Visualização normal

Antes de ontemStream principal
  • ✇ASEC BLOG
  • July 2026 Threat Trend Report on Ransomware ATCP
    Purpose and Scope The July 2026 Threat Trend Report on Ransomware summarizes major Korean & global ransomware issues based on statistics regarding the quantity of new ransomware samples, the number of compromised systems, and statistics on targeted businesses. Statistics on targeted businesses were compiled based on information published on DLS (Dedicated Leak Sites, also referred […]
     

July 2026 Threat Trend Report on Ransomware

Por:ATCP
23 de Agosto de 2026, 12:00
Purpose and Scope The July 2026 Threat Trend Report on Ransomware summarizes major Korean & global ransomware issues based on statistics regarding the quantity of new ransomware samples, the number of compromised systems, and statistics on targeted businesses. Statistics on targeted businesses were compiled based on information published on DLS (Dedicated Leak Sites, also referred […]
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 2, August 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 2, August 2026.           DragonForce Ransomware Attack on a South Korean Online Education Company Qilin Ransomware Attack on a South Korean Motor and Robotics Manufacturer ShinyHunters Claims Data Leak from a U.S. Digital Healthcare Company
     

Ransom & Dark Web Issues Week 2, August 2026

Por:ATCP
12 de Agosto de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 2, August 2026.           DragonForce Ransomware Attack on a South Korean Online Education Company Qilin Ransomware Attack on a South Korean Motor and Robotics Manufacturer ShinyHunters Claims Data Leak from a U.S. Digital Healthcare Company
  • ✇@BushidoToken Threat Intel
  • UK Cybercrime Journal: Qilin Ransomware Rampage in H1 2026 BushidoToken
     What HappenedThroughout H1 2026, the Qilin ransomware-as-a-service (RaaS) Tor data leak site (DLS) listed the most UK-based victims out of all ransomware gangs, with up to 37 British organisations hit in total. Qilin's victim count is followed by DragonForce with 21 victims listed, and TheGentlemen with 18 listed.The fallout from the Qilin attack on the UK National Health Service (NHS) supplier, Synnovis, in 2024 persists as well. On 1 June 2026, the Bedfordshire Hospitals NHS Foundation Trust
     

UK Cybercrime Journal: Qilin Ransomware Rampage in H1 2026

5 de Agosto de 2026, 05:00

 

What Happened

  • Throughout H1 2026, the Qilin ransomware-as-a-service (RaaS) Tor data leak site (DLS) listed the most UK-based victims out of all ransomware gangs, with up to 37 British organisations hit in total. Qilin's victim count is followed by DragonForce with 21 victims listed, and TheGentlemen with 18 listed.
  • The fallout from the Qilin attack on the UK National Health Service (NHS) supplier, Synnovis, in 2024 persists as well. On 1 June 2026, the Bedfordshire Hospitals NHS Foundation Trust disclosed that over 32,000 patient data records related to Synnovis tests were exfiltrated and took over a year to analyse what information was related to which patient. The breached data includes patient name and number, date of birth, postcode, and test results.
  • In H1 2026, Qilin averaged between seven and nine published UK victims per month. For the entries listing an estimated attack date, there was a roughly six-week extortion lifecycle on average, from initial intrusion to the date the victim is publicly named.
  • This UK footprint highlights their aggressive pursuit of Small-to-Medium Enterprises (SMEs) as most organisations had a revenue between £10m and £250m.
  • Interestingly, one of the Qilin victims, Salford City College, also appeared on both the Qilin and DragonForce Tor data leak site (DLS) only a few days apart from 6 March to 10 March 2026, respectively.

Qilin’s UK-based victims from H1 2026 spanned a diverse range of sectors:

  • Construction & Property Development
  • Manufacturing & Engineering
  • Legal & Professional Services
  • Technology & IT Infrastructure
  • Education
  • Healthcare

Analyst Comment 

Many of the organisations targeted by Qilin operators are just large enough to have the funds to pay mid-tier ransoms but often never got around to making an investment into a 24/7 dedicated threat detection service, such as an outsourced Security Operations Centre (SOC). Such services are usually enough protection to prevent an attack. If a ransomware affiliate faces tough resistance from a target, they often move on to a weaker and easier one.

One key face to also note about Tor data leak sites operated by ransomware groups is that they include victims who failed to pay the ransom. The total number of victims by each group is often going to be higher.

