Visualização normal
-
ASEC BLOG
-
July 2026 Threat Trend Report on Ransomware
Purpose and Scope The July 2026 Threat Trend Report on Ransomware summarizes major Korean & global ransomware issues based on statistics regarding the quantity of new ransomware samples, the number of compromised systems, and statistics on targeted businesses. Statistics on targeted businesses were compiled based on information published on DLS (Dedicated Leak Sites, also referred […]
-
ASEC BLOG
-
Ransom & Dark Web Issues Week 2, August 2026
ASEC Blog publishes Ransom & Dark Web Issues Week 2, August 2026. DragonForce Ransomware Attack on a South Korean Online Education Company Qilin Ransomware Attack on a South Korean Motor and Robotics Manufacturer ShinyHunters Claims Data Leak from a U.S. Digital Healthcare Company
Ransom & Dark Web Issues Week 2, August 2026
-
@BushidoToken Threat Intel

-
UK Cybercrime Journal: Qilin Ransomware Rampage in H1 2026
What HappenedThroughout H1 2026, the Qilin ransomware-as-a-service (RaaS) Tor data leak site (DLS) listed the most UK-based victims out of all ransomware gangs, with up to 37 British organisations hit in total. Qilin's victim count is followed by DragonForce with 21 victims listed, and TheGentlemen with 18 listed.The fallout from the Qilin attack on the UK National Health Service (NHS) supplier, Synnovis, in 2024 persists as well. On 1 June 2026, the Bedfordshire Hospitals NHS Foundation Trust
UK Cybercrime Journal: Qilin Ransomware Rampage in H1 2026
What Happened
- Throughout H1 2026, the Qilin ransomware-as-a-service (RaaS) Tor data leak site (DLS) listed the most UK-based victims out of all ransomware gangs, with up to 37 British organisations hit in total. Qilin's victim count is followed by DragonForce with 21 victims listed, and TheGentlemen with 18 listed.
- The fallout from the Qilin attack on the UK National Health Service (NHS) supplier, Synnovis, in 2024 persists as well. On 1 June 2026, the Bedfordshire Hospitals NHS Foundation Trust disclosed that over 32,000 patient data records related to Synnovis tests were exfiltrated and took over a year to analyse what information was related to which patient. The breached data includes patient name and number, date of birth, postcode, and test results.
- In H1 2026, Qilin averaged between seven and nine published UK victims per month. For the entries listing an estimated attack date, there was a roughly six-week extortion lifecycle on average, from initial intrusion to the date the victim is publicly named.
- This UK footprint highlights their aggressive pursuit of Small-to-Medium Enterprises (SMEs) as most organisations had a revenue between £10m and £250m.
- Interestingly, one of the Qilin victims, Salford City College, also appeared on both the Qilin and DragonForce Tor data leak site (DLS) only a few days apart from 6 March to 10 March 2026, respectively.
Qilin’s UK-based victims from H1 2026 spanned a diverse range of sectors:
- Construction & Property Development
- Manufacturing & Engineering
- Legal & Professional Services
- Technology & IT Infrastructure
- Education
- Healthcare
Analyst Comment
Many of the organisations targeted by Qilin operators are just large enough to have the funds to pay mid-tier ransoms but often never got around to making an investment into a 24/7 dedicated threat detection service, such as an outsourced Security Operations Centre (SOC). Such services are usually enough protection to prevent an attack. If a ransomware affiliate faces tough resistance from a target, they often move on to a weaker and easier one.
One key face to also note about Tor data leak sites operated by ransomware groups is that they include victims who failed to pay the ransom. The total number of victims by each group is often going to be higher.
The reason for the cross-posting of Salford City College is unknown for now. However, it could indicate that an affiliate may be using both Qilin and DragonForce RaaS platforms. An alternative theory could be that the college was hit by two affiliates of each RaaS. Interestingly, cross-posting on multiple leak sites is not as uncommon as it seems. Some victims listed on the Qilin leak site have historically appeared on the leak sites of ALPHV/BlackCat and Conti as well.
