers discovered exposed INC Ransom staging server directories on AEZA Group bulletproof hosting containing Windows and Linux encryptors cross-compiled for 14 CPU architectures — including PowerPC, SPARC64, IBM Z (s390x), and RISC-V — alongside GPO deployment scripts targeting a Japanese food and beverage company and 675 MB of operator tooling. The exposed tooling also showed SMB pass-the-hash lateral movement via hardcoded Administrator NTLM hashes against a Southeast Asian manufacturer spanning food production, biotechnology, and chemicals. The mainframe and POWER-series expansion represents a significant escalation — INC/Lynx is now actively pivoting toward IBM POWER, SPARC64, and z/Architecture mainframes that anchor global banking, telecom, and high-volume financial-transaction processing, extending the group's encryption capability to enterprise platforms historically outside ransomware's crosshairs; of the 14 Rust-compiled binaries recovered, only the x86-64 Linux/ESXi variants matched previously documented capability, meaning 10 of the 14 architecture targets were not previously linked to the group. NOTABLE (early July 2026): SOCRadar research published around 2026-07-01/02 (picked up by BleepingComputer, TheHackerNews, SecurityWeek and others) tied a large-scale FortiBleed credential-theft campaign against 430,000+ internet-facing FortiGate firewalls directly to Lynx and INC Ransom — an operator with access to the FortiBleed-harvested credentials was found logged into both groups' ransomware-negotiation panels. The campaign achieved admin-level access on 409 targeted devices and full compromise on 354, with at least 12 ransomware deployments and hundreds of endpoints encrypted traced to the harvested access; internal tracking documents recovered in the disclosure referenced 9,426 additional FortiGate devices (as of 2026-06-29), alongside a previously undisclosed Nextcloud zero-day and Citrix-related target lists (~29,000 IPs, 37 domains) used to extend access — concentrated on manufacturing, technology, and logistics targets in Latin America and Asia-Pacific. The sibling INC Ransom brand — operationally distinct from Lynx despite the shared lineage and frequent tracker confusion — surged independently through July-August 2026 on the back of new SonicWall SMA 1000 zero-days; see the separate 'inc-ransom' tracker entry for details.
TTPs
KryBit
RaaS operation that emerged in early 2026 with 25+ claimed victims across the United States, Germany, Austria, and Turkey by May 2026. Operates an 80% affiliate revenue-share model with encryptors compatible with ESXi, Linux, and Windows environments and advertised 24/7 technical support. MAJOR EVENT (April–May 2026): publicly engaged in a destructive doxing feud with rival group 0APT. After 0APT first breached KryBit's RaaS admin panel and exfiltrated staff names, credentials, wallet addresses, and ransom negotiation logs — then attempted to extort KryBit for $2M — KryBit retaliated by breaching 0APT's infrastructure and dumping evidence that 0APT was operating from a single Droid phone running Parrot OS off an SD card, confirming long-standing analyst assessments that 0APT was largely a fake operation. The retaliation locked out 0APT's staff but KryBit's exposed admin data (affiliate list, victim records, account credentials) materially increases its own risk of a law enforcement takedown and has damaged its standing with potential affiliates. Reflecting that fallout, KryBit dropped out of Bitdefender's Top 10 most active ransomware groups in the June 2026 Threat Debrief after being exposed. Despite that, KryBit continued posting through late June 2026: it claimed the Central Directorate of Tourism Police (POLITUR/CESTUR), a Dominican Republic law-enforcement agency, on 2026-06-25, and listed a Brazilian victim (mupras.com) on 2026-06-19. KryBit kept up a high tempo into early July 2026, claiming B'Laofood Joint Stock Company (Vietnam, food manufacturer), AeroVision Avionics Inc. (Taiwan), and DISS Corporation (US) on 2026-07-01; GitMea, GSP (IT consulting), and Hôpital Catholique/Moscati (Italy) on 2026-07-02; and SEPREC, Bolivia's Plurinational Commercial Registry Service (~5GB of data claimed stolen), on 2026-07-07. Despite the 0APT fallout, KryBit's pace accelerated sharply through mid-July 2026: Shanghai Xuerong Biotechnology (China, 2026-07-08), LAGUS s.r.o. (Czech manufacturer, 2026-07-17), PERKESO Rehabilitation Centre (Malaysia, government-linked, 2026-07-17), Euroins Insurance Company AD (Bulgaria, 2026-07-18), and Eurohold Bulgaria AD (Bulgaria, holding company, 2026-07-19) were all claimed as victims. Cumulative claimed-victim counts jumped to the high-70s by 2026-07-19 per multiple trackers (up sharply from the ~42 assessed in May), reflecting a substantial scale-up in operational tempo. KryBit sustained that pace through the end of July 2026, claiming Vibonum Technologies (India, 2026-07-22), CH. Karnchang Public Co. (Thailand construction firm, 2026-07-23), and LAXAI Life Sciences (India CRDMO, 2026-07-23). Delhi Heart and Lung Institute (India healthcare, ~22GB of patient/employee/medical records claimed) was detected 2026-07-22 and posted 2026-07-25. KryBit posted a large batch of new victims on 2026-08-02: ASHA Microfinance Bank Limited (Nigeria), ProHealth Medical Group Pte Ltd (Singapore healthcare), Country Motos S.A. de C.V. (Mexico motorcycle dealership), and DC Partner (Pty) Ltd (South Africa payment distribution agency), followed by Centro Universitário CESMAC (Brazil, university) around 2026-08-04. Cumulative claimed-victim counts vary widely across trackers (roughly 83-108 by early August 2026).
TTPs
ALPHV/BlackCat BlackCat / Noberus
Defunct Rust-based RaaS operation that exit-scammed affiliates in early 2024 following the Change Healthcare breach. Group infrastructure was seized by FBI/Europol in December 2023 and the operation collapsed shortly after. New May 2026 development: two US-based former cybersecurity professionals, Ryan Goldberg (former incident response manager) and Kevin Martin (former ransomware negotiator), each received four-year prison sentences after pleading guilty to conspiracy charges. They collaborated with Angelo Martino to purchase access to the ALPHV platform and extorted multiple US victims between April and October 2023. Martino — a ransomware negotiator for incident-response firm DigitalMint who abused that role by sharing confidential victim information with threat actors to increase ransom payments — was sentenced on 2026-07-09 to 70 months in federal prison; roughly $10M in his assets (cryptocurrency, vehicles, a food truck, and other luxury goods) were seized as part of the case.
