Ransomware Watch · May 26, 2026
Time window: 2026-05-25 → 2026-05-26
Data sources: WebSearch aggregation (ransomware.live / breachsense.com / cyberthreatintelligence.net / sharkstriker / DFIR Report and other public tracking sources)
⚠️ Note: Direct pulls from the RansomLook API again failed this cycle due to the egress allowlist; this edition relies on aggregated second-hand data.
Overview
- New posts (24h aggregate): ~35-45
- Active DLS sites: ~91 (flat)
- Groups involved: 6+ (primarily Qilin / Akira / The Gentlemen / DragonForce(Devman) / Nova / NightSpire, plus second-tier Genesis / Inc Ransom / Sinobi / Lamashtu / Play)
- Watchlist hits: ≥ 5 by rough filtering on victim names visible in the aggregate (healthcare / education / manufacturing)
Watchlist hits (matched on known victim names)
| Group | Victim | Sector | Geo | Hit | Note |
|---|---|---|---|---|---|
| Qilin | Alpha Health Care | healthcare | (likely US) | group:qilin, sector:healthcare | Qilin continues to focus on healthcare plus backup destruction |
| Qilin | Alpert Slobin & Rubenstein | legal / financial-adjacent | US | group:qilin, sector:financial (law-firm adjacency) | Qilin continues targeting law firms |
| Akira | Buffalo Niagara Convention Center | hospitality / education-adjacent | US | group:akira, sector:education (venue partly serves education conferences) | New Akira addition inside the US |
| TheGentlemen | ACAM Systemautomation GmbH | manufacturing / industrial automation | DE | sector:manufacturing | GPO-deployment TTP persists; German industrial automation target |
| Nova | Adensa Technology / AMACCAO Group | technology / construction | global | — | Nova remains on an upward trajectory |
| NightSpire | Bresme Madrid, S.L. | (regional, sector unknown) | ES | geo:es? | Outside the watchlist geography; logged for the record only |
All new posts (aggregate view; some entries are batch deltas observed only at group level)
| Group | New count (24h estimate) | Note |
|---|---|---|
| DragonForce / Devman | 5+ | Standout single-day activity (allianceadjustment.com / xtr-global.de / saver.nl / vegfresh.com / ggroupcpas.com) |
| Qilin | 4-6 | Still first on cumulative volume; heavy healthcare/legal share this cycle |
| Akira | 3-5 | New US public/convention facility additions |
| The Gentlemen affiliates | 2-4 | DFIR Report 5/11 EtherRAT + TukTuk → GPO deployment chain now public |
| Nova | 2-3 | Continued upward trajectory |
| NightSpire | 1-2 | Regional European targets |
| Genesis / Inc Ransom / Sinobi / Lamashtu / Play | 1-2 each | Second tier keeps producing |
A complete per-victim table remains unavailable this cycle (egress restriction); it will be backfilled tomorrow if RansomLook recovers.
Anomalies / trend notes
New observations in the last 24 hours
- DragonForce / Devman standout single-day activity— a high share of
.deand.nldomains, targeting small and mid-sized European manufacturing, food, and services firms. Worth watching this group's weekly trajectory — the last comparable single-day cluster was 5/22. - Qilin keeps hitting healthcare/legal proportionally—
Alpha Health CareplusAlpert Slobin & Rubenstein. Combined with the M-Trends 2026 / Mandiant 5/22 findings on Qilin (AGENDA) targeting backup infrastructure and identity systems, EDR teams in these two sectors should prioritize checking reachability of backup systems. - The Gentlemen affiliates keep posting after the 5/5 internal leak— the DFIR Report of 5/11 published the full EtherRAT → TukTuk (AI-generated framework) → GoTo Resolve RMM → GPO deployment chain, with usable IOCs. Worth pulling into this week's hunt list for IR teams.
Sector concentration (rough estimate)
- Healthcare / legal: ~25% (Qilin-dominated)
- Manufacturing / industrial automation: ~20% (The Gentlemen affiliates + Akira)
- Food / logistics / services: ~20% (DragonForce standout day)
- Education / public venues: ~10% (Akira × Buffalo Niagara)
- Other: ~25%
The quarterly picture is unchanged: Qilin / Akira / The Gentlemen / LockBit together account for ~41% of all 2026 victims; Qilin alone exceeds the sum of the bottom 50 groups.
New / resurfaced groups
- Given data-source limits, no clearly new group was observed this cycle (Genesis returned to normal levels after its 7-post day on 5/24-5/25; continued observation recommended)
IR / hunt recommendations
- The Gentlemen family: pull the DFIR Report 5/11 IOCs plus the 5/22 Check Point joint-report IOCs, and focus on:
- Anomalous GPO creation/modification and scheduled tasks under SYSVOL/NETLOGON
- GoTo Resolve installers, especially from unusual download sources
- EtherRAT / TukTuk artifacts
- Qilin / Akira: audit backup infrastructure reachability — who can reach the backup control plane from an ordinary workstation?M-Trends 2026 states plainly that recovery denial is now the norm.
- DragonForce / Devman: do not let recent EDR alerts from small and mid-sized European businesses get buried in noise; this group had a standout single-day volume.
Data health
- RansomLook API + RSS: HTTP 403 from proxy (egress allowlist not in the provenance set)
- ransomware.live: readable indirectly via WebSearch
- DFIR Report / Check Point Research: direct sources, but no new articles today (5/11 and 5/22 remain inside this week's window)
- breachsense / sharkstriker: victim samples can be assembled via WebSearch
Next step: work with the project maintainer to add RansomLook's two endpoints to the WebFetch allowed domains, which would restore per-victim data.