The reason for the cross-posting of Salford City College is unknown for now. However, it could indicate that an affiliate may be using both Qilin and DragonForce RaaS platforms. An alternative theory could be that the college was hit by two affiliates of each RaaS. Interestingly, cross-posting on multiple leak sites is not as uncommon as it seems. Some victims listed on the Qilin leak site have historically appeared on the leak sites of ALPHV/BlackCat and Conti as well.

The Ransomware Vulnerability Matrix Group Profile for Qilin reveals a diverse set of exploits leveraged by its operators. Like many other ransomware gangs, Qilin operators have exploited corporate VPN gateways such as Fortinet, Check Point, and WatchGuard for initial access. Interestingly, the exploitation of SmarterTools SmarterMail and SolarWinds Web Help Desk is less common but are also exploited by the Warlock ransomware gang. Another common theme from Qilin's Ransomware Tool Matrix Group Profile is their regular abuse of Bring Your Own Vulnerable Driver (BYOVD) tactics to bypass Endpoint Detection and Response (EDR) and Antivirus software.

Defensive Takeaways 

  • Harden Common Attack Paths: Treat any web-facing helpdesk or mail server as a high-risk device. If it does not absolutely require open internet access, place it behind a zero-trust network access gateway or a strict VPN. Enforce strict phishing-resistant Multi-Factor Authentication (MFA) on all remote access points. Ensure processes are in place for rapid patching and integrity checks for all corporate VPN gateways.
  • Overcoming SME Resource Caps: Organisations must bridge the gap with an outsourced MDR service. Ransomware execution routinely happens at 2:00 AM on Fridays and weekends. Outdated antivirus agents alone are not enough to stop a motivated human adversary.
  • Utilise Free Support Services: Capitalise on sovereign and community-vetted threat intelligence feeds to block attacker infrastructure early. UK defenders should actively enroll in the National Cyber Security Centre’s MyNCSC portal and integrate community resources like the Spamhaus DROP list and Abuse.ch tracking into their perimeter firewalls to automatically block known ransomware command-and-control (C2) nodes. ShadowServer and Team Cymru also offer useful free community resources.

Relevant Sources 

  1. https://www.bbc.co.uk/news/articles/c1d2wwyd6qqo
  2. https://www.bedfordshirehospitals.nhs.uk/news/notification-synnovis-cyber-incident/
  3. https://www.bleepingcomputer.com/news/security/qilin-ransomware-gang-linked-to-attack-on-london-hospitals/

Relevant CTI Sources

  1. https://www.ransomware.live/map/GB
  2. https://www.ransomware.live/group/qilin
  3. https://www.ransomware.live/id/c2FsZm9yZGNjLmFjLnVrQGRyYWdvbmZvcmNl
  4. https://www.ransomware.live/id/U2FsZm9yZCBDaXR5IENvbGxlZ2VAcWlsaW4
  5. https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/GroupProfiles/Qilin.md
  6. https://github.com/BushidoUK/Ransomware-Vulnerability-Matrix/blob/main/GroupProfiles/Qilin.md
  7. https://blog.bushidotoken.net/2024/06/tracking-adversaries-qilin-raas.html 
  8. https://www.bleepingcomputer.com/news/security/check-point-links-vpn-zero-day-attacks-to-qilin-ransomware-gang/

  • ✇ASEC BLOG
  • June 2026 Ransomware Trend Report ATCP
    Purpose and Scope This report summarizes the quantity of ransomware samples collected, the number of affected systems, statistics on targeted businesses, and major Korean & global issues during the month of June 2026. Statistics on targeted businesses were compiled based on information posted on DLS (Dedicated Leak Sites) operated by ransomware groups, which publish details […]
     

June 2026 Ransomware Trend Report

Por:ATCP
15 de Julho de 2026, 12:00
Purpose and Scope This report summarizes the quantity of ransomware samples collected, the number of affected systems, statistics on targeted businesses, and major Korean & global issues during the month of June 2026. Statistics on targeted businesses were compiled based on information posted on DLS (Dedicated Leak Sites) operated by ransomware groups, which publish details […]

One Country Absorbed Nearly Half of the World’s Ransomware Attacks in Just Six Months – The United States

24 de Julho de 2026, 02:09

Ransomware Attacks, Qilin, US, Ransomware Attacks on US

Strip away the geopolitics, the hacktivist noise, and the espionage headlines, and one number from the first half of 2026 stands out above everything else: 1,721. That's how many ransomware attacks hit organizations in the United States between January and June, according to new research from Cyble Research and Intelligence Labs (CRIL). It's not just the highest total of any country tracked in the report — it's more than the next nine most-targeted countries combined.