The Ransomware Vulnerability Matrix Group Profile for Qilin reveals a diverse set of exploits leveraged by its operators. Like many other ransomware gangs, Qilin operators have exploited corporate VPN gateways such as Fortinet, Check Point, and WatchGuard for initial access. Interestingly, the exploitation of SmarterTools SmarterMail and SolarWinds Web Help Desk is less common but are also exploited by the Warlock ransomware gang. Another common theme from Qilin's Ransomware Tool Matrix Group Profile is their regular abuse of Bring Your Own Vulnerable Driver (BYOVD) tactics to bypass Endpoint Detection and Response (EDR) and Antivirus software.
Defensive Takeaways
- Harden Common Attack Paths: Treat any web-facing helpdesk or mail server as a high-risk device. If it does not absolutely require open internet access, place it behind a zero-trust network access gateway or a strict VPN. Enforce strict phishing-resistant Multi-Factor Authentication (MFA) on all remote access points. Ensure processes are in place for rapid patching and integrity checks for all corporate VPN gateways.
- Overcoming SME Resource Caps: Organisations must bridge the gap with an outsourced MDR service. Ransomware execution routinely happens at 2:00 AM on Fridays and weekends. Outdated antivirus agents alone are not enough to stop a motivated human adversary.
- Utilise Free Support Services: Capitalise on sovereign and community-vetted threat intelligence feeds to block attacker infrastructure early. UK defenders should actively enroll in the National Cyber Security Centre’s MyNCSC portal and integrate community resources like the Spamhaus DROP list and Abuse.ch tracking into their perimeter firewalls to automatically block known ransomware command-and-control (C2) nodes. ShadowServer and Team Cymru also offer useful free community resources.
Relevant Sources
- https://www.bbc.co.uk/news/articles/c1d2wwyd6qqo
- https://www.bedfordshirehospitals.nhs.uk/news/notification-synnovis-cyber-incident/
- https://www.bleepingcomputer.com/news/security/qilin-ransomware-gang-linked-to-attack-on-london-hospitals/
Relevant CTI Sources
- https://www.ransomware.live/map/GB
- https://www.ransomware.live/group/qilin
- https://www.ransomware.live/id/c2FsZm9yZGNjLmFjLnVrQGRyYWdvbmZvcmNl
- https://www.ransomware.live/id/U2FsZm9yZCBDaXR5IENvbGxlZ2VAcWlsaW4
- https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/GroupProfiles/Qilin.md
- https://github.com/BushidoUK/Ransomware-Vulnerability-Matrix/blob/main/GroupProfiles/Qilin.md
- https://blog.bushidotoken.net/2024/06/tracking-adversaries-qilin-raas.html
- https://www.bleepingcomputer.com/news/security/check-point-links-vpn-zero-day-attacks-to-qilin-ransomware-gang/
-
ASEC BLOG
-
June 2026 Ransomware Trend Report
Purpose and Scope This report summarizes the quantity of ransomware samples collected, the number of affected systems, statistics on targeted businesses, and major Korean & global issues during the month of June 2026. Statistics on targeted businesses were compiled based on information posted on DLS (Dedicated Leak Sites) operated by ransomware groups, which publish details […]
June 2026 Ransomware Trend Report
-
Firewall Daily – The Cyber Express

-
One Country Absorbed Nearly Half of the World’s Ransomware Attacks in Just Six Months – The United States
Strip away the geopolitics, the hacktivist noise, and the espionage headlines, and one number from the first half of 2026 stands out above everything else: 1,721. That's how many ransomware attacks hit organizations in the United States between January and June, according to new research from Cyble Research and Intelligence Labs (CRIL). It's not just the highest total of any country tracked in the report — it's more than the next nine most-targeted countries combined. Canada, in second place wo
One Country Absorbed Nearly Half of the World’s Ransomware Attacks in Just Six Months – The United States
![]()
Strip away the geopolitics, the hacktivist noise, and the espionage headlines, and one number from the first half of 2026 stands out above everything else: 1,721. That's how many ransomware attacks hit organizations in the United States between January and June, according to new research from Cyble Research and Intelligence Labs (CRIL). It's not just the highest total of any country tracked in the report — it's more than the next nine most-targeted countries combined.