TTPs
Law Enforcement Actions
- FBI/Europol infrastructure seizure (Dec 2023)
- Affiliate exit scam collapsed operation (Mar 2024)
- US former IR manager Ryan Goldberg sentenced to 4 years (May 2026)
- US former ransomware negotiator Kevin Martin sentenced to 4 years (May 2026)
- Angelo Martino (DigitalMint negotiator) sentenced to 70 months in federal prison (2026-07-09); ~$10M in assets (crypto, vehicles, food truck, luxury goods) seized
Leak Bazaar LeakBazaar / SnowTeam
Stolen-data marketplace and extortion operation launched by a Russian-speaking threat actor known as 'Snow' of the SnowTeam crew, advertised on the TierOne (T1) cybercrime forum on March 25, 2026. Rather than deploying an encryptor, Leak Bazaar operates as a post-exfiltration processing service: it ingests raw corporate data dumps and converts them into structured, sellable intelligence using ML-assisted text analysis, automated removal of system files, database reverse engineering, and ERP parsing before human analyst validation. It focuses on organisations with annual revenue above $10M and segments stolen content into high-value products such as quarterly financials, M&A data, R&D files, and personal-data records, while also running a Tor leak site and offering ransom-negotiation support to partner gangs. Although it is a marketplace rather than a traditional encryptor crew, ransomware-tracking platforms (ransomware.live, RansomLook) list it as a distinct group; in the May 10, 2026 reporting window it was the single most active group tracked, posting 9 victims in 24 hours.
TTPs
Vect VECT / Vect 2.0
RaaS operation that launched its affiliate program in late December 2025 and moved into active campaigns in early 2026, with first leak-site victim posted January 5, 2026 and 25 publicly named victims as of late May 2026 (Vect claims an additional ~300 unreleased victims). MAJOR EVENT (April 2026): Vect formalized an unprecedented alliance with the BreachForums cybercrime marketplace and the TeamPCP hacking crew, and on April 18, 2026 issued automatic Vect affiliate keys to every BreachForums member — roughly 300,000 registered users — in a single bulk onboarding. Analysts at Cynet, Dataminr, and Industrial Cyber describe this as an attempt to convert an entire mainstream cybercrime forum into a distribution network, contrasting with historical selective recruitment models such as Conti's affiliate program. Even partial activation of the BreachForums base would represent one of the largest coordinated ransomware affiliate mobilizations ever observed. Check Point Research and Cloud Security Alliance Labs subsequently shipped reports on a 'Vect 2.0' build that behaves as a wiper in many configurations — paying the ransom does not reliably recover enterprise data — raising the risk profile for victims of any affiliate using the toolkit. On 2026-07-02 the FBI's Internet Crime Complaint Center issued FLASH advisory FLASH-20260702-01 detailing how TeamPCP's supply-chain credential-harvesting campaign — which stole 500,000+ CI/CD credentials from projects including Trivy, Checkmarx KICS, LiteLLM, and the Telnyx SDK — feeds directly into Vect ransomware deployments, formally confirming the Vect/TeamPCP pipeline as a federal law-enforcement concern. Vect was also named alongside Anubis in a July 2026 trend roundup on ransomware groups pivoting toward Citrix Bleed 2 exploitation, BYOVD, and stolen supply-chain credentials as core initial-access methods. A Sophos Counter Threat Unit investigation reported in early July 2026 confirmed the Vect/TeamPCP partnership is now operational in the wild: Vect ransomware is being deployed against organisations compromised via the Trivy and LiteLLM supply-chain credential-harvesting campaigns, directly combining TeamPCP's stolen CI/CD credentials with Vect's encryption payload. A separate ExtraHop retrospective published in July 2026 noted no additional confirmed victim intrusions had been publicly reported since April 2026 — a contrast with the Sophos findings on active TeamPCP-fed deployments — underscoring how little independently verified visibility exists into the operation's true current tempo.
TTPs
Law Enforcement Actions
- FBI IC3 issued FLASH-20260702-01 advisory (2026-07-02) on the TeamPCP supply-chain credential-harvesting campaign feeding Vect ransomware operations
Nova RALord / RAlord / Nova RaaS
Ransomware-as-a-service operation that rebranded from RALord (active since April 2025) to Nova in mid-2025. Runs a structured affiliate program (marketed as 'APIPN') that recruits affiliates and buys network access, and uses double extortion — encrypting files and threatening to leak stolen data via a Tor site. Has claimed roughly 100+ victims across five continents, with the United States the top target, followed by France, Brazil, Spain and Singapore; heaviest sector impact in Manufacturing, Technology, Healthcare, Education and Business Services. SonicWall researchers note Nova has so far largely spared schools and nonprofits. Remained one of the most active groups in late May / early June 2026 (3 new victims on 2026-05-30 and continued posts into June). NOTABLE EVENT (late May-June 2026): a Nova affiliate broke the long-standing 'don't hit CIS targets' taboo by listing Eriell Group, a major Uzbekistan-headquartered oilfield-services firm with a Moscow office, in the group's 2026-05-26 batch. After backlash, Nova issued a public apology, banned the affiliate, claimed no files were encrypted, pledged not to leak the stolen data, and offered to help Eriell recover free of charge — a reminder that the rule barring attacks on Russia and CIS states still governs the Russian-speaking ransomware ecosystem in 2026. Bitdefender's June 2026 Threat Debrief listed Nova among the month's Top 10 most active ransomware groups. On 2026-06-24 Nova claimed responsibility for a breach of the NSW Rural Fire Service (Australia's largest volunteer firefighting agency), alleging theft of roughly 300GB of data including files on emergency-response projects and topographic maps; NSW RFS confirmed a security incident affecting IT systems but said emergency operations were unaffected, and has not confirmed Nova's specific claim — attribution is contested. By late June 2026 the group had logged roughly 157 documented victims across 42 countries. Tracker data showed continued activity into mid-July 2026, with the most recent discovered victim dated 2026-07-10 and a cumulative total of roughly 158 victims across 43 countries. Activity accelerated further through the rest of July: by 2026-07-22 ransomware.live-derived tracking put Nova's cumulative claimed-victim count at 174 across 43 countries, with the most recent post logged that same day. Top sectors shifted slightly to Technology (34), Manufacturing (24), and Healthcare (19); top countries US (24), Brazil (12), and France (11). AttackIQ and Security Boulevard published a detailed analysis on 2026-07-31 of Nova's Rust-based cross-platform encryptor (Windows/Linux/ESXi), documenting multi-layered Microsoft Defender tampering, security-process termination, Volume Shadow Copy deletion, anti-analysis techniques, and XChaCha20-Poly1305/RSA-2048 encryption; the affiliate revenue split was cited at roughly 85/15. New victims claimed in the window include VNSO (US, discovered 2026-07-22) and Digital Edge (digitaledgedc.com, Hong Kong managed-services provider, claimed 2026-07-24). Estimates of Nova's cumulative victim count as of late July 2026 range around 180 victims across 38 countries.
