Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-06-01
Ransomware·2026-06-01

Ransomware Watch · Jun 1, 2026

Time window: 2026-05-31 → 2026-06-01
Data sources: WebSearch aggregation (ransomware.live / breachsense / SharkStriker / The Record / Coveware-cited and other public tracking sources)
⚠️ Note: RansomLook API + RSS again failed this cycle due to the egress allowlist (WebFetch domain filtering); this edition relies on aggregated second-hand data.

Overview

  • New posts (24h aggregate): ~30-40
  • Active DLS sites: ~90 (flat)
  • Groups involved: 5+ (primarily Qilin / Akira / DragonForce(Devman) / The Gentlemen / Sinobi, plus second-tier Inc Ransom / Nova / NightSpire / Play)
  • Watchlist hits: ≥ 3 by rough filtering on victims visible in the aggregate (healthcare / manufacturing)
  • Macro signal: the ransom payment rate has fallen to 28%, an all-time low(Coveware basis), despite claims of rising attack volume

Watchlist hits (matched on known victims/sectors)

GroupVictim/TargetSectorGeoHitNote
Qilin(healthcare/legal targeting continues; per-victim list unavailable this cycle)healthcare / legal(likely US)group:qilin, sector:healthcareQilin keeps the lead, focused on healthcare plus backup destruction
Akira(manufacturing targeting)manufacturingglobalgroup:akira, sector:manufacturingAkira's manufacturing activity continues
The Gentlemen(mixed sectors; GPO deployment TTP continues)mixed / industrialEU/USgroup:thegentlemenThe DFIR Report 5/11 EtherRAT+TukTuk→GPO chain is public

A complete per-victim table remains unavailable this cycle (egress restriction). It can be backfilled once RansomLook's two endpoints are restored.


All new posts (aggregate view, batch deltas observed at group level)

GroupNew count (24h estimate)Note
Qilin4-6Still first on cumulative volume; heavy healthcare/legal share
Akira3-5Mostly manufacturing
DragonForce / Devman2-4Small and mid-sized European businesses continue
The Gentlemen affiliates2-3GPO deployment TTP is now standardized
Sinobi1-3Steady second-tier output
Inc Ransom / Nova / NightSpire / Play1-2 eachSecond tier continues

Anomalies / trend notes

New observations in the last 24 hours

  • Payment rate at a record low (28%)— the most important macro signal this cycle. The share of victims who pay has now declined for multiple consecutive quarters, indicating that backup/recovery maturity and "do not pay" policies are landing at more organizations. Ransomware groups offset this with higher claimed attack volume and double-extortion pressure, so DLS posting volume has not fallen in step. For defenders this means groups will apply public pressure more aggressively and accelerate their leak cadence.
  • Qilin keeps hitting healthcare/legal proportionally— combined with the M-Trends 2026 / Mandiant findings on Qilin (AGENDA) targeting backup infrastructure and identity systems, EDR/IR teams in these two sectors should prioritize checking reachability of the backup control plane.
  • Akira's manufacturing focus continues— it overlaps with The Gentlemen affiliates on industrial/manufacturing targets, so OT-adjacent environments warrant attention.

Sector concentration (rough estimate)

  • Healthcare / legal: ~30% (Qilin-dominated)
  • Manufacturing / industrial: ~25% (Akira + The Gentlemen affiliates)
  • Services / logistics / SMBs: ~20% (DragonForce's European targets)
  • Other: ~25%

The quarterly picture is unchanged: Qilin / Akira / The Gentlemen / LockBit together account for roughly 40% of all 2026 victims; Qilin alone still exceeds the sum of the bottom 50 groups.

New / resurfaced groups

  • Given data-source limits, no clearly new group was observed this cycle.

IR / hunt recommendations

  1. Qilin / Akira: audit backup infrastructure reachability — who can reach the backup control plane from an ordinary workstation?Recovery denial is now the norm. Against a record-low 28% payment rate, recovery capability is exactly what makes not paying possible.
  2. The Gentlemen family: pull the DFIR Report 5/11 IOCs plus the Check Point joint-report IOCs, focusing on anomalous GPO creation/modification, scheduled tasks under SYSVOL/NETLOGON, and unusual GoTo Resolve installations.
  3. DragonForce / Devman: do not let recent EDR alerts from small and mid-sized European businesses get buried in noise.

Data health

  • RansomLook API + RSS: blocked by WebFetch domain filtering (egress allowlist not in the provenance set)
  • ransomware.live / The Record / SharkStriker: readable indirectly via WebSearch
  • Coveware-basis payment-rate data: readable via the Bleeping Computer reprint

Next step: work with the project maintainer to add RansomLook's two endpoints to the WebFetch allowed domains, which would restore per-victim data.

← Prev
Ransomware Watch · May 31, 2026
Next →
Ransomware Watch · Jun 2, 2026