Canada, in second place worldwide, recorded 179 attacks. Germany logged 155. The United Kingdom, 138. Add up the rest of the global top 10 — France, Italy, Spain, Thailand, India and Brazil — and the total still falls more than 600 attacks short of the U.S. figure alone. Out of 3,836 ransomware attacks CRIL tracked worldwide this half, roughly 45% landed on American soil.
Also read: Fairlife Ransomware Attack Hits Production Systems, U.S. Operations Suspended
A Single Region, an Outsized Share
Widen the lens slightly and the picture holds. North America as a whole recorded 1,981 ransomware attacks in H1 2026 — more than half of every ransomware incident Cyble observed globally — alongside 35 data breach and leak incidents and 9 initial access sale listings. The report describes the region as home to "a mature, persistently active RaaS ecosystem operating at high volume across a wide range of industries and geographies."
Two ransomware-as-a-service operators did much of the damage. Qilin, the single most prolific gang worldwide, claimed 370 of those North American attacks on its own — nearly 19% of the regional total. Akira followed with 268, and INC Ransom added another 164. Together, Qilin and Akira alone accounted for more than half of all recorded ransomware activity across the region, a level of concentration that points to a small number of highly organized affiliate networks doing the bulk of the damage rather than a diffuse swarm of opportunists.
Also read: Qilin Ransomware Group’s TTPs Examined by Researchers
Where the Pressure Lands
Professional Services bore the brunt of North American ransomware activity, with INC Ransom showing a marked preference for law firms and other high-value services with sensitive client data. Construction, Manufacturing and Healthcare followed close behind.
One operator, AiLock, stood out for a coordinated wave of victim disclosures that all landed on the same day — March 3 — a pattern consistent with a mass-exploitation campaign rather than isolated intrusions. LockBit, despite years of law enforcement pressure and takedown attempts, kept up a steady tempo against public-sector and educational targets throughout the period, showcasing how difficult the group has been to fully dismantle.
On the data breach side, Technology and financial services (BFSI) were the most frequently targeted sectors in North America, together accounting for roughly 43% of incidents — a reflection of how much intellectual property and monetizable personal data those industries hold.
Notably, Agriculture & Livestock emerged as a significant target for initial access brokers, accounting for a third of all access listings tied to the region. Cyble flags this as a sign of "growing risk in the food supply chain," an area that has historically drawn less attention from ransomware operators than finance or healthcare.
The initial access market itself was strikingly concentrated: two sellers, tracked under the handles "redpin" and "xpl0itrs," accounted for nearly all listings targeting North American organizations. Threat actors also continued to lean on known and zero-day vulnerabilities in widely deployed enterprise platforms — including products from Ivanti and Palo Alto Networks — as their preferred way into corporate networks.
Hacktivism Blurs into Cybercrime
North America wasn't spared the hacktivism wave sweeping the rest of the world either. Collectives including SOLDADOS DIGITALES – UNIÓN AMERICANA and LYSTIC TEAM #ID drove roughly 56 data leak or dump posts and touched about 360 unique domains across the region, with Government, Technology, financial services and telecommunications entities most frequently in the crosshairs.
Cyble's broader findings suggest many groups marketing themselves as ideologically driven hacktivists are, in practice, running side businesses in stolen data brokerage and DDoS-for-hire services — a blurring of motive that complicates how defenders triage the threat.
The scale of the U.S. numbers doesn't necessarily mean American companies have weaker defenses than their global peers — the concentration also reflects the sheer size and digital density of the U.S. economy, and its outsized share of the high-value targets ransomware affiliates chase. But the data does argue for a shift in posture.