Canada, in second place worldwide, recorded 179 attacks. Germany logged 155. The United Kingdom, 138. Add up the rest of the global top 10 — France, Italy, Spain, Thailand, India and Brazil — and the total still falls more than 600 attacks short of the U.S. figure alone. Out of 3,836 ransomware attacks CRIL tracked worldwide this half, roughly 45% landed on American soil.

Also read: Fairlife Ransomware Attack Hits Production Systems, U.S. Operations Suspended

A Single Region, an Outsized Share

Widen the lens slightly and the picture holds. North America as a whole recorded 1,981 ransomware attacks in H1 2026 — more than half of every ransomware incident Cyble observed globally — alongside 35 data breach and leak incidents and 9 initial access sale listings. The report describes the region as home to "a mature, persistently active RaaS ecosystem operating at high volume across a wide range of industries and geographies."

Two ransomware-as-a-service operators did much of the damage. Qilin, the single most prolific gang worldwide, claimed 370 of those North American attacks on its own — nearly 19% of the regional total. Akira followed with 268, and INC Ransom added another 164. Together, Qilin and Akira alone accounted for more than half of all recorded ransomware activity across the region, a level of concentration that points to a small number of highly organized affiliate networks doing the bulk of the damage rather than a diffuse swarm of opportunists.

Also read: Qilin Ransomware Group’s TTPs Examined by Researchers

Where the Pressure Lands

Professional Services bore the brunt of North American ransomware activity, with INC Ransom showing a marked preference for law firms and other high-value services with sensitive client data. Construction, Manufacturing and Healthcare followed close behind.

One operator, AiLock, stood out for a coordinated wave of victim disclosures that all landed on the same day — March 3 — a pattern consistent with a mass-exploitation campaign rather than isolated intrusions. LockBit, despite years of law enforcement pressure and takedown attempts, kept up a steady tempo against public-sector and educational targets throughout the period, showcasing how difficult the group has been to fully dismantle.

On the data breach side, Technology and financial services (BFSI) were the most frequently targeted sectors in North America, together accounting for roughly 43% of incidents — a reflection of how much intellectual property and monetizable personal data those industries hold.

Notably, Agriculture & Livestock emerged as a significant target for initial access brokers, accounting for a third of all access listings tied to the region. Cyble flags this as a sign of "growing risk in the food supply chain," an area that has historically drawn less attention from ransomware operators than finance or healthcare.

The initial access market itself was strikingly concentrated: two sellers, tracked under the handles "redpin" and "xpl0itrs," accounted for nearly all listings targeting North American organizations. Threat actors also continued to lean on known and zero-day vulnerabilities in widely deployed enterprise platforms — including products from Ivanti and Palo Alto Networks — as their preferred way into corporate networks.

Hacktivism Blurs into Cybercrime

North America wasn't spared the hacktivism wave sweeping the rest of the world either. Collectives including SOLDADOS DIGITALES – UNIÓN AMERICANA and LYSTIC TEAM #ID drove roughly 56 data leak or dump posts and touched about 360 unique domains across the region, with Government, Technology, financial services and telecommunications entities most frequently in the crosshairs.

Cyble's broader findings suggest many groups marketing themselves as ideologically driven hacktivists are, in practice, running side businesses in stolen data brokerage and DDoS-for-hire services — a blurring of motive that complicates how defenders triage the threat.

The scale of the U.S. numbers doesn't necessarily mean American companies have weaker defenses than their global peers — the concentration also reflects the sheer size and digital density of the U.S. economy, and its outsized share of the high-value targets ransomware affiliates chase. But the data does argue for a shift in posture.

Cyble's broader recommendations — treating data exfiltration, not just encryption, as the primary risk; prioritizing patches for the recurring vendor list; and monitoring initial access markets as a leading indicator rather than an afterthought — apply nowhere more urgently than in a country absorbing this much of the world's ransomware volume on its own.

