Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-05-24
Ransomware·2026-05-24

Ransomware Watch · May 24, 2026

Time window: 2026-05-23 → 2026-05-24 (including the tail end of late 5/22)
Data sources: RansomLook recent posts + ransomware.live + public reporting
⚠️ Note: direct RansomLook API pulls failed due to egress restrictions; this issue is assembled from second-hand sources aggregated via WebSearch and full coverage is not guaranteed.

Overview

  • New posts (known): ~20+ (limited to what is publicly searchable; actual DLS posting velocity is higher — see the Q1 ReliaQuest +22% YoY trend)
  • Groups involved: 8+ (ShinyHunters / Titan / Qilin / Akira / Inc Ransom / Play / Clop / The Gentlemen, etc.)
  • Watchlist hits: 4 (education, financial, shipping, healthcare-adjacent)

Watchlist Hits (Priority)

GroupVictimSectorGeoHitLink
Multi-groupUniversity of ValenciaEducationESsector:educationransomlook recent
Multi-groupBank Negara IndonesiaFinancialIDsector:financial, sector:bankingransomware.live
Multi-groupG. Theodor Freese GmbHShipping / MaritimeDEsector:shipping, sector:logisticsransomware.live
Multi-groupAlkaloid AD SkopjePharmaceutical (healthcare-adjacent)MKsector:medical (loose match)ransomware.live

All New Posts (aggregated)

GroupVictimSectorGeoDiscoveredLink
ShinyHuntersCharter Communications, Inc.TelecomUS2026-05-23 01:50ransomlook recent
ShinyHuntersBaker Distributing CompanyHVAC distributionUS2026-05-23 01:50ransomlook recent
Titan(9 posts, mid-sized)MixedMixed2026-05-23ransomlook recent
Multi-groupUniversity of Valencia ⭐EducationES2026-05-23 14:49ransomlook recent
Multi-groupMopas Online SupermarketRetail—2026-05-23 11:48ransomlook recent
Multi-groupMecanizados y Montajes AeronáuticosAerospace manufacturingES2026-05-23 16:52ransomlook recent
Multi-groupA-Sonic LogisticsLogistics—2026-05-22ransomware.live
Multi-groupAlkaloid AD Skopje ⭐PharmaceuticalMK2026-05-22ransomware.live
Multi-groupBank Negara Indonesia ⭐BankingID2026-05-22ransomware.live
Multi-groupConsulTICIT consulting—2026-05-22ransomware.live

Anomalies / Trend Notes

This week's most active (by DLS post volume)

  • ShinyHunters— Charter Communications is a highly conspicuous target (a major US telecom operator); ShinyHunters keeps posting on the Trinity of Chaos DLS
  • Titan— 9 posts on 5/23 alone; consistently high-frequency over the past two weeks
  • Akira / Qilin— the "duopoly" position held since Q1 continues (M-Trends 2026 tracks Akira as REDBIKE and Qilin as AGENDA)
  • The Gentlemen— despite itself being leaked on 5/5, its affiliates keep posting— corroborating that its 90/10 split retains affiliates well
  • Inc Ransom / Clop / Play / Nightspire / DragonForce / Sinobi— the second tier keeps up steady output

Newly appeared groups

  • No entirely new actor observed coming online in the 5/23–5/24 window

Unusual concentration

  • Spanish manufacturing: back-to-back Spanish victims on 5/23 (University of Valencia in education + Mecanizados y Montajes Aeronáuticos in aerospace manufacturing + Cablematic Dos Mil SLU in industrial equipment on 5/22) — worth watching; an affiliate may be working the Spanish manufacturing / education circles
  • Shipping + logistics: G. Theodor Freese GmbH (German maritime) + A-Sonic Logistics both listed on 5/22 — consistent with M-Trends 2026 on RaaS normalizing "recovery denial" (deliberately hitting backups, identity, and virtualization management planes before encrypting)

Check Point 5/22 "Thus Spoke The Gentlemen" analysis (must-read)

See the "Threat Intelligence" section of the main brief. Key points:

  • The Gentlemen's industrialized flow: victim VPN access → C2 push → EDR neutralization → encryption
  • An aggressive 90/10 split to poach affiliates
  • Roles: zeta88/hastalamuerte(admin), Kunder, qbit, JeLLy, Protagor, Bl0ck, Wick, quant, donpakto, mAst3r

Data Collection Statement

  • Direct RansomLook API pulls failed due to egress restrictions
  • Data is assembled via WebSearch from multiple second-hand sources (RansomLook public recent-page summaries, ransomware.live, media reporting)
  • Actual DLS posting velocity is higher; this table lists publicly indexable victims. Full structured data requires direct access to the RansomLook APIor the ransomware.live API
  • Remediation suggestion: add www.ransomlook.ioand api.ransomware.liveto the egress allowlist

Sources

  • RansomLook recent posts
  • Ransomware.live
  • Resecurity — ShinyHunters DLS Trinity of Chaos
  • Check Point Research — "Thus Spoke The Gentlemen"
  • KELA — Analysis of the Gentlemen internal chat leak
← Prev
Ransomware Watch · May 23, 2026
Next →
Ransomware Watch · May 25, 2026
Multi-groupG. Theodor Freese GmbH ⭐Maritime / shippingDE2026-05-22ransomware.live
Multi-groupBMJ PaperpackPackaging—2026-05-22ransomware.live
Multi-groupSemgrepDevTools / securityUS2026-05-22ransomware.live
Multi-groupCablematic Dos Mil SLUIndustrial equipmentES2026-05-22ransomware.live