Cyble's broader recommendations — treating data exfiltration, not just encryption, as the primary risk; prioritizing patches for the recurring vendor list; and monitoring initial access markets as a leading indicator rather than an afterthought — apply nowhere more urgently than in a country absorbing this much of the world's ransomware volume on its own.
-
ASEC BLOG
-
Ransom & Dark Web Issues Week 4, July 2026
ASEC Blog publishes Ransom & Dark Web Issues Week 4, July 2026 Source Code Collection of a South Korean Autonomous Robot Manufacturer Shared on a Cybercrime Forum Qilin Ransomware Attack on a Spanish Public Wastewater Management Organization RansomHouse Ransomware Attack on a Japanese Frozen Food and Logistics Company
Ransom & Dark Web Issues Week 4, July 2026
-
ASEC BLOG
-
June 2026 Security Issues in Korean & Global Financial Sector
Statistics on Malware Distributed to the Financial Sector In the June threat analysis for the financial sector, phishing was the most prevalent attack method in Attack Stage 1, while droppers/downloaders (distribution tools that download additional malware) were the most prevalent in Attack Stage 2. Infostealers were identified in the third attack stage, indicating that multi-stage […]
June 2026 Security Issues in Korean & Global Financial Sector
-
ASEC BLOG
-
Ransom & Dark Web Issues Week 4, June 2026
ASEC Blog publishes Ransom & Dark Web Issues Week 4, June 2026 BreachForums, a cybercrime forum, showing signs of admitting to sales and impersonation of its staff Lapsus$ claims to have leaked data from a bank in Myanmar Qilin launches a ransomware attack targeting a law firm in South Korea
Ransom & Dark Web Issues Week 4, June 2026
-
ASEC BLOG
-
May 2026 Threat Trend Report on Ransomware
Purpose and Scope This report summarizes the quantity of new ransomware samples collected during the month of May 2026, the number of affected systems, statistics on targeted businesses, and major Korean & Global ransomware issues. Statistics on samples and affected systems are based on AhnLab’s detection names, while statistics on targeted businesses are aggregated based […]
May 2026 Threat Trend Report on Ransomware
-
ASEC BLOG
-
Ransom & Dark Web Issues Week 3, June 2026
ASEC Blog publishes Ransom & Dark Web Issues Week 3, June 2026 Sale of Confidencial Defense Industry Documents in South Korea on Spear Forums Ransomware Attack by Qilin Targeting a South Korean Big Data Solution Company Ransomware Attack by Anubis Targeting a South Korean Semiconductor Equipment Parts Company
Ransom & Dark Web Issues Week 3, June 2026
-
ASEC BLOG
-
Ransom & Dark Web Issues Week 1, June 2026
ASEC Blog publishes Ransom & Dark Web Issues Week 1, June 2026 Qilin Ransomware Attack Targets South Korean Automation Equipment Company New Data Extortion Group Black X Claims Leak of Internal Data from South Korean Plastic Surgery Clinic Nova Ransomware Attack Targets Department of AI at University in Daegu, South […]
Ransom & Dark Web Issues Week 1, June 2026
-
Firewall Daily – The Cyber Express

-
Ransomware Attacks Surge 30% in 2026 as Qilin and INC Ransom Intensify Operations
Ransomware attacks surged 30% in the first half of 2026 compared to the same period in 2025, with Qilin and INC Ransom emerging as two of the most prolific and dangerous operators in a crowded criminal ecosystem. Healthcare continues to be the top targeted industry, with 27 incidents in January 2026 alone, a figure that reflects both the sector's operational sensitivity and the premium value of health records on darknet markets. Qilin: The Dominant Force Qilin — also known as Agenda — is a ran
Ransomware Attacks Surge 30% in 2026 as Qilin and INC Ransom Intensify Operations
![]()
Qilin: The Dominant Force
Qilin — also known as Agenda — is a ransomware group that entered 2026 accelerating, not slowing down. By early 2026, Qilin had already posted 55 confirmed victims, placing it ahead of its own 2025 pace. By June 2026, tracking data, Qilin had accumulated 168 confirmed victims in the healthcare sector alone, behind only manufacturing (291) and business services (245) in overall victim count. Qilin operates as a Ransomware-as-a-Service (RaaS) platform, recruiting affiliates who conduct attacks using Qilin's ransomware builder and infrastructure in exchange for a percentage of ransom proceeds. This model allows the core group to expand operational throughput without directly executing every attack. The group's double extortion model — encrypting victim data while simultaneously exfiltrating it and threatening public release on their leak site — has proven effective at pressuring victims into paying ransom demands even when robust backups exist. Public exposure of sensitive patient records creates regulatory, legal, and reputational pressure that many healthcare organisations find more immediately damaging than operational downtime. A notable recent case involves Covenant Health, which suffered a Qilin ransomware breach that exposed 478,188 patient records. The Covenant Health incident highlights Qilin's willingness to attack hospitals and health systems regardless of the direct patient safety implications.INC Ransom: Targeting Critical Sectors