TTPs
World Leaks WorldLeaks / World_Leaks / Hunters International (predecessor)
Extortion-only operation that emerged in January 2025 as a rebrand of Hunters International (itself a 2023 rebrand of the Hive RaaS). Hunters International wound down its encryptor operation during 2025 — even releasing free decryptors — and migrated to a pure data-theft-and-extortion model under the World Leaks name, judging traditional ransomware too risky and less profitable amid law-enforcement pressure and falling payment rates. Runs an Extortion-as-a-Service (EaaS) model providing custom exfiltration tooling to affiliates, atop a four-platform infrastructure: a main Tor leak site, a victim negotiation portal with live chat, an affiliate management panel, and an Insider journalist portal that grants media outlets 24-hour advance access to stolen data before public release. Highly selective targeting of organisations with significant intellectual property and weak authentication (e.g. VPNs without MFA); single-victim leaks have exceeded 780GB. By June 2026 World Leaks had roughly 167 documented victims across 28 countries, with the United States hit hardest (~90 victims, over half of all attacks), followed by the UK (10) and Germany (8); top sectors are Healthcare (31), Manufacturing (24), Business Services (21), Technology (17) and Consumer Services (11). It ranked among the single most active groups by leak-site postings in mid-2026. Although it markets a no-encryption model, Darktrace documented an early-2026 incident in which World Leaks both exfiltrated and encrypted victim data, contradicting its stated data-only posture. The window's most significant World Leaks incident: around 2026-06-10/12 the group listed Tata Electronics — a major Apple and Tesla supplier — claiming theft of 204,341 files totaling 630.4GB, allegedly including iPhone 18 Pro technical specifications, Tesla-related manufacturing documents, employee passport scans, and internal operational records; Tata Electronics confirmed the incident (a rare victim confirmation for a World Leaks target) but said business operations were unaffected. Major press coverage of the leak publication continued through 2026-06-30. The group added further victims into early July 2026, including Treet Corp (Pakistani conglomerate, posted 2026-07-03); ransomware.live tracked World Leaks' cumulative victim count at roughly 173 across 29 countries as of 2026-07-02. World Leaks has also recently claimed Reliance Group and Hungarian media group Mediaworks, the latter involving an 8.5TB data leak — among the group's largest single disclosures to date. Further victims comhar.org and service.com.br were discovered on the leak site around 2026-07-02/03, keeping the cumulative count at roughly 173 through mid-July 2026. World Leaks' most significant incident of the window came around 2026-07-14/17, when the group claimed a breach of Reliance Infrastructure's third-party data-center provider (Yotta), exposing roughly 19,000 files (14.3GB) of Balance-of-Plant contractor data tied to India's Kudankulam Nuclear Power Plant (KKNPP) — including blueprints, supplier details, and inspection records; India's NPCIL stated core/safety systems were not compromised. Tracker snapshots showed no newly named World Leaks victims strictly dated between 2026-07-22 and 2026-08-05, a possible lull following the KKNPP-linked disclosure; cumulative claimed-victim estimates for the group range roughly 142-175 depending on source and cutoff date.
TTPs
PEAR Pear
Extortion operation first observed August 5, 2025 that scaled steadily through early 2026, claiming roughly 92 victims by June 10, 2026 and ranking among the most active groups by victim count in mid-2026 reporting windows. Overwhelmingly US-focused — more than 53 of its known victims are located in the United States — with heaviest impact in Business Services (32), Healthcare (18), Financial Services (7), Technology (6) and the Public Sector (6). Average dwell time between initial compromise and public leak-site disclosure is about 33 days. Recent victims include the San Diego Eye Bank, The Odom Firm (US law firm, 2026-02-26), CTI & Coordinators (freight transport, 2026-03-05), a New Jersey private university (posted 2026-03-03) and Family Psychological Associates (US mental-health provider, 2026-04-09), reflecting a pronounced focus on healthcare, legal and professional-services SMBs. Late-June 2026 victims posted 2026-06-30 include Spector and Lenz, PC (US legal/business services, attack estimated 2026-06-22), ORA Group (retail/POS sector, attack estimated 2026-06-23), and Sociedad Latina (US nonprofit/education, attack estimated 2026-06-25). A further victim, Tostrud & Temp, S.C. (US CPA firm, attack estimated 2026-06-23), surfaced on tracker listings in early July 2026, keeping PEAR's steady SMB-focused cadence going into Q3. PEAR maintained that cadence through mid-July 2026, posting AC Beverage, Inc. (US draft beer service, 2026-07-03), confirming the Tostrud & Temp, S.C. claim on 2026-07-08, and adding Faro Products Inc. (Canada, promotional products/souvenirs) on 2026-07-13. PEAR claimed Metropolitan Construction Systems (US NYC commercial roofing) as a victim on 2026-07-24, continuing its steady cadence of mid-market US targets. Sonitor Technologies was discovered as a victim around 2026-07-31. Media coverage of a PEAR breach of MCBS (Medical Computer Business Services) broke around 2026-07-28, exposing 1.26M patient records from an underlying compromise dated Sept-Oct 2025.
TTPs
Brain Cipher BrainCipher
Ransomware operation that surfaced in mid-2024 and gained immediate global notoriety with a June 2024 attack on Indonesia's National Data Center (PDN) that disrupted more than 160 government services, including national immigration systems. Widely assessed to be built on the leaked LockBit 3.0 builder, it runs a double-extortion model — encrypting systems and threatening to leak stolen data via a Tor site — and has expanded targeting across Southeast Asia, Europe and the Americas. Primary sectors include information technology, professional goods and services, government and civic bodies, manufacturing, healthcare, education and finance. The group sustained activity into mid-June 2026: on June 15, 2026 it claimed Anglomoil, Avantage Global and Avantage Mari, and separately compromised Japanese internet service provider Kisnet Co., Ltd. A further victim, PAI Pharma (Brazil, healthcare), was posted 2026-06-30; no ransom amount or data samples were published and impact remains unconfirmed. Brain Cipher claimed further victims into July 2026, including Golden State Orthopedic (US healthcare) and Digital Dynamics Inc. (US technology) on 2026-07-01, and IAC International (US industrial services) on 2026-07-09; cumulative victim-count estimates vary widely by tracker (roughly 31-75 depending on methodology), so the total should be treated as approximate.
