Ransomware Attacks Surge to 2026 Peak Amid Evolving Threats
Ransomware has reached its highest activity level of the year in 2026, with July alone recording 873 claimed victims across global data leak sites—a 22% surge from the previous month. New threat groups are emerging at an unprecedented pace, extortion tactics are growing more deceptive, and the criminal ecosystem is fragmenting in ways that make attribution and defense significantly harder. The latest intelligence reports from Check Point, Microsoft Threat Intelligence, GuidePoint Research, and CYFIRMA paint a picture of a threat landscape that is not only expanding but also maturing in its operational sophistication.
A Fragmenting Ransomware Ecosystem
According to Check Point’s State of Ransomware Q2 2026 report, 2,139 organizations were publicly listed on data leak sites during the second quarter. While that number alone is alarming, what stands out is the shift in group concentration. The top 10 ransomware groups now account for only 57.6% of claimed victims, down from 71% the previous quarter. The number of active groups has jumped from 71 to 93 in the same timeframe.
This fragmentation signals a meaningful change. The era dominated by a handful of well-known ransomware-as-a-service (RaaS) operations is giving way to a broader field of smaller, agile groups. New names such as Tengu, CRPx0, Majinahanashi, Elite Enterprise, Aur0ra, Lalia, QV Ransomware, and Orova have surfaced in recent months. Each brings its own tactics, target preferences, and technical innovations.
For defenders, fragmentation is a double-edged sword. On one hand, smaller groups may lack the resources and reach of legacy operations. On the other, a wider variety of actors means more intrusion vectors, more malware variants, and a greater challenge for threat intelligence teams attempting to track and attribute attacks.
The Ransom Busters Deception
One of the most striking developments uncovered this August is the emergence of a threat actor calling itself Ransom Busters. According to GuidePoint Research and Intelligence Team (GRIT), this affiliate has been proactively emailing ransomware victims and offering to delete stolen data from ransomware group servers in exchange for fees ranging from $20,000 to $60,000.
While the offer might initially sound like a lifeline to a desperate organization, GuidePoint’s analysis reveals a more sinister reality. Ransom Busters is believed to be a ransomware affiliate working across multiple RaaS operations, including DragonForce, Settra, and Anubis. The group claims to have found vulnerabilities in administrative panels maintained by RaaS groups and to have been breaching their servers for over three years.
In practice, this is a secondary extortion scheme. The affiliate exploits its own access to criminal infrastructure to identify victims, then contacts those victims directly to extract additional payments under the guise of a rescue service. GuidePoint’s investigation uncovered striking similarities across incidents, including the use of SoftPerfect Network Scanner for internal reconnaissance, s5cmd for exfiltrating data to AWS cloud storage, and the Remotely RMM tool deployed via PowerShell scripts. A shared backdoor account password and an identical attacker-controlled hostname across separate intrusions point to a single operator behind the persona.
The lesson for organizations is clear: criminal actors cannot be trusted, even when they claim to be on your side. Payment to any criminal party offers no guarantee that stolen data will be deleted or that further extortion will not follow.
UNC6671 and the Industrialization of Credential Theft
Beyond traditional ransomware deployments, GuidePoint also disclosed a sustained adversary-in-the-middle (AitM) operation orchestrated by a group tracked as UNC6671, also known as Cordial Spider. Since April, this group has targeted financial services, legal, and other high-value industries under at least five separate extortion brands: Falcon, Helix, Pink, Redact, and BlackFile.
More than $8 million in payments have been traced across 15 Bitcoin wallets attributed to these brands, with an average extortion demand of $600,000. The group has been identified as targeting 76 distinct organizations across 15 industry sectors, with 40% of victims concentrated in hedge funds, venture capital, private equity, and asset management firms.
What sets UNC6671 apart is its operational maturity. According to Okta, the group operates a custom console called Work Panel that enables role-based access control, integrated target reconnaissance via commercial B2B data APIs, automated infrastructure provisioning, and real-time credential relay management. The phishing templates impersonate identity providers like Okta and Microsoft 365, making them highly convincing.
The organizational design is equally notable. Callers are recruited through underground channels, paid per successful credential capture, and deliberately prevented from accessing the product of their own work. Managers see only the live session queue, while administrators own the infrastructure. This separation of duties is a deliberate design decision to solve the insider risk problem inherent in running criminal operations with hired labor.