INC Ransom is another highly active operator that was among the top ransomware groups by victim count in January 2026, with 47 known attacks that month. The group targets organisations across multiple sectors, including healthcare, legal services, and public administration. INC Ransom gained significant attention in 2025 for its attack on NHS Scotland, which exposed 3 terabytes of patient data. The group continues to operate aggressively in 2026, targeting entities including healthcare practices, municipal agencies, and regional service providers. Recent INC Ransom victims include healthcare organisations such as Lymphedema Therapy Specialists, Inc. (February 2026, affecting 378 Texas patients) and various municipal and public sector entities, including Champaign-Urbana Public Health District.The 2026 Ransomware Landscape
Beyond Qilin and INC Ransom, the broader 2026 ransomware ecosystem is characterised by:- AI-assisted operations: Multiple ransomware groups are now using AI tools to accelerate phishing campaign creation, target research, and initial access operations, reducing the operational cost of launching attacks.
- Healthcare as a premium target: Patient records sell for up to 10 times as much as financial records on darknet markets, making it a persistently attractive target. Operational disruption of healthcare services also creates patient-safety leverage that can pressure organisations to make faster payment decisions.
- The Play and SafePay operators were also confirmed in recent June 2026 attack disclosures, targeting organisations including Clínica Maitenes and various regional businesses.
Why It Matters
The 30% year-over-year increase in ransomware incidents confirms that neither law enforcement action nor improved defensive capabilities has materially reduced the operational tempo of ransomware criminal enterprises. The professionalisation of RaaS platforms, combined with AI-assisted tooling and shortened attack timelines, is creating conditions in which even well-defended organisations face materially elevated risk. For healthcare specifically, the combination of operational sensitivity, high data value, and historically underfunded security programmes creates a structural vulnerability that the industry has not yet resolved despite years of high-profile attacks.-
ASEC BLOG
-
April 2026 Security Issues in Korean & Global Financial Sector
Statistics on Malware Distributed to the Financial Sector attack Stage 1 Phishing, Attack Stage 2 Backdoor-Downloader-Dropper, and Attack Stage 3 Infostealer-Ransomware were identified as the top malware in the financial sector. The actual distribution files were identified based on MD5 Hash, and it was explained that there may be many variants of the same family. […]
April 2026 Security Issues in Korean & Global Financial Sector
-
ASEC BLOG
-
March 2026 Ransomware Trends Report
Purpose and Scope. this report summarizes the number of ransomware samples, number of affected systems, DLS-based statistics, and major Korean & Global ransomware issues identified during the month of March 2026. Key statistics. ransomware sample counts and victimized systems statistics were aggregated by detection name assigned by AhnLab. statistics on targeted businesses were calculated based […]
March 2026 Ransomware Trends Report
-
@BushidoToken Threat Intel

-
Ransomware Tool Matrix Project Updates: May 2025
IntroductionThis blog is a summary and analysis of recent additions to the Ransomware Tool Matrix (RTM) as well as the Ransomware Vulnerability Matrix (RVM). Feedback from the infosec community about these projects has been overwhelmingly positive and many researchers have contacted me to tell me how helpful they have found these to be. It makes me happy to hear how doing something in my spare time can help stop ransomware attacks and cybercriminals from exploiting our society’s systems. And it
Ransomware Tool Matrix Project Updates: May 2025
Introduction
This blog is a summary and analysis of recent additions to the Ransomware Tool Matrix (RTM) as well as the Ransomware Vulnerability Matrix (RVM). Feedback from the infosec community about these projects has been overwhelmingly positive and many researchers have contacted me to tell me how helpful they have found these to be. It makes me happy to hear how doing something in my spare time can help stop ransomware attacks and cybercriminals from exploiting our society’s systems. And it is for that reason, I shall continue to maintain these projects as long as ransomware is still around. For anyone new to these projects, please read the descriptions on GitHub or feel free to watch my talk explaining the project at BSides London.
