Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-05-25
Ransomware·2026-05-25

Ransomware Watch · May 25, 2026

Time window: 2026-05-24 → 2026-05-25
Data sources: WebSearch aggregation (cyberthreatintelligence.net, purple-ops.io and other public trackers) + DFIR Report reporting
⚠️ Note: direct RansomLook API pulls failed again due to egress restrictions (HTTP 403 from proxy); this issue is aggregated second-hand data.

Overview

  • New posts (24h aggregate): ~40
  • Active DLS sites: 91 (flat vs. yesterday)
  • Groups involved: 8+ (Genesis / Qilin / Akira / CoinbaseCartel / Lamashtu / The Gentlemen affiliates / Inc Ransom / Sinobi, etc.)
  • Watchlist hits: not explicitly tagged per victim in the public aggregate data — a rough keyword screen against the watchlist yields ~3–5 (education, energy, healthcare)

Watchlist Hits (inferred from aggregate signals; to be verified once RansomLook is back)

GroupInferred sectorGeoHitNote
QilinHealthcare-adjacentUS/EUsector:healthcare, sector:medicalQilin (= M-Trends AGENDA) keeps focusing on healthcare / backup destruction
AkiraManufacturingEU/USsector:manufacturingAkira (= M-Trends REDBIKE) continues to produce manufacturing victims
The Gentlemen affiliatesMixed incl. educationglobalkw:double extortionThe 5/22 DFIR Report shows affiliates still deploying via GPO

All New Posts (aggregate view)

GroupNew (24h)Note
Genesis7Single-day activity high; watch whether this is a newly emerged / returning group
Qilin5Still #1 in cumulative victims this year (1,733)
Akira5Close behind Qilin at a cumulative 1,299
CoinbaseCartel4Recently rising group
Lamashtu4Second tier, steady output
Inc Ransom2–3Second tier
Play2–3Cumulative total 885
Sinobi / Dragonforce / Nightspire1–2 eachSecond tier
The Gentlemen affiliates1–2Still posting after the 5/5 internal leak
Other / low-frequencybalance—

The per-victim table is unavailable this issue (data-source problems); it will be backfilled tomorrow once RansomLook recovers.


Anomalies / Trend Notes

This week's most active (DLS post volume)

  • Qilin / Akira— the "duopoly" pattern in place since Q1 continues; M-Trends 2026 (published by Mandiant on 5/22) confirms both prioritize backup infrastructure + identity systems("recovery denial") as targets
  • The Gentlemen affiliates— on 5/22 the DFIR Report published a complete intrusion post-mortem: ransomware payload delivered via Group Policy / GPO + SystemBC SOCKS5 proxy + RC4 C2; public IOCs are now available
  • Genesis at 7 posts in a single day— a rare high; recommend tracking 5/26–5/27 to see whether it persists

Newly appeared / returning groups

  • Genesis (sustained high on 5/24–5/25) — whether it is newly emerged or a previously underestimated existing group needs confirmation on 5/26–5/27
  • CoinbaseCartel / Lamashtu — on a continued upward trajectory

Single-day sector anomalies

  • Without a per-victim sector breakdown this issue, sector concentration cannot be computed independently
  • Historical baseline: ReliaQuest Q1 2026 data shows overall ransomware posts up +22% YoY; 40 posts in one day is upper-middle for the year but not a record

Companion threat intelligence (since 5/22)

  • M-Trends 2026: ransomware families are systematically attacking backup / identity / virtualization management planes → IR teams should audit these three layers immediately
  • The Gentlemen GPO deployment pattern→ AD monitoring should add high-priority alerts for newly created / modified GPOs accompanied by SYSVOL binary writes
  • PROMPTFLUX / PROMPTSTEAL spilling over beyond the ransomware clusters— in the coming months we may see ransomware affiliates use LLMs to generate lateral-movement scripts on the fly

References

  • Cyber Threat Intelligence — Ransomware Victims Database
  • Purple Ops — Ransomware Activity Tracker 2026
  • Purple Ops — Latest Ransomware Victims
  • CipherCue — 7,655 ransomware claims Mar 25–Mar 26
  • Check Point Research — The Gentlemen RaaS deep dive
  • Mandiant M-Trends 2026
  • SecurityBrief — ransomware posts +22% Q1 trend
← Prev
Ransomware Watch · May 24, 2026
Next →
Ransomware Watch · May 26, 2026