TTPs
Scattered LAPSUS$ Hunters SLH / Scattered Lapsus$ Hunters / ShinyHunters / Scattered Spider (component) / LAPSUS$ (component)
Federated cybercriminal brand that coalesced in mid-2025 as an umbrella uniting members of Scattered Spider, ShinyHunters and LAPSUS$, letting affiliated operators present a unified front. Specialises in social-engineering-led data theft and extortion rather than encryption — most notably a sprawling Salesforce/SaaS data-theft campaign in which the actors claimed to have stolen over a billion Salesforce records and listed 39 high-profile victims including Google, Cisco, FedEx, Disney/Hulu, Toyota, Marriott and IKEA; confirmed leaks include Albertsons, Engie Resources, Fujifilm, Gap, Qantas and Vietnam Airlines (Qantas and Vietnam Airlines each exposing 5M+ customer records). In November 2025 the group announced a Ransomware-as-a-Service platform, ShinySp1d3r, to be led by ShinyHunters under the Scattered LAPSUS$ Hunters brand, signalling a move from pure extortion toward encryption-capable operations; as of mid-2026 ShinySp1d3r remains largely in development, with the group's actual 2026 revenue still driven by OAuth/SSO credential theft and SaaS data extortion rather than deployed ransomware. Its public leak site has intermittently gone dark, but the group has continued claiming victims into 2026 (60M+ breached records year-to-date) and explicitly signalled it would persist through the year. Between 2026-05-27 and 2026-06-09 ShinyHunters ran a widespread campaign against on-premises Oracle PeopleSoft servers, claiming compromise of 100+ organisations across 300+ instances via CVE-2026-35273 (critical PeopleSoft Environment Management RCE, CVSS 9.8); Google Threat Intelligence Group/Mandiant corroborated the campaign on 2026-06-11, finding 68% of notified victims in higher education, including the University of Nottingham's Campus Solutions student-records system. ShinyHunters also listed Eastman Kodak on its leak site around 2026-06-15/18, threatening to publish 2.2M+ customer PII records (Kodak confirmed unauthorized third-party access to a limited amount of data), and published stolen Salesforce data taken from Sysco Corporation on 2026-06-28 (originally claimed 2026-06-16) after Sysco reportedly declined to pay — roughly 2.7M unique email addresses from the dump were subsequently loaded into Have I Been Pwned. A further claim against Illinois Central College (~28GB, payroll and financial-aid data) was posted 2026-06-28. On 2026-07-01 the DOJ announced the extradition from Finland to Chicago of Peter Stokes (19, dual US/Estonian citizen, alias 'Bouquet'), arrested in April 2026 on an Interpol Red Notice and charged with conspiracy, computer intrusion, and fraud tied to at least four Scattered Spider intrusions since age 16, including a May 2025 breach of a luxury jewelry retailer via spoofed help-desk vishing calls and an attempted $8M crypto extortion. Separately, around 2026-07-01, the NAIC (National Association of Insurance Commissioners) stated that the ShinyHunters/Scattered LAPSUS$ Hunters PeopleSoft breach (via CVE-2026-35273) exposed only publicly available data, outdated logs, and configuration files rather than sensitive member records, pushing back on the severity of the group's earlier claims. In late June 2026 the group published roughly 45GB of data stolen from Madison Square Garden Sports after a missed ransom deadline, allegedly including 26M+ customer/corporate records and internal 'talent' files covering celebrity contact information, appearance fees, and risk ratings. Court filings around the Peter Stokes extradition detail an $8M cryptocurrency ransom demand made against a luxury jewelry retailer (unpaid) and attribute 100+ intrusions and $100M+ in ransom payments group-wide to the Scattered Spider component of the brand. ShinyHunters escalated a claimed breach of Ernst & Young (EY) in late July 2026, updating its leak-site notice on 2026-07-27 with a 'final warning' ultimatum — threatening to leak stolen client tax documents and internal files (allegedly obtained via Jira/GitHub/Azure access) unless EY responded by 2026-07-31; EY had not confirmed attribution as of this update. The 2026-07-31 deadline passed without ShinyHunters publishing a confirmed data leak or EY confirming the claim; as of this update no independent evidence (data samples, technical artifacts) has surfaced to substantiate the alleged EY breach beyond EY's earlier-confirmed, separate third-party support-ticket-system compromise (accessed 2026-03-28 to 2026-04-12, disclosed prior to the ShinyHunters claim).
TTPs
Law Enforcement Actions
- DOJ announced extradition of Scattered Spider suspect Peter Stokes ('Bouquet') from Finland to Chicago (2026-07-01)
Anubis Sphinx
RaaS operation that emerged in November 2024 under the original name Sphinx before rebranding to Anubis in early 2025. Distinguished by a built-in wiper mode (/WIPEMODE parameter) that permanently overwrites file contents during encryption, removing any recovery path even if a ransom is paid — a destructive capability that significantly elevates victim risk. Launched a formal affiliate program in February 2025 offering negotiable revenue splits and additional monetization paths including data extortion and access sales. Activity surged sharply in early 2026, with internal data-volume tracking metrics rising from 187 to over 2,600 points between late 2025 and March 2026, with peak tempo in February 2026 seeing victim claims every 48–72 hours. Disproportionately targets healthcare — 17 of 35 confirmed 2026 attacks targeted US healthcare entities, a risk-tolerance well above baseline for most top-20 ransomware operators. By mid-2026 the group had 68–80+ confirmed victims across the United States (43+), United Kingdom (6), Australia (6), Canada (5), Netherlands, France, Spain, Poland, and Peru. Notable 2026 incidents include Singing River Health System (Mississippi, 54,000+ patient records exposed), a confirmed attack on the Adriatic Port Authority (maritime critical infrastructure — cargo tracking, shipping schedules, and customs processing disrupted; ransom demand reported around $11M), and Quest Health Solutions (claimed 2026-06-24, alleging exfiltration of employee data and internal files, ~239GB with a 2-3 day publication deadline). Cross-platform payload supports Windows, Linux, and VMware ESXi environments. Also claimed FÉTIS Group & SECOM Engineering (French engineering firms, posted 2026-06-11), alleging exfiltrated financial records and project details. On 2026-06-25/26 Anubis claimed Nachlass Nord, a German inheritance-law/estate-management firm. Arctic Wolf Labs published a full investigation on 2026-07-01 documenting Anubis affiliates' heavy reliance on legitimate RMM/remote-access tools (ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, Total Software Deployment) and Cloudflared tunneling for persistence across healthcare, financial-services, manufacturing, and technology victims; coverage the same week also documented Anubis affiliates exploiting Citrix Bleed 2 (CVE-2025-5777), a pre-auth NetScaler memory-disclosure flaw, to steal session tokens and bypass MFA without a password. By 2026-07-04 Anubis's leak site listed 91 total victims, with 11 added in June 2026 alone. A coordinated law-enforcement operation on 2026-06-10 — Georgian authorities working with the DOJ, US Secret Service, and Europol — dismantled the 'AudiA6' crypto-mixing service and the linked 'Dark2Web' cybercrime forum, seizing/freezing over €778,000 in cryptocurrency and taking down 30+ servers and 25 domains tied to Anubis's money-laundering infrastructure; two administrators were arrested in Batumi, Georgia. Anubis claimed three further victims on 2026-07-12 alone: Surtifamiliar (Colombia retail chain), Community Advocates (US law firm), and Casper Orthopedics (US medical clinic). MAJOR INCIDENT (July 2026): on 2026-07-20 Anubis listed Coca-Cola and its Fairlife dairy subsidiary on its leak site, claiming compromise via the Citrix Bleed 2 flaw (CVE-2025-5777), encryption of Fairlife servers, and theft of roughly 1TB of data, with a ransom deadline of 2026-07-27. Coca-Cola refused to pay and Anubis published the full dataset after the deadline lapsed; Fairlife's US production was briefly halted while Canadian operations continued. Anubis claimed further US victims Winn-Dixie (retail/grocery) and Blackburn's Physicians Pharmacy, Inc. (western PA/NY healthcare/pharmacy supplier) on 2026-08-03. Arctic Wolf's July 2026 investigation put Anubis's confirmed cumulative victim count at 91, with 11 added in June 2026 alone and over half of victims US-based. Anubis added Cameron Regional as a further claimed victim (discovered 2026-08-04), continuing its high-tempo targeting into the second week of August 2026.