Background on the current ransomware ecosystem as of May 2025
Following the impact of Operation Cronos against LockBit and the exit scam by ALPHV/BlackCat, the ransomware ecosystem has been even more unstable than usual. The exit scams and law enforcement infiltration operations have created a zero trust environment for the cybercriminals participating in the ransomware economy. The days of affiliates putting their faith in one RaaS platform seem to be long gone and many are experimenting and going from one RaaS to the next.
Sources of Threat Intelligence for the RTM
The RTM was updated with OSINT reports shared by cybersecurity researchers at various private service providers or vendors. The thing to remember about these reports is that the tool usage is going to be slightly outdated due to the time it takes incident response teams to wrap up an investigation, compile findings, and publish a report.
From the reports, threat groups such as Qilin, BlackSuit, RansomEXX, Medusa, BianLian, Hunters International and PLAY have been active for over one year or for multiple years. These are established groups. Since RansomHub and LockBit have shut down, it is more likely than not that the affiliates have already shifted to one of the other RaaS platforms, like Qilin, among others.
There has also been a number of ransomware operations suspected to be linked to Chinese cyber-espionage groups, such as RA World (for using PlugX), NailaoLocker (for using ShadowPad and PlugX), and CrazyHunter (for its focus on Taiwan).
Threat groups such as IMN Crew, QWCrypt (linked to RedCurl), NightSpire, SuperBlack, and Helldown are all rising threat groups that have more recently begun their ransomware campaigns.
These factors have led to seeing a large variety of tool usage in ransomware operations being observed across the landscape. The reliance on tools from sites like GitHub and other free software sites, however, continues to remain a constant theme among all of these ransomware operations.
List of sources used for the May 2025 major update to the RTM:
|
Group Name |
Report Publish Date |
URL |
|
Qilin |
25 April 2025 10 March 2025 |
|
|
IMN Crew |
24 April 2025 |
|
|
CrazyHunter |
16 April 2025 |
|
|
RansomEXX |
8 April 2025 |
|
|
BlackSuit |
31 March 2025 |
|
|
QWCrypt |
26 March 2025 |
|
|
RansomHub |
26 March 2025 20 March 2025 |
|
|
Medusa |
26 March 2025 6 March 2025 |
|
|
BianLian |
26 March 2025 |
|
|
PLAY |
26 March 2025 |
|
|
NightSpire |
25 March 2025 |
|
|
Hunters International |
19 March 2025 |
|
|
SuperBlack |
13 March 2025 |
|
|
LockBit |
24 February 2025 |
|
|
NailaoLocker |
20 February 2025 18 February 2025 |
|
|
RA World |
13 February 2025 22 July 2024 |
|
|
Helldown |
7 November 2024 |
Tools Used by Multiple Groups
- EDRSandBlast and WKTools are relatively new tools that are being used by multiple groups to deactivate and overcome EDR tools that many victims will have on their networks to prevent ransomware attacks.