  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 4, July 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 4, July 2026           Source Code Collection of a South Korean Autonomous Robot Manufacturer Shared on a Cybercrime Forum Qilin Ransomware Attack on a Spanish Public Wastewater Management Organization RansomHouse Ransomware Attack on a Japanese Frozen Food and Logistics Company
     

Ransom & Dark Web Issues Week 4, July 2026

Por:ATCP
22 de Julho de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 4, July 2026           Source Code Collection of a South Korean Autonomous Robot Manufacturer Shared on a Cybercrime Forum Qilin Ransomware Attack on a Spanish Public Wastewater Management Organization RansomHouse Ransomware Attack on a Japanese Frozen Food and Logistics Company
  • ✇ASEC BLOG
  • June 2026 Security Issues in Korean & Global Financial Sector ATCP
    Statistics on Malware Distributed to the Financial Sector In the June threat analysis for the financial sector, phishing was the most prevalent attack method in Attack Stage 1, while droppers/downloaders (distribution tools that download additional malware) were the most prevalent in Attack Stage 2. Infostealers were identified in the third attack stage, indicating that multi-stage […]
     

June 2026 Security Issues in Korean & Global Financial Sector

Por:ATCP
15 de Julho de 2026, 12:00
Statistics on Malware Distributed to the Financial Sector In the June threat analysis for the financial sector, phishing was the most prevalent attack method in Attack Stage 1, while droppers/downloaders (distribution tools that download additional malware) were the most prevalent in Attack Stage 2. Infostealers were identified in the third attack stage, indicating that multi-stage […]
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 4, June 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 4, June 2026       BreachForums, a cybercrime forum, showing signs of admitting to sales and impersonation of its staff Lapsus$ claims to have leaked data from a bank in Myanmar Qilin launches a ransomware attack targeting a law firm in South Korea
     

Ransom & Dark Web Issues Week 4, June 2026

Por:ATCP
24 de Junho de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 4, June 2026       BreachForums, a cybercrime forum, showing signs of admitting to sales and impersonation of its staff Lapsus$ claims to have leaked data from a bank in Myanmar Qilin launches a ransomware attack targeting a law firm in South Korea
  • ✇ASEC BLOG
  • May 2026 Threat Trend Report on Ransomware ATCP
    Purpose and Scope This report summarizes the quantity of new ransomware samples collected during the month of May 2026, the number of affected systems, statistics on targeted businesses, and major Korean & Global ransomware issues. Statistics on samples and affected systems are based on AhnLab’s detection names, while statistics on targeted businesses are aggregated based […]
     

May 2026 Threat Trend Report on Ransomware

Por:ATCP
18 de Junho de 2026, 12:00
Purpose and Scope This report summarizes the quantity of new ransomware samples collected during the month of May 2026, the number of affected systems, statistics on targeted businesses, and major Korean & Global ransomware issues. Statistics on samples and affected systems are based on AhnLab’s detection names, while statistics on targeted businesses are aggregated based […]
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 3, June 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 3, June 2026         Sale of Confidencial Defense Industry Documents in South Korea on Spear Forums Ransomware Attack by Qilin Targeting a South Korean Big Data Solution Company Ransomware Attack by Anubis Targeting a South Korean Semiconductor Equipment Parts Company
     

Ransom & Dark Web Issues Week 3, June 2026

Por:ATCP
17 de Junho de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 3, June 2026         Sale of Confidencial Defense Industry Documents in South Korea on Spear Forums Ransomware Attack by Qilin Targeting a South Korean Big Data Solution Company Ransomware Attack by Anubis Targeting a South Korean Semiconductor Equipment Parts Company
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 1, June 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 1, June 2026           Qilin Ransomware Attack Targets South Korean Automation Equipment Company New Data Extortion Group Black X Claims Leak of Internal Data from South Korean Plastic Surgery Clinic Nova Ransomware Attack Targets Department of AI at University in Daegu, South […]
     

Ransom & Dark Web Issues Week 1, June 2026

Por:ATCP
3 de Junho de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 1, June 2026           Qilin Ransomware Attack Targets South Korean Automation Equipment Company New Data Extortion Group Black X Claims Leak of Internal Data from South Korean Plastic Surgery Clinic Nova Ransomware Attack Targets Department of AI at University in Daegu, South […]

Ransomware Attacks Surge 30% in 2026 as Qilin and INC Ransom Intensify Operations

Qilin

Ransomware attacks surged 30% in the first half of 2026 compared to the same period in 2025, with Qilin and INC Ransom emerging as two of the most prolific and dangerous operators in a crowded criminal ecosystem. Healthcare continues to be the top targeted industry, with 27 incidents in January 2026 alone, a figure that reflects both the sector's operational sensitivity and the premium value of health records on darknet markets.

