Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-05-26
Ransomware·2026-05-26

Ransomware Watch · May 26, 2026

Time window: 2026-05-25 → 2026-05-26
Data sources: WebSearch aggregation (ransomware.live / breachsense.com / cyberthreatintelligence.net / sharkstriker / DFIR Report and other public tracking sources)
⚠️ Note: Direct pulls from the RansomLook API again failed this cycle due to the egress allowlist; this edition relies on aggregated second-hand data.

Overview

  • New posts (24h aggregate): ~35-45
  • Active DLS sites: ~91 (flat)
  • Groups involved: 6+ (primarily Qilin / Akira / The Gentlemen / DragonForce(Devman) / Nova / NightSpire, plus second-tier Genesis / Inc Ransom / Sinobi / Lamashtu / Play)
  • Watchlist hits: ≥ 5 by rough filtering on victim names visible in the aggregate (healthcare / education / manufacturing)

Watchlist hits (matched on known victim names)

GroupVictimSectorGeoHitNote
QilinAlpha Health Carehealthcare(likely US)group:qilin, sector:healthcareQilin continues to focus on healthcare plus backup destruction
QilinAlpert Slobin & Rubensteinlegal / financial-adjacentUSgroup:qilin, sector:financial (law-firm adjacency)Qilin continues targeting law firms
AkiraBuffalo Niagara Convention Centerhospitality / education-adjacentUSgroup:akira, sector:education (venue partly serves education conferences)New Akira addition inside the US
TheGentlemenACAM Systemautomation GmbHmanufacturing / industrial automationDEsector:manufacturingGPO-deployment TTP persists; German industrial automation target
NovaAdensa Technology / AMACCAO Grouptechnology / constructionglobal—Nova remains on an upward trajectory
NightSpireBresme Madrid, S.L.(regional, sector unknown)ESgeo:es?Outside the watchlist geography; logged for the record only

All new posts (aggregate view; some entries are batch deltas observed only at group level)

GroupNew count (24h estimate)Note
DragonForce / Devman5+Standout single-day activity (allianceadjustment.com / xtr-global.de / saver.nl / vegfresh.com / ggroupcpas.com)
Qilin4-6Still first on cumulative volume; heavy healthcare/legal share this cycle
Akira3-5New US public/convention facility additions
The Gentlemen affiliates2-4DFIR Report 5/11 EtherRAT + TukTuk → GPO deployment chain now public
Nova2-3Continued upward trajectory
NightSpire1-2Regional European targets
Genesis / Inc Ransom / Sinobi / Lamashtu / Play1-2 eachSecond tier keeps producing

A complete per-victim table remains unavailable this cycle (egress restriction); it will be backfilled tomorrow if RansomLook recovers.


Anomalies / trend notes

New observations in the last 24 hours

  • DragonForce / Devman standout single-day activity— a high share of .deand .nldomains, targeting small and mid-sized European manufacturing, food, and services firms. Worth watching this group's weekly trajectory — the last comparable single-day cluster was 5/22.
  • Qilin keeps hitting healthcare/legal proportionally— Alpha Health Careplus Alpert Slobin & Rubenstein. Combined with the M-Trends 2026 / Mandiant 5/22 findings on Qilin (AGENDA) targeting backup infrastructure and identity systems, EDR teams in these two sectors should prioritize checking reachability of backup systems.
  • The Gentlemen affiliates keep posting after the 5/5 internal leak— the DFIR Report of 5/11 published the full EtherRAT → TukTuk (AI-generated framework) → GoTo Resolve RMM → GPO deployment chain, with usable IOCs. Worth pulling into this week's hunt list for IR teams.

Sector concentration (rough estimate)

  • Healthcare / legal: ~25% (Qilin-dominated)
  • Manufacturing / industrial automation: ~20% (The Gentlemen affiliates + Akira)
  • Food / logistics / services: ~20% (DragonForce standout day)
  • Education / public venues: ~10% (Akira × Buffalo Niagara)
  • Other: ~25%

The quarterly picture is unchanged: Qilin / Akira / The Gentlemen / LockBit together account for ~41% of all 2026 victims; Qilin alone exceeds the sum of the bottom 50 groups.

New / resurfaced groups

  • Given data-source limits, no clearly new group was observed this cycle (Genesis returned to normal levels after its 7-post day on 5/24-5/25; continued observation recommended)

IR / hunt recommendations

  1. The Gentlemen family: pull the DFIR Report 5/11 IOCs plus the 5/22 Check Point joint-report IOCs, and focus on:
    • Anomalous GPO creation/modification and scheduled tasks under SYSVOL/NETLOGON
    • GoTo Resolve installers, especially from unusual download sources
    • EtherRAT / TukTuk artifacts
  2. Qilin / Akira: audit backup infrastructure reachability — who can reach the backup control plane from an ordinary workstation?M-Trends 2026 states plainly that recovery denial is now the norm.
  3. DragonForce / Devman: do not let recent EDR alerts from small and mid-sized European businesses get buried in noise; this group had a standout single-day volume.

Data health

  • RansomLook API + RSS: HTTP 403 from proxy (egress allowlist not in the provenance set)
  • ransomware.live: readable indirectly via WebSearch
  • DFIR Report / Check Point Research: direct sources, but no new articles today (5/11 and 5/22 remain inside this week's window)
  • breachsense / sharkstriker: victim samples can be assembled via WebSearch

Next step: work with the project maintainer to add RansomLook's two endpoints to the WebFetch allowed domains, which would restore per-victim data.

← Prev
Ransomware Watch · May 25, 2026
Next →
Ransomware Watch · May 31, 2026