- Typical ransomware tools, such as PsExec, Mimikatz, and Rclone remain effective and still used by multiple ransomware gangs for the foreseeable future.
|
Tool |
Type |
Groups Using It |
|
WinSCP |
Exfiltration |
NightSpire Hunters International |
|
Mimikatz |
Credential Theft |
RansomHub Qilin Helldown |
|
Impacket |
Offensive Security Tool |
RansomHub RA World NailaoLocker |
|
Rclone |
Exfiltration |
RansomHub Hunters International Medusa |
|
NetScan |
Discovery |
RansomHub Medusa |
|
WKTools |
Discovery |
RansomHub BianLian PLAY |
|
Advanced IP Scanner |
Discovery |
Hunters International BianLian |
|
Advanced Port Scanner |
Discovery |
Hunters International Helldown |
|
AnyDesk |
RMM Tool |
Medusa BianLian |
|
EDRSandBlast |
Defense Evasion |
Medusa Qilin |
New Tools Added to the RTM
- The most notable new tools added to RTM include several defense evasion tools for deactivating EDRs, discovery for sensitive files, and tunnelling tools to conceal adversary network connections.
|
Tool |
Type |
Groups Usage |
|
Bublup |
Exfiltration |
BlackSuit |
|
WKTools |
Discovery |
BianLian, PLAY |
|
AmmyyAdmin |
RMM Tool |
BianLian |
|
CQHashDump |
Credential Theft |
NailaoLocker |
|
Throttle Stop Driver |
Defense Evasion |
Medusa |
|
KillAV |
Defense Evasion |
Medusa |
|
BadRentdrv2 |
Defense Evasion |
RansomHub |
|
Toshiba Power Driver (BYOVD) |
Defense Evasion |
Qilin |
|
ZammoCide |
Defense Evasion |
CrazyHunter |
|
FRP |
Networking |
Medusa |
|
Stowaway |
Networking |
RansomHub |
|
Navicat |
Discovery |
Medusa |
|
Everything.exe |
Discovery |
NighSpire |
|
RoboCopy |
Discovery |
Medusa |
|
NPS |
Networking |
RA World |
|
SharpGPOAbuse |
Offensive Security Tool |
CrazyHunter |
|
Attrib |
LOLBAS |
BlackSuit |
|
Curl |
LOLBAS |
QWCrypt (RedCurl) |
|
PCA Utility (pcalua) |
LOLBAS |
QWCrypt (RedCurl) |
Exploits used by Ransomware Gangs added to the RVM
- As is now usual, multiple ransomware groups have been targeting Fortinet networking devices for initial access into to victim environments.
- Multiple ransomware groups continue to exploit the Windows Common Log File System (CLFS) for local privilege escalation to run hacking tools and steal credentials.
- Other exploits involve targeting edge devices, such as Check Point VPNs or PAN Firewalls, or exposed servers, such as Atlassian Confluence Data Center Servers.
- The targeting of Veeam backup software should come as no surprise as preventing backups or stealing sensitive files, such as Active Directory backups, are key objectives of ransomware gangs to complete their mission.
|
Ransomware Group |
Exploited CVEs |
|
NightSpire |
CVE-2024-55591 (FortiOS) |
|
RansomHub |
CVE-2022-24521 (Windows CLFS) |
|
LockBit |
CVE-2023-22527 (Confluence) |
|
Hunters International |
CVE-2024-55591 (FortiProxy) |
|
SuperBlack |
CVE-2024-55591 (FortiProxy) |
|
RA World |
CVE-2024-0012 (PAN-OS) |
|
NailaoLocker |
CVE-2024-24919 (Check Point VPN) |
|
RansomEXX |
CVE-2025-29824 (Windows CLFS) |
Conclusion
My recommendation for defenders who continue the fight against ransomware is to take some of the findings from this report and begin threat hunting, detection rule writing, and start blocking some of these tools not present in the environments you are protecting.
Here are a few sites to help you get started with: