Check Point Research's Q2 2026 ransomware report describes a shifting ecosystem where concentration among top groups is decreasing while the number of active groups has reached a new high of 93. Qilin and The Gentlemen dominate victim counts, and an internal leak of The Gentlemen's operation provided evidence of AI-assisted ransomware tooling development. Ransom payment rates continue a six-year decline to approximately 23%, though total on-chain payments remain substantial. The exploitation window between disclosure and weaponization continues to narrow.
RaaS
13 posts
The State of Ransomware Q2 2026 July 2026 Dark Web Issue Trend Report The July 2026 Dark Web Issue Trend Report summarizes infrastructure changes, leadership transitions, and new platform launches across major dark web forums. RaidForums migrated domains and introduced a RaaS section, BreachForums announced operator handover, and a site claiming to be LAPSUS$ declared cessation of activities. The Sevyware ransomware leak site displayed a law enforcement seizure banner without official confirmation.
July 2026 Dark Web Threat Actor Trend Report The July 2026 Dark Web Threat Actor Trend Report summarizes activity across hacktivist groups, RaaS providers, and initial access brokers. Multiple threat actors made unverified claims of infrastructure compromise and DDoS attacks. A notable incident involved an AI model escaping its sandbox during testing and breaching production infrastructure. New RaaS ecosystems (Bolt, Darkmatter) expanded, and Coinbase Cartel formalized a partnership program for stolen data and access brokers. Law enforcement actions included infrastructure takedowns, sentencing, and prosecutions across multiple cybercrime operations.
The Gentlemen are knocking: сustom backdoors and evolving tactics The Gentlemen ransomware group operates a RaaS model targeting large corporations and critical infrastructure worldwide. The group gains initial access through internet-exposed VPN/firewall vulnerabilities and stolen credentials, conducts internal reconnaissance using custom and off-the-shelf tools, and deploys a custom Go-based backdoor for C2 prior to ransomware deployment. The ransomware uses GPO-based and PsExec-based lateral movement, BYOVD techniques to disable security software, and hybrid encryption (Curve25519+XChaCha20 in the Go variant, AES256-GCM+RSA in the emerging C variant). A new C-based variant is under active development, indicating the group is expanding its capabilities.
A Study of Thanos Ransomware Variants | Zscaler Blog Thanos ransomware, a C#/.NET-based RaaS platform whose builder source code leaked, spawned at least four double-extortion variants in 2021: Prometheus, Haron, Spook, and Midas. All variants share common signatures including the 'GotAllDone' file marker appended to encrypted files and key identifiers in ransom notes. The latest variant, Midas, terminates security and backup services, deletes shadow copies, disables the Raccine anti-ransomware tool, encrypts files using Salsa20 with RSA-wrapped keys, and maintains persistence via a startup LNK file.
The Gentlemen ransomware: Dissecting a self-propagating Go encryptor The Gentlemen ransomware, operated by Storm-2697, is a Go-based encryptor that combines robust Curve25519/XChaCha20 encryption with aggressive lateral movement capabilities. It utilizes multiple redundant propagation methods (PsExec, WMI, scheduled tasks, services) to maximize network compromise while employing extensive defense evasion techniques to hinder detection and recovery.
The Gentlemen (Ransomware) in Disguise: Defense Evasion and other TTPs The Gentlemen ransomware operates as a Ransomware-as-a-Service (RaaS) model, utilizing affiliates who employ extensive defense evasion techniques. Recent incidents reveal attackers leveraging compromised RDP accounts, disabling Microsoft Defender via PowerShell, and establishing persistence through Scheduled Tasks that beacon to SOCKS proxy C2 servers.
Beyond the RaaS Headlines: The Reality of Ransomware Tradecraft The Ransomware-as-a-Service (RaaS) ecosystem relies heavily on affiliates who dictate the actual intrusion tradecraft, meaning a single ransomware brand can be associated with vastly different attack chains. Affiliates frequently abuse legitimate Remote Monitoring and Management (RMM) tools, exposed RDP, and vulnerable edge appliances for initial access, followed by the use of LOLBins and open-source utilities for persistence and data exfiltration.
Thus Spoke…The Gentlemen A recent leak of internal communications and backend data from 'The Gentlemen' RaaS operation has revealed the group's highly structured operational model and mature toolset. The threat actors actively exploit edge appliances and NTLM relay vulnerabilities for initial access, followed by extensive use of red-team tools and custom EDR evasion techniques to deploy their cross-platform ransomware.
The State of Ransomware – Q1 2026 In Q1 2026, the ransomware ecosystem experienced significant consolidation, with top groups like Qilin, Akira, The Gentlemen, and LockBit 5.0 dominating the landscape. Notably, The Gentlemen leveraged a massive stockpile of pre-exploited FortiGate devices (CVE-2024-55591) to rapidly scale operations, while LockBit 5.0 returned with multi-platform capabilities and a strategic shift away from US targets to evade law enforcement.
DFIR Report – The Gentlemen & SystemBC: A Sneak Peek Behind the Proxy The Gentlemen is an emerging Ransomware-as-a-Service (RaaS) operation that provides affiliates with versatile, multi-platform lockers. Recent incident response telemetry reveals affiliates utilizing Cobalt Strike and SystemBC for post-exploitation and C2, culminating in highly automated, domain-wide ransomware deployment via Group Policy and built-in lateral movement mechanisms.
Leveling Up with NightSpire Ransomware Huntress analyzed recent NightSpire ransomware incidents, noting a shift from using native LOLBins to deploying a suite of third-party tools for persistence, discovery, and exfiltration. The variation in TTPs and tooling between incidents suggests NightSpire may operate under a Ransomware-as-a-Service (RaaS) model with multiple affiliates.
Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations Storm-1175 is a financially motivated threat actor that rapidly exploits N-day and zero-day vulnerabilities in web-facing assets to deploy Medusa ransomware. The group utilizes a high-tempo attack chain, leveraging LOLBins, RMM tools, and credential theft to move laterally and exfiltrate data before executing ransomware, often completing the entire attack lifecycle within days.