Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationcybercrime-service-ecosystemhealthcare-sector-threatinitial-access-method

Ransomware Activity and Related Threat Intelligence Updates

Updated 1mo agoFirst seen Mar 4, 20265 sources

Reporting highlighted elevated ransomware activity and evolving access-broker ecosystems. BlackFog’s February ransomware roundup counted 82 publicly disclosed ransomware incidents across 20 countries, with the U.S. most affected (51 incidents) and healthcare the most targeted sector (31%). The report attributed publicly claimed attacks to 24 ransomware groups, led by Shiny Hunters (8) and Qilin (6), while noting 41% of incidents were not yet attributed; it also cited individual victim disclosures/claims involving Nova Biomedical (PII exposure affecting 10,764 people), Hosokawa Micron (files accessed; Everest claimed ~30GB theft), and Iron Mountain (Everest claim of 1.4TB theft, while Iron Mountain stated access was limited to a single marketing folder via a compromised credential).

Separately, Huntress described how investigation of a “routine” RDP brute-force success led to discovery of credential-hunting behavior and geo-distributed infrastructure consistent with a ransomware-as-a-service ecosystem and associated initial access activity, illustrating how exposed remote access can connect to broader ransomware operations. Arctic Wolf warned of heightened cyber risk following the February 2026 U.S./Israel-Iran escalation (Operation Epic Fury), advising increased vigilance—especially for sectors historically targeted by Iranian-linked actors (e.g., energy, defense, transportation, healthcare, government)—and anticipating potential wiper activity, DDoS, targeted intrusions, supply-chain risk, and possible collaboration with ransomware-affiliate activity amid geopolitical retaliation dynamics.

Share:
Ransomware Activity and Related Threat Intelligence Updates
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
May 11, 20261mo ago

AhnLab publishes April 2026 ransomware trends report

AhnLab’s ASEC released an April 2026 ransomware report summarizing activity observed via ransomware leak sites and damaged-system counts. The report said attacks continued across industries worldwide, highlighted critical infrastructure sectors such as manufacturing, healthcare, and finance, and noted activity from groups including Qilin, DragonForce, and INC Ransom alongside emerging threats.

April 2026 Threat Trend Report on Ransomware - ASEC
May 8, 20262mo ago

ESRC publishes Q1 2026 ransomware trends report

ESRC released a first-quarter 2026 ransomware report stating that 73 groups were responsible for 2,565 confirmed incidents globally and that South Korea recorded 17 cases, about double the year-earlier period. The report identified Qilin as the most active group, said healthcare was the most targeted sector, and highlighted incidents affecting Covenant Health and Stryker as examples of ransomware-driven disruption.

2026년 1분기 랜섬웨어 동향보고서
Apr 12, 20262mo ago

AhnLab publishes March 2026 ransomware trends report

AhnLab’s ASEC released a March 2026 ransomware report describing continued attacks across critical sectors including manufacturing, healthcare, and finance, with activity from groups such as Qilin, The Gentlemen, and INC Ransom. The report also said ransomware operators increasingly combined encryption with exposure and blackmail via dedicated leak sites and warned that post-December 2025 victim statistics use a changed aggregation methodology.

March 2026 Ransomware Trends Report - ASEC
Mar 4, 20264mo ago

Huntress maps infrastructure tied to ransomware-access operations

Using pivots from the brute-force source IP, TLS certificate analysis, and related domains such as specialsseason[.]com and 1vpns[.]com, Huntress identified a wider geo-distributed infrastructure network. Third-party references linked one observed IP to Hive ransomware and BlackSuite, leading Huntress to assess the activity as connected to a ransomware-as-a-service ecosystem and/or initial access broker operations.

Victim network isolated after malicious enumeration is confirmed

After confirming post-compromise malicious activity, Huntress contained the incident by isolating the affected environment across the network. The response stopped the intrusion before the investigation expanded to the attacker’s broader infrastructure.

Huntress investigates brute-force compromise of exposed RDP server

Huntress Tactical Response Team responded to what appeared to be routine brute-force activity against an internet-exposed RDP server and confirmed a successful compromise of a single account. The intruder then performed domain enumeration and manually searched for password-related files using Notepad rather than relying mainly on common credential-dumping techniques.

Feb 28, 20264mo ago

Victim organizations dispute some February extortion claims

BlackFog reported several disputed cases in February 2026 where threat actors claimed large-scale exfiltration but victims said impact was limited or that they found no evidence of compromise. Examples cited included Iron Mountain, HP/Poly, Epworth HealthCare, Atlas Air, and Safran Group.

February attacks cause broad data theft and operational disruption

BlackFog highlighted that February ransomware incidents affected sectors including healthcare, education, transportation, finance, hospitality, government, and critical infrastructure. Reported impacts included theft of personally identifiable information, protected health information, financial records, and operational disruption at organizations such as BridgePay, Conpet, Sapienza University of Rome, and the University of Mississippi Medical Center.

BlackFog identifies leading ransomware groups active in February

BlackFog said 24 ransomware groups were linked to publicly claimed attacks during February 2026, led by ShinyHunters with eight incidents and Qilin with six. It also noted that 41% of attacks remained unattributed.

February 2026 records 82 publicly disclosed ransomware incidents

BlackFog reported that February 2026 saw 82 publicly disclosed ransomware and cyber extortion incidents across 20 countries. Healthcare was the most targeted sector, and the United States accounted for 51 of the reported incidents.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

25 LINKEDOpen in app
Malware
1 linked
Affected products
3 linked
WindowsAmazon Web ServicesRemote Desktop Protocol (Rdp)
Organizations
8 linked
AhnlabAmazon Web ServicesStrykerMicrosoft CorporationHuntressESTsecurityCovenant HealthKyowon Group
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.