DeadLock: Ransomware with Decentralized Infrastructure
Microsoft Threat Intelligence has published a detailed technical analysis of DeadLock, an emerging ransomware operation that leverages decentralized infrastructure for victim communications and data leak operations. First observed in July 2025, DeadLock had published over 80 compromised organizations on its data leak site by July 2026, with more than half of claimed victims located in Europe.
DeadLock’s recovery ecosystem is particularly noteworthy. It combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process. This decentralized architecture increases the resilience of communication, leak-hosting, and negotiation infrastructure, allowing operators to recover from some disruption efforts while maintaining continuity for victims.
The DeadLock encryptor, written in Rust, includes a resource-aware throttling mechanism designed to maintain system responsiveness during encryption, reducing the likelihood of detection. It also implements language-based geofencing, self-terminating in environments associated with former Soviet and CIS countries. Microsoft has observed DeadLock being deployed by affiliates of the Lynx and INC ransomware ecosystems, demonstrating the cross-pollination of tools and techniques across groups.
How Ransomware Groups Are Evolving Their Playbooks
Several trends emerge from the latest intelligence that organizations should understand:
- Pre-positioned access operations: Groups are prioritizing credential harvesting, reconnaissance, privilege escalation, and environment preparation before encryption, maximizing operational success.
- Abuse of trusted infrastructure: Ransomware actors increasingly use collaboration platforms, legitimate cloud services, signed binaries, and remote administration tools to blend malicious activity with normal enterprise operations.
- Double and triple extortion: Beyond encrypting files, groups steal data and threaten public release. Some, like Ransom Busters, add a third layer by offering fraudulent recovery services.
- Decentralized infrastructure: Groups like DeadLock use blockchain-backed services and encrypted messaging to make takedown and disruption significantly harder for law enforcement.
- Industrialized credential theft: Operations like UNC6671’s Work Panel demonstrate criminal groups are building full platforms with role-based access, automation, and commodity labor models.
Practical Defense Strategies for Organizations
Given the escalating and diversifying threat, organizations must adopt a layered defense posture. The following measures are critical:
Strengthen Identity and Access Management
Most ransomware intrusions begin with compromised credentials. Implement phishing-resistant multi-factor authentication across all external access points. Regularly audit privileged accounts and enforce least-privilege principles. Monitor for anomalous authentication patterns, particularly from adversary-in-the-middle phishing infrastructure.
Maintain Immutable Backups
Backup strategies must account for the reality that ransomware actors actively seek out and destroy backup infrastructure. Maintain offline or immutable backups that cannot be modified or deleted by compromised accounts. Test restoration procedures regularly to ensure they work under pressure.
Deploy Endpoint Detection and Response
Modern ransomware encryptors use defense evasion techniques, process injection, and privilege escalation. Endpoint detection and response (EDR) solutions can identify these behaviors before encryption begins. Focus on detecting lateral movement, suspicious PowerShell execution, and unauthorized RMM tool deployment.
Monitor for Data Exfiltration
Since double extortion is now the norm, preventing data exfiltration is as important as preventing encryption. Deploy data loss prevention tools and monitor outbound traffic for large or unusual transfers, particularly to cloud storage services.
Develop and Rehearse an Incident Response Plan
Organizations that have a well-rehearsed incident response plan recover faster and at lower cost. The plan should include communication protocols, legal counsel coordination, law enforcement notification procedures, and a clear decision framework for whether to engage negotiators or pay ransoms—though payment is never recommended and offers no guarantees.
The Road Ahead
The ransomware landscape of 2026 is defined by fragmentation, deception, and technical sophistication. With 93 active groups, record victim counts, and new tactics like fraudulent recovery services and decentralized extortion infrastructure, the threat shows no sign of abating. The most active groups in July—The Gentlemen (138 victims), Qilin (133), and CRPx0 (46)—demonstrate that even as the ecosystem fragments, certain actors maintain outsized influence.
For organizations, the message is unambiguous. Ransomware is no longer a question of if but when. The difference between a manageable incident and a catastrophic one comes down to preparation. Strengthening identity security, maintaining tested backups, deploying modern detection capabilities, and rehearsing incident response are no longer optional. In a landscape where even the criminals’ own affiliates are scamming their victims, trusting no one and preparing for everything is the only rational strategy.
Edited by Palawan @QUE.COM
Website: https://QUE.COM Intelligence
Sponsored by: https://MAJ.COM AI Autonomous
Discover more from QUE.com
Subscribe to get the latest posts sent to your email.