TTPs
Law Enforcement Actions
- AudiA6 crypto-mixer / Dark2Web forum takedown disrupted Anubis money-laundering infrastructure — 2 arrests in Batumi, Georgia; €778,000+ seized/frozen; 30+ servers and 25 domains taken down (2026-06-10, joint DOJ/US Secret Service/Europol operation)
- US Treasury/OFAC sanctioned FirstVPN, its Ukrainian administrator, and a Belarusian malware-obfuscation seller (2026-07-13) as part of 'Operation Saffron' (a May 2026 multinational takedown by French/Dutch authorities with Europol/Eurojust/FBI support that seized 33 servers across 27 countries); blockchain tracing cited in the action showed Anubis sent payments (~$715) to FirstVPN in December 2025 and March 2026
Warlock GOLD SALEM / Storm-2603
Emerged publicly in June 2025 on the Russian-language RAMP forum and scaled rapidly by exploiting unpatched Microsoft SharePoint servers (the 'ToolShell' exploit chain) for initial access, later expanding to unpatched SmarterMail servers (breaching SmarterTools itself, reported February 2026) and continued SharePoint exploitation into 2026 — one Trend Micro-tracked intrusion in January 2026 saw attackers dwell 15 days before deploying the encryptor. Also tracked by Microsoft as Storm-2603 and assessed by some researchers (Computer Weekly, SecureWorks) as potentially linked to a Chinese state-nexus actor (GOLD SALEM per Sophos), a notable divergence from the mostly Russian/Eastern-European ransomware ecosystem. Reached roughly 78 recorded victims on ransomware.live by March 2026, up from 19 in July 2025 and 60 in September 2025. Deploys multiple EDR killers per intrusion — sometimes dozens in a single operation — abusing at least nine distinct vulnerable/malicious kernel drivers via BYOVD (including a legitimate-but-vulnerable NSec driver, 'NSecKrnl.sys', replacing the earlier 'googleApiUtil64.sys'), effectively brute-forcing its way to a working defense-evasion chain rather than relying on one exploit; one deployed tool contained AI-generated boilerplate code (a printed list of 'possible fixes'), suggesting AI-assisted malware development. Also uses TightVNC for persistent remote control. Claimed attacks on European telecom operators Colt and Orange. NOTABLE (July 2026): CISA added CVE-2026-45659 — a Microsoft SharePoint Server deserialization RCE (CVSS 8.8) — to its Known Exploited Vulnerabilities catalog on 2026-07-01, with federal agencies given until 2026-07-04 to patch; Microsoft's Incident Response team confirmed Storm-2603/Warlock is behind the active exploitation, following the same ToolShell-style playbook (exploit SharePoint flaw for initial access, create new local/domain admin accounts, use BYOVD to tamper with EDR, then deploy the Warlock encryptor). Investigators also found a second, unrelated threat actor operating simultaneously inside at least one victim network via DLL side-loading and custom backdoors, complicating incident response. ReliaQuest reported in early August 2026 that Storm-2603 was observed exploiting a critical SmarterMail authentication-bypass vulnerability, CVE-2026-23760, to gain unauthenticated access to internet-facing SmarterMail servers and stage Warlock ransomware, matching confirmed Warlock TTPs including MSI-installer delivery and Velociraptor used as a C2 tool; Warlock has been tied to at least 11 confirmed incidents since mid-2025, with roughly 19+ confirmed attacks tracked as of late-summer 2026.
TTPs
Icarus
Data-extortion-only group (no encryptor observed) that launched in April 2026 with just two initial victims before gaining major attention via a June 2026 SaaS supply-chain breach. Klue, a market-intelligence/competitive-battlecard platform, identified unauthorized activity in its Salesforce integration infrastructure on 2026-06-12, traced to a compromised legacy OAuth credential; on 2026-06-19 Icarus claimed to have exfiltrated Salesforce-integration data (business names, product-usage and subscription details, business contacts, and sales/marketing communications) from Klue's customer base, naming a downstream victim list heavily weighted toward cybersecurity vendors — including Huntress, Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity. Extortion contact was conducted via the Session messaging app. A second, separate extortion actor reportedly also began demanding payment over the same stolen Klue data after Icarus claimed to have deleted its copy — that second group remains unnamed in public reporting. The downstream victim list grew through the 2026-06-23/24 window as LastPass, BeyondTrust, and HackerOne separately confirmed their own Salesforce customer-support-case data was exposed via the same Klue OAuth breach, joining the previously confirmed Huntress and Recorded Future/Tanium disclosures, with HDS Corp (US) also confirmed as an affected downstream party. The Klue-driven campaign continued to expand into July 2026, with Icarus listing several additional organizations on its leak site; a separate, unrelated extortion crew also began independently pressuring some of the same Klue-breach victims for payment, complicating attribution of individual demands. Icarus separately claimed Cazh.id (Indonesia) as a victim outside the Klue campaign.
TTPs
Prinz Eugen GERMANIA (operator's predecessor persona)
Newly identified closed-group/solo ransomware operation, not a RaaS and not currently recruiting affiliates. Earliest indicator traced to 2026-04-16 (a leak portal targeting Standard Bank Group, South Africa); formally identified and named by Malwarebytes/ThreatDown researchers on 2026-05-11 after investigating an infected customer, with broader security-media coverage following through June 2026. The operator, using the handle ROOTBOY (active on the Exploit and DarkForums cybercrime forums), previously ran a data-selling persona called GERMANIA (linked via a shared TOX ID; also used the alias 'avtokz' on the XSS forum) before pivoting to the Prinz Eugen ransomware brand. Uses a freshly-built, custom Go-based encryptor (payload observed as 'servertool.exe') deployed via legitimate RMM software (specifically RemotePC) and PowerShell stagers, likely following stolen RDP credential access. Distinctively prioritizes recently-modified files for encryption first (ties broken alphabetically by filename) and deliberately skips dropping a ransom note or changing the desktop wallpaper — an anti-forensic, direct-contact extortion model rather than the standard leak-site playbook. At least 5 victims identified as of the most recent reporting, including Standard Bank Group (South Africa), which refused a 1 BTC ransom demand.
TTPs
CMDOrganization CMD Organization
Extortion operation that surfaced around May 2026 and markets itself publicly as a legitimate 'IT security firm' while running ransomware and auction-style data-extortion campaigns — rather than a flat ransom demand, it lists stolen victim data for auction on its leak site. Victim counts vary widely by tracker (Ransomwhere.org cites 3, SOCRadar 64, ransomware.live statistics roughly 25 as of May 2026), reflecting inconsistent leak-site indexing. Remained active through the June-July 2026 window, claiming Coldstat Refrigeration (Paramus, NJ) on 2026-06-23, alongside Wall Independent School District (TX, threatening to leak student data), Advanced Software Products Group, and Zampell. Continued claiming victims into mid-July 2026, including Finance Yorkshire (UK SME funding organization, posted 2026-07-09) and Els for Autism (US non-profit, posted 2026-07-12). Additional victims claimed through mid-July 2026 include Cytek Biosciences, Golden Star Resources, Lake Washington School District, and Port Angeles Composite; cumulative claimed-victim count reached roughly 31 as of 2026-07-16 (sector breakdown: Healthcare 9, Business Services 5, Education 4), up from the ~25 baseline. Not previously tracked; added given its sustained victim count and multi-tracker coverage. CMDOrganization claimed further victims into early August 2026: Rondout Electric (US electrical contracting) and Contact Group (contactgroup.com.au, Tasmanian building/multi-technology services), both on 2026-07-30, plus Goodstone Group shortly after — pushing the cumulative claimed-victim count to roughly 32-35.
TTPs
Phobos Phobos ransomware / 8base (major affiliate brand)
Long-running RaaS family, commercialized and sold to affiliates by Russian national Evgenii Ptitsyn, who administered the group's operations and dark-web leak site. Phobos affiliates are estimated to have victimized 1,000+ organisations worldwide and extorted more than $39M in ransom payments, with the 8Base brand among its most prolific affiliate operations. MAJOR EVENT: Ptitsyn pleaded guilty in US federal court on 2026-03-04 to charges tied to developing and administering Phobos, after extradition from South Korea; agreed to forfeit $1.77M in assets and owes $39.3M+ in restitution. His sentencing hearing was held 2026-07-15, where he faced up to 20 years in prison — the final sentence had not been publicly reported as of this update. Added to the tracker given the scale of confirmed victims and the significance of the July 2026 sentencing.
TTPs
Law Enforcement Actions
- Administrator Evgenii Ptitsyn pleaded guilty to wire-fraud conspiracy (2026-03-04) in the District of Maryland after extradition from South Korea; agreed to forfeit $1.77M in assets and owes $39.3M+ in restitution; sentencing hearing held 2026-07-15 (faces up to 20 years) — final sentence not yet publicly confirmed as of this update
Pink Helix / Redact / O-UNC-066 (Unit 42 tracking) / CL-CRI-1147 (Unit 42 tracking)
Newly identified 'Com'-affiliated cyber-extortion crew specializing in identity-focused, encryption-free data theft against Microsoft 365/SharePoint environments. Vishing activity traces back to April 2026; a dedicated Tor data-leak site went live 2026-05-31, and the operation drew a major wave of security-vendor and press coverage between 2026-07-06 and 2026-07-13 after Microsoft warned of an associated fake-Entra-passkey-enrollment campaign. Operators cold-call enterprise employees while spoofing caller ID to impersonate corporate IT support (or even the victim's own manager), then walk the target through a fraudulent Microsoft Entra ID 'passkey enrollment' or device-code phishing flow that silently registers an attacker-controlled credential/authenticator — bypassing MFA without ever needing a password. Once inside, automated tooling built on Microsoft's own APIs sweeps OneDrive/SharePoint document libraries for bulk exfiltration, and the group extorts victims via their own hijacked email/Teams accounts with roughly 72-hour deadlines, negotiating over a qTox ID. Researchers (ReliaQuest, Unit 42, Check Point) assess Pink, Helix, and Redact as fragments or sequential rebrands of the same underlying threat cluster that emerged after the BlackFile/UNC6671 data-extortion brand shut down in April 2026 — sharing registrar infrastructure (NICENIC) and adjacent hosting. Targeting infrastructure analysis identified 69 malicious subdomains, roughly 92% aimed at US organisations, spanning food & beverage, technology, healthcare, automotive, construction, aviation, and financial-services victims; precise cumulative victim count has not been publicly disclosed by any tracker as of this writing, but the campaign is described as widespread and ongoing across all three sibling brand names. Added given the volume of dedicated vendor and press coverage in July 2026, even though a firm victim count is not yet published.
TTPs
"2019" 2019 (forum handle)
Threat actor operating under the forum handle '2019', first tracked publishing stolen datasets in February 2026 with 23 tracked forum publications through 2026-06-01. Check Point's June 2026 monthly ransomware report identified '2019' as the single actor claiming the most victims that month (12), ranking ahead of established RaaS brands, though researchers note its behavior — posting and selling stolen datasets on a cybercrime forum rather than running a dedicated Tor leak site with ransom negotiation — resembles a data-broker/leak-forum operator more than a classic ransomware gang, and this classification uncertainty should be treated as an open question. Heavily but not exclusively targets Australian organisations: claimed victims include the Melbourne International Film Festival (initially claimed 340,000 records; MIFF disputed the scale, confirming roughly 26,782 affected records tied to third-party ticketing vendor Ferve), the Australian Centre for the Moving Image, Ochre Medical Centre Tuggeranong (~25,000 patients' Medicare/DVA data), and Kalkine Media. Added given it crossed 20+ tracked victim publications and was named the most active claimed-victim actor of June 2026 by Check Point Research. Continued publishing through mid-July 2026: claimed Hot Toner Australia (printer-consumables supplier, ~10,000+ record sets, ~2026-07-11) and Lifeline Australia (suicide-prevention charity, staff names/emails/DOBs/client IDs/phone numbers, shared for free; ~2026-07-12, breach confirmed by Lifeline). Other recent claims include a Canberra medical clinic and Hampr (360,000+ records claimed).
TTPs
JadePuffer
First documented case of a fully autonomous, LLM-agent-run ransomware attack, reported by Sysdig and widely covered in early-to-mid July 2026 (Sysdig research published, picked up by TechCrunch, DarkReading, and BleepingComputer around 2026-07-06 to 2026-07-10). Unlike conventional ransomware operations, JadePuffer was executed end-to-end by an autonomous AI/LLM agent rather than a human operator directing tooling: the agent gained initial access via an internet-facing Langflow instance vulnerable to CVE-2025-3248, autonomously pivoted to a production MySQL/Alibaba Nacos server, encrypted and deleted 1,342 Nacos configuration records, authored its own ransom note, and left a Bitcoin payment address — adapting to failed steps in real time (one failed login attempt was corrected within 31 seconds) without human intervention at the technical-execution stage. There is no known overlap with existing ransomware brands or nation-state activity; TechCrunch's coverage noted a human operator was still involved in initial setup, pushing back somewhat on a 'fully autonomous' framing. UPDATE (2026-07-22): Sysdig disclosed a second JadePuffer incident in which the same AI agent re-entered the identical Langflow instance from its first intrusion, this time exploiting an exposed Docker socket to create a privileged escape container, then deployed a new payload dubbed ENCFORGE — a UPX-packed Go ransomware binary purpose-built to target AI/ML assets (roughly 180 file extensions across the machine-learning stack), a notable shift from the first attack's database-configuration focus. Included in the tracker despite the small known victim count because of the significant, sustained security-media coverage and its status as a notable first for agentic-AI-driven cybercrime — the identity, nationality, and motive of the human operator(s) behind the agent remain undisclosed.
TTPs
Deadlock
RaaS operation whose malware family has circulated since July 2025 but which re-emerged as a significant public threat when its Tor data-leak site relaunched in June 2026, rapidly listing 80+ victims (ZeroFox flash report, 2026-06-16) and sustaining high-volume coverage through July 2026 (CYFIRMA weekly intelligence report, 2026-07-17; DarkWebInformer noted 11 new victims posted within a single 24-hour period around 2026-07-11). Roughly 57% of claimed victims are concentrated in Europe and Russia, an unusual geographic skew for a RaaS operation given the traditional 'no CIS targets' norm among Russian-speaking crews. Distinguished by two notable technical traits: command-and-control resilience via Polygon blockchain smart contracts (making C2 infrastructure difficult to seize or take down through conventional means), and kernel-level EDR evasion via abuse of vulnerable/malicious signed drivers (BYOVD). Added to the tracker given its sustained 80+ victim count and multi-outlet security-vendor coverage through mid-July 2026. Deadlock claimed West African Resources Ltd, an Australian gold miner, as a victim on 2026-07-26, alongside further victims in Colombia and elsewhere in late July 2026. Deadlock sustained a fast pace into early August 2026, claiming KEMEK (Lithuanian engineering firm, 2026-07-25), Vinilon Group (Indonesian pipe manufacturer, 2026-07-25), Caspian One (UK IT/recruitment, 2026-07-26), High Class Car Limo (NYC transport, 2026-07-26), Hardware Asesorias Software Ltda (Chile, 2026-07-27), Pasello (US, 2026-07-28), AHENK lab (Turkey, 2026-07-28), and Diater (Madrid biopharma, patient/HCP medical records, 2026-08-01); Security Affairs also reported a batch of 12 Italian organizations claimed in a single day alongside LockBit 5.0 and Qilin activity. Group-IB assesses the Polygon-blockchain C2 model may spread to other ransomware operations given its resilience to conventional takedown. Microsoft's Security Blog and The Hacker News both published detailed technical breakdowns of Deadlock's Polygon-blockchain-backed C2/recovery infrastructure on 2026-08-10, reinforcing the earlier assessment that the model is designed to resist conventional takedown; TechTimes reported the group had surpassed 80 confirmed victims by 2026-08-11, with cumulative estimates from other trackers running as high as roughly 96-100 victims concentrated in Italy, Spain, Poland, Turkey, and the US.
TTPs
Chaos Chaos RaaS (2026 incarnation)
RaaS operation launched in February 2026 by operators assessed to be former BlackSuit (Royal-lineage) affiliates, reorganizing after BlackSuit's disruption. Distinguishes itself commercially by bundling optional DDoS attacks into its affiliate service alongside the standard double-extortion encryptor, and by using vishing (voice phishing) as a primary initial-access vector. Reached roughly 36 claimed victims by late March 2026 and has continued posting through mid-2026, including a claim against Wikoff.com noted on its leak site around 2026-07-20. Added to the tracker given its 20+ victim count, distinct BlackSuit-successor lineage, and sustained security-vendor coverage. Cisco Talos disclosed a new Chaos-linked Rust-based RAT, 'msaRAT,' around 2026-07-23 that hides its C2 traffic entirely inside legitimate Chrome/Edge browser sessions via the Chrome DevTools Protocol, tunneling through Cloudflare/Twilio infrastructure so it never touches the network directly — a notable evasion technique that drew coverage from The Hacker News, BleepingComputer, and Help Net Security. Chaos claimed The Craneware Group (~960GB of claimed 'regulatory data', 2026-07-28) and healthcarehighways.com (US healthcare, ~235GB claimed, leak notice published 2026-08-04). Note: a separate, unrelated ShinyHunters/Scattered Spider/LAPSUS$ leak-site brand calling itself 'Trinity of Chaos' emerged in mid-2026 — it is not the same operation as this BlackSuit-lineage Chaos RaaS and should not be conflated with it.
TTPs
INC Ransom INC Ransomware
Long-running RaaS whose leak-site brand has persisted independently alongside the Lynx rebrand that split from it in 2024; the two operations continue to be confused on some tracking platforms despite the operational separation. INC Ransom surged sharply in the 2026-07/08 window, emerging as the dominant exploiter of two new SonicWall SMA 1000 series VPN zero-days, CVE-2026-15409 and CVE-2026-15410 (patched by SonicWall in mid-July 2026); The Hacker News described the group as 'the dominant' operation riding this exploit chain in coverage published 2026-08-03. Cumulative leak-site claims reached roughly 885 victims by early August 2026, with new postings between 2026-07-17 and 2026-08-02 spanning Australia, the United States, the UAE, Colombia, Switzerland, and other countries across both private- and government-sector targets. The group is also linked (alongside sibling brand Lynx) to the 'FortiBleed' mass FortiGate-credential-theft campaign (430,000+ exposed devices) reported 2026-07-02, with an operator observed logged into both INC Ransom's and Lynx's ransom-negotiation panels and at least 12 ransomware deployments (hundreds of endpoints encrypted) traced to harvested FortiBleed credentials. Distinctive for direct phone-based victim-pressure tactics: a caller using the name 'Andrew' (+1 304-384-0401) has been contacting victims directly and directing negotiations to info@helprans[.]com.
TTPs
Gunra
Conti-source-derived double-extortion ransomware first observed April 2025 that expanded into a structured RaaS affiliate program advertised on dark-web forums in early 2026. MAJOR EVENT: on 2026-08-10 CISA, the FBI, the DoD Cyber Crime Center (DC3), the NSA, the US Secret Service, and South Korea's National Police Agency issued a joint #StopRansomware advisory (AA26-222A) warning that Gunra actors are actively targeting healthcare and public health, financial services and insurance, critical manufacturing and construction, transportation systems and logistics, government services and facilities, utilities, academia, media and communications, retail, and professional/nonprofit services. Gunra actors gain initial access chiefly by exploiting CVE-2024-5559 and CVE-2025-24472 in internet-facing devices, demand ransom via a customized Tor-based negotiation portal, and threaten to publish exfiltrated data on a dedicated leak site if victims do not comply. Separate reporting the same week (The Hacker News, 2026-08) linked the group to active exploitation of Fortinet and Schneider Electric vulnerabilities for network access. ransomware.live tracked roughly 50-51 claimed victims as of early August 2026, concentrated in South Korea, Brazil, Spain, Thailand, and Hong Kong.