Qilin: The Dominant Force

Qilin — also known as Agenda — is a ransomware group that entered 2026 accelerating, not slowing down. By early 2026, Qilin had already posted 55 confirmed victims, placing it ahead of its own 2025 pace. By June 2026, tracking data, Qilin had accumulated 168 confirmed victims in the healthcare sector alone, behind only manufacturing (291) and business services (245) in overall victim count. Qilin operates as a Ransomware-as-a-Service (RaaS) platform, recruiting affiliates who conduct attacks using Qilin's ransomware builder and infrastructure in exchange for a percentage of ransom proceeds. This model allows the core group to expand operational throughput without directly executing every attack. The group's double extortion model — encrypting victim data while simultaneously exfiltrating it and threatening public release on their leak site — has proven effective at pressuring victims into paying ransom demands even when robust backups exist. Public exposure of sensitive patient records creates regulatory, legal, and reputational pressure that many healthcare organisations find more immediately damaging than operational downtime. A notable recent case involves Covenant Health, which suffered a Qilin ransomware breach that exposed 478,188 patient records. The Covenant Health incident highlights Qilin's willingness to attack hospitals and health systems regardless of the direct patient safety implications.

INC Ransom: Targeting Critical Sectors

INC Ransom is another highly active operator that was among the top ransomware groups by victim count in January 2026, with 47 known attacks that month. The group targets organisations across multiple sectors, including healthcare, legal services, and public administration. INC Ransom gained significant attention in 2025 for its attack on NHS Scotland, which exposed 3 terabytes of patient data. The group continues to operate aggressively in 2026, targeting entities including healthcare practices, municipal agencies, and regional service providers. Recent INC Ransom victims include healthcare organisations such as Lymphedema Therapy Specialists, Inc. (February 2026, affecting 378 Texas patients) and various municipal and public sector entities, including Champaign-Urbana Public Health District.

The 2026 Ransomware Landscape

Beyond Qilin and INC Ransom, the broader 2026 ransomware ecosystem is characterised by:
  • AI-assisted operations: Multiple ransomware groups are now using AI tools to accelerate phishing campaign creation, target research, and initial access operations, reducing the operational cost of launching attacks.
  • Healthcare as a premium target: Patient records sell for up to 10 times as much as financial records on darknet markets, making it a persistently attractive target. Operational disruption of healthcare services also creates patient-safety leverage that can pressure organisations to make faster payment decisions.
  • The Play and SafePay operators were also confirmed in recent June 2026 attack disclosures, targeting organisations including Clínica Maitenes and various regional businesses.

Why It Matters

The 30% year-over-year increase in ransomware incidents confirms that neither law enforcement action nor improved defensive capabilities has materially reduced the operational tempo of ransomware criminal enterprises. The professionalisation of RaaS platforms, combined with AI-assisted tooling and shortened attack timelines, is creating conditions in which even well-defended organisations face materially elevated risk. For healthcare specifically, the combination of operational sensitivity, high data value, and historically underfunded security programmes creates a structural vulnerability that the industry has not yet resolved despite years of high-profile attacks.
  • ✇ASEC BLOG
  • April 2026 Security Issues in Korean & Global Financial Sector ATCP
    Statistics on Malware Distributed to the Financial Sector attack Stage 1 Phishing, Attack Stage 2 Backdoor-Downloader-Dropper, and Attack Stage 3 Infostealer-Ransomware were identified as the top malware in the financial sector. The actual distribution files were identified based on MD5 Hash, and it was explained that there may be many variants of the same family. […]
     

April 2026 Security Issues in Korean & Global Financial Sector

Por:ATCP
12 de Maio de 2026, 12:00
Statistics on Malware Distributed to the Financial Sector attack Stage 1 Phishing, Attack Stage 2 Backdoor-Downloader-Dropper, and Attack Stage 3 Infostealer-Ransomware were identified as the top malware in the financial sector. The actual distribution files were identified based on MD5 Hash, and it was explained that there may be many variants of the same family. […]
  • ✇ASEC BLOG
  • March 2026 Ransomware Trends Report ATCP
    Purpose and Scope. this report summarizes the number of ransomware samples, number of affected systems, DLS-based statistics, and major Korean & Global ransomware issues identified during the month of March 2026. Key statistics. ransomware sample counts and victimized systems statistics were aggregated by detection name assigned by AhnLab. statistics on targeted businesses were calculated based […]
     

