Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationactively-exploited-vulnerabilityrapid-weaponizationdata-exfiltration-method

Industry reporting highlights ransomware shift to stealthy, long-dwell intrusions and increased zero-day exploitation

Updated 3mo agoFirst seen Feb 27, 20262 sources

Multiple security reports and commentary describe ransomware operators shifting from fast “smash-and-grab” encryption to stealthier campaigns that prioritize long-term access, data theft, and operational leverage. VulnCheck’s 2026 exploit intelligence findings indicate that while only a small fraction of newly disclosed vulnerabilities are exploited in the wild, the exploited set drives outsized impact; the report also assesses that ransomware-linked vulnerability exploitation is increasingly zero-day-led, with over half of ransomware-associated CVEs first identified via active exploitation. The same analysis notes rapid weaponization dynamics (including growth in public PoCs and noisy, low-quality AI-generated exploit code) that can distort prioritization while attackers move faster than patch cycles—an issue that is particularly consequential for OT environments where downtime and patch latency are common.

Several other items in the set are not reporting on this specific ransomware/zero-day trend and instead provide general security guidance or leadership content. These include broad, non-incident overviews of financial-sector threats, dark web monitoring decision-making, AI skills discussions, board-level risk/metrics perspectives, and DDoS readiness best practices; they do not add concrete, corroborating detail to the ransomware zero-day/long-dwell access narrative beyond general context that cybercrime is evolving and defenders should focus on actionable risk signals.

Share:
Industry reporting highlights ransomware shift to stealthy, long-dwell intrusions and increased zero-day exploitation
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Feb 27, 20264mo ago

CSO Online highlights shift toward stealthier ransomware intrusions

By February 27, 2026, CSO Online highlighted analysis that ransomware groups were moving away from immediate, noisy attacks toward stealthier intrusions and maintaining long-term access in victim environments. The item reflected an industry-observed evolution in ransomware tradecraft rather than a single incident.

Feb 26, 20264mo ago

VulnCheck publishes 2026 exploit intelligence report

On or before February 26, 2026, VulnCheck released its 2026 exploit intelligence report, stating that more than 48,000 CVEs were disclosed in 2025 but only about 1% were exploited in the wild. The report also noted a 16.5% increase in proof-of-concept availability, a 52% year-over-year rise in China-nexus attributions, and warned that ransomware groups were increasingly relying on zero-days, raising risk for OT environments.

Jan 31, 20265mo ago

VulnCheck says one-third of known 2025 ransomware CVEs lacked public exploits

As of January 2026, VulnCheck found that roughly one-third of known 2025 CVEs associated with ransomware still had no public or commercial exploit available. The finding suggested many ransomware exploit chains remained private despite active criminal use.

Dec 31, 20256mo ago

VulnCheck links 39 newly disclosed 2025 CVEs to ransomware activity

During 2025, VulnCheck identified 39 newly disclosed CVEs tied to ransomware operations across at least 17 ransomware families. The report said 56.4% of ransomware-linked 2025 CVEs were first discovered through evidence of active exploitation, indicating increased zero-day use by ransomware actors.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

55 LINKEDOpen in app
Affected products
12 linked
FtaSysaidWeblogic ServerE-Business SuiteMoveit TransferFortiosEsxiServ-UConnect SecureServ-UMoveit TransferLog4j
Organizations
19 linked
AT&TCisco SystemsRapid7GladinetProgress SoftwareAccellionSolarWindsCleoFortinetBroadcomMicrosoft CorporationOracleThe Coca-Cola CompanyVulnCheckSimpleHelpBaiduFortraSysaidYakult Honsha Co., Ltd.
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Industry reporting highlights ransomware shift to stealthy, long-dwell intrusions and increased zero-day exploitation | Mallory