TTPs
Law Enforcement Actions
- Joint #StopRansomware advisory AA26-222A issued by CISA, FBI, DC3, NSA, US Secret Service, and South Korea's National Police Agency (2026-08-10) detailing Gunra TTPs and IOCs
Orova
Newly identified data-broker/extortion operation first seen in May 2026 (per WatchGuard's ransomware tracker) but only publicized starting 2026-08-04, when threat-intelligence firm FalconFeeds.io posted a bulk alert announcing the group had placed 24 organizations on its Tor-hosted data leak site (plus a separate Tor-hosted negotiation chat portal). Darkfield and ransomware.live independently indexed 35 public victims claimed between 2026-08-04 and 2026-08-06, with estimated attack dates stretching back to late May 2026 — indicating months of quiet operation before the public leak-site launch. WatchGuard classifies Orova as a 'Data Broker' operation, meaning its leverage comes from data theft and threatened publication rather than encryption. Victims cluster in the United States (13), Hong Kong (5), Taiwan (4), Brazil (1), and Egypt (1), spanning manufacturing, retail/e-commerce, healthcare, and agriculture/food production — an opportunistic rather than narrowly targeted pattern. Notably, Orova's disclosure of five breached Hong Kong firms (2026-08-06) landed the same day as the Hong Kong Securities and Futures Commission's first-ever cybersecurity fine, per TechTimes.
TTPs
L Group
Relatively new double-extortion operation assessed to have emerged in late 2025 (exact founding date not independently confirmed), which encrypts victim systems while exfiltrating data and threatening publication unless paid. RansomLook recorded 26 L Group posts on 2026-08-06, all published the same day, making it one of the top-claiming groups during the 2026-08-03 to 2026-08-09 weekly window (336 total victim listings tracked across all leak sites that week). As of early August 2026, L Group had 26 victims across 15 countries, led by the United States (7), with additional victims in Brazil, Australia, Argentina, and Germany (2 each); top sectors are Retail & E-Commerce (6), Professional Services (5), Technology (3), and Manufacturing (2). Likely gains initial access through phishing, exploited remote-desktop services, or compromised credentials rather than sophisticated zero-days; operational tempo is moderate, with campaigns tending to focus on a limited number of higher-value targets per burst rather than mass opportunistic phishing. Added given it crossed the 20+ tracked-victim threshold within days of first being flagged.
TTPs
Dire Wolf DireWolf
Human-operated, financially motivated double-extortion group that surfaced publicly in May 2025 and has continued expanding operations through mid-2026; not previously tracked here despite its age given a lower public profile until recent growth. Presents itself to victims with the tagline 'We only seek money. No morals, no political stance,' emphasizing a purely financial motive. As of 2026-08-10 the group had publicly claimed 75 victims on its leak site across 30 countries, with top sectors Manufacturing (21%), Professional Services (19%), and Healthcare (9%), and top countries Malaysia (9), Thailand (6), United States (6), Taiwan (5), and Singapore (5). Recent named victims include Quironsalud (Spain, major private healthcare provider, discovered 2026-08-10) and AliveCor, Inc. (US medical-device company, discovered 2026-08-10). Added to the tracker given its sustained 75-victim count and multi-outlet security-vendor coverage (SOCRadar, ProvenData, Cyble, ASEC, DarkReading, LevelBlue).
TTPs
Dark Project
Newly emerging financially motivated ransomware/data-extortion operation first publicly observed 2026-08-05, with a heterogeneous initial victim list (healthcare, manufacturing, automotive, education, transportation/logistics, engineering, packaging, IT, and a public convention/entertainment authority) supporting opportunistic rather than sector-specialized targeting. As of 2026-08-05, GalaxyWarden had tracked 28 incidents attributed to the group. Victims span five countries, led by the United States (14), with the UK (2), and one each in Mexico, Germany, and the Philippines; top sectors are Manufacturing (6), Healthcare (4), and Transportation (3). Named victims include The Miller Group, Mayco International, Leviton, Long-Lewis Automotive Group, and Reid Electric Service, Inc. Best characterized by its data-extortion leak-site posture rather than a confirmed public link to a specific encryptor family. Added given it crossed the 20+ tracked-incident threshold within days of first being observed.
TTPs
Silent Ransom Group Luna Moth / Chatty Spider / UNC3753 / LeakedData
Financially motivated extortion crew, also widely known as Luna Moth, that emerged in March 2022 in the wake of Conti's collapse (BazarCall/callback-phishing lineage). Distinctively, the group does not deploy ransomware or an encryptor at all — it relies on vishing and fake IT-helpdesk social engineering to trick employees into installing legitimate remote-access tools, then exfiltrates data and extorts victims purely under threat of publication. Since late 2025 the group has escalated to sending in-person operators to physically visit targeted companies' corporate offices, impersonating IT support staff, to gain the same remote-access foothold — an old physical-intrusion tactic returning to prominence. The FBI issued FLASH advisory FLASH-20260526-01 (2026-05-26) warning specifically of the group's IT-impersonation social-engineering campaign against US law firms. Not previously tracked here despite the group's age given its non-ransomware technical profile; added given the scale of 2026 media/insurance-market coverage and its outsized financial impact. The group has claimed 100+ attacks since 2022 without deploying a single line of ransomware code, heavily concentrated on US law firms. Confirmed high-value ransom/suppression payments reported by The Insurer across 2026 include: Jones Day (data published after a $13M demand went unmet, ~April 2026), Weil Gotshal & Manges (between $18M-$20M paid, reported 2026-05-27), WilmerHale (at least $18M paid, with CNA covering the primary layer, reported 2026-08-07), and Goodwin Procter (roughly $10M paid, reported 2026-08-07).
TTPs
Law Enforcement Actions
- FBI FLASH advisory FLASH-20260526-01 (2026-05-26) warning of Silent Ransom Group's IT-impersonation social-engineering campaign targeting law firms
Ransom Cartel
RaaS operation created and administered by Maksim Silnikau, a 40-year-old Belarusian national active on Russian-speaking cybercrime forums since at least 2005 (aliases 'J.P. Morgan,' 'xxx,' 'lansky'; former member of the Direct Connection cybercrime forum, 2011-2016). Silnikau began developing Ransom Cartel in May 2021 and recruited affiliates and initial-access brokers through underground forums. Between 2021 and 2023, Ransom Cartel affiliates attacked at least 18 companies worldwide — including victims in California, New York, and Nebraska — attempting to extort at least $5.2M, with more than $6.7M in confirmed US victim losses identified. Silnikau was arrested in Spain on 2023-07-18 and later extradited via Poland to the United States. MAJOR EVENT: on 2026-08-05 a federal judge in Alexandria, Virginia, sentenced Silnikau to 16 years in prison after conviction for conspiracy to commit offenses against the United States, conspiracy to commit wire fraud, and aggravated identity theft. Added to the tracker despite the operation's small confirmed victim count and long-defunct status, given the scale of DOJ/US Secret Service coverage of the sentencing and its significance as a Ransom Cartel case closure.
TTPs
Law Enforcement Actions
- Creator/administrator Maksim Silnikau (Belarusian national) sentenced to 16 years in federal prison (2026-08-05, Alexandria, VA) after pleading guilty to conspiracy to commit offenses against the United States, conspiracy to commit wire fraud, and aggravated identity theft; arrested in Spain 2023-07-18, extradited via Poland