March 2026 Ransomware Trends Report

Por:ATCP
12 de Abril de 2026, 12:00
Purpose and Scope. this report summarizes the number of ransomware samples, number of affected systems, DLS-based statistics, and major Korean & Global ransomware issues identified during the month of March 2026. Key statistics. ransomware sample counts and victimized systems statistics were aggregated by detection name assigned by AhnLab. statistics on targeted businesses were calculated based […]
  • ✇@BushidoToken Threat Intel
  • Ransomware Tool Matrix Project Updates: May 2025 BushidoToken
    IntroductionThis blog is a summary and analysis of recent additions to the Ransomware Tool Matrix (RTM) as well as the Ransomware Vulnerability Matrix (RVM). Feedback from the infosec community about these projects has been overwhelmingly positive and many researchers have contacted me to tell me how helpful they have found these to be. It makes me happy to hear how doing something in my spare time can help stop ransomware attacks and cybercriminals from exploiting our society’s systems. And it
     

Ransomware Tool Matrix Project Updates: May 2025

5 de Maio de 2025, 19:01

Introduction

This blog is a summary and analysis of recent additions to the Ransomware Tool Matrix (RTM) as well as the Ransomware Vulnerability Matrix (RVM)Feedback from the infosec community about these projects has been overwhelmingly positive and many researchers have contacted me to tell me how helpful they have found these to be. It makes me happy to hear how doing something in my spare time can help stop ransomware attacks and cybercriminals from exploiting our society’s systems. And it is for that reason, I shall continue to maintain these projects as long as ransomware is still around. For anyone new to these projects, please read the descriptions on GitHub or feel free to watch my talk explaining the project at BSides London.

Background on the current ransomware ecosystem as of May 2025

Following the impact of Operation Cronos against LockBit and the exit scam by ALPHV/BlackCat, the ransomware ecosystem has been even more unstable than usual. The exit scams and law enforcement infiltration operations have created a zero trust environment for the cybercriminals participating in the ransomware economy. The days of affiliates putting their faith in one RaaS platform seem to be long gone and many are experimenting and going from one RaaS to the next.

Sources of Threat Intelligence for the RTM

The RTM was updated with OSINT reports shared by cybersecurity researchers at various private service providers or vendors. The thing to remember about these reports is that the tool usage is going to be slightly outdated due to the time it takes incident response teams to wrap up an investigation, compile findings, and publish a report.

From the reports, threat groups such as Qilin, BlackSuit, RansomEXX, Medusa, BianLian, Hunters International and PLAY have been active for over one year or for multiple years. These are established groups. Since RansomHub and LockBit have shut down, it is more likely than not that the affiliates have already shifted to one of the other RaaS platforms, like Qilin, among others.

There has also been a number of ransomware operations suspected to be linked to Chinese cyber-espionage groups, such as RA World (for using PlugX), NailaoLocker (for using ShadowPad and PlugX), and CrazyHunter (for its focus on Taiwan).

Threat groups such as IMN Crew, QWCrypt (linked to RedCurl), NightSpire, SuperBlack, and Helldown are all rising threat groups that have more recently begun their ransomware campaigns.

These factors have led to seeing a large variety of tool usage in ransomware operations being observed across the landscape. The reliance on tools from sites like GitHub and other free software sites, however, continues to remain a constant theme among all of these ransomware operations.

List of sources used for the May 2025 major update to the RTM:

Group Name

Report Publish Date

URL

Qilin

25 April 2025

10 March 2025


redpiranha.net

picussecurity.com

IMN Crew

24 April 2025


s-rminform.com

CrazyHunter

16 April 2025


trendmicro.com

RansomEXX

8 April 2025


microsoft.com

BlackSuit

31 March 2025


thedfirreport.com

QWCrypt

26 March 2025


bitdefender.com

RansomHub

26 March 2025

20 March 2025


welivesecurity.com

security.com

Medusa

26 March 2025

6 March 2025


welivesecurity.com

security.com

BianLian

26 March 2025


welivesecurity.com

PLAY

26 March 2025


welivesecurity.com

NightSpire

25 March 2025


s-rminform.com

Hunters International

19 March 2025

esentire.com

SuperBlack

13 March 2025


forescout.com

LockBit

24 February 2025


thedfirreport.com

NailaoLocker

20 February 2025

18 February 2025


orangecyberdefense.com

trendmicro.com

RA World

13 February 2025

22 July 2024


security.com

unit42.paloaltonetworks.com

Helldown

7 November 2024


truesec.com

Tools Used by Multiple Groups

  • EDRSandBlast and WKTools are relatively new tools that are being used by multiple groups to deactivate and overcome EDR tools that many victims will have on their networks to prevent ransomware attacks.
  • Typical ransomware tools, such as PsExec, Mimikatz, and Rclone remain effective and still used by multiple ransomware gangs for the foreseeable future.

Tool

Type

Groups Using It

WinSCP

Exfiltration

NightSpire

Hunters International


Mimikatz

Credential Theft

RansomHub

Qilin

Helldown


Impacket

Offensive Security Tool

RansomHub

RA World

NailaoLocker


Rclone

Exfiltration

RansomHub

Hunters International Medusa


NetScan

Discovery

RansomHub

Medusa


WKTools

Discovery

RansomHub

BianLian

PLAY


Advanced IP Scanner

Discovery

Hunters International BianLian


Advanced Port Scanner

Discovery

Hunters International Helldown


AnyDesk

RMM Tool

Medusa

BianLian


EDRSandBlast

Defense Evasion

Medusa

Qilin


New Tools Added to the RTM

  • The most notable new tools added to RTM include several defense evasion tools for deactivating EDRs, discovery for sensitive files, and tunnelling tools to conceal adversary network connections.

Tool

Type

Groups Usage

Bublup

Exfiltration


BlackSuit

WKTools

Discovery


BianLian, PLAY

AmmyyAdmin

RMM Tool


BianLian

CQHashDump

Credential Theft


NailaoLocker

Throttle Stop Driver

Defense Evasion


Medusa

KillAV

Defense Evasion


Medusa

BadRentdrv2

Defense Evasion


RansomHub

Toshiba Power Driver (BYOVD)

Defense Evasion

Qilin

ZammoCide

Defense Evasion


CrazyHunter

FRP

Networking


Medusa

Stowaway

Networking


RansomHub

Navicat

Discovery


Medusa

Everything.exe

Discovery


NighSpire

RoboCopy

Discovery


Medusa

NPS

Networking


RA World

SharpGPOAbuse

Offensive Security Tool


CrazyHunter

Attrib

LOLBAS


BlackSuit

Curl

LOLBAS


QWCrypt (RedCurl)

PCA Utility (pcalua)

LOLBAS


QWCrypt (RedCurl)

Exploits used by Ransomware Gangs added to the RVM

  • As is now usual, multiple ransomware groups have been targeting Fortinet networking devices for initial access into to victim environments.
  • Multiple ransomware groups continue to exploit the Windows Common Log File System (CLFS) for local privilege escalation to run hacking tools and steal credentials.
  • Other exploits involve targeting edge devices, such as Check Point VPNs or PAN Firewalls, or exposed servers, such as Atlassian Confluence Data Center Servers.
  • The targeting of Veeam backup software should come as no surprise as preventing backups or stealing sensitive files, such as Active Directory backups, are key objectives of ransomware gangs to complete their mission.

Ransomware Group

Exploited CVEs

NightSpire

CVE-2024-55591 (FortiOS)


RansomHub

CVE-2022-24521 (Windows CLFS)
CVE-2023-27532 (Veeam)


LockBit

CVE-2023-22527 (Confluence)


Hunters International

CVE-2024-55591 (FortiProxy)


SuperBlack

CVE-2024-55591 (FortiProxy)


RA World

CVE-2024-0012 (PAN-OS)


NailaoLocker

CVE-2024-24919 (Check Point VPN)


RansomEXX

CVE-2025-29824 (Windows CLFS)


Conclusion

My recommendation for defenders who continue the fight against ransomware is to take some of the findings from this report and begin threat hunting, detection rule writing, and start blocking some of these tools not present in the environments you are protecting.

Here are a few sites to help you get started with:

❌
❌