Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-06-10
Ransomware·2026-06-10

Ransomware Watch · Jun 10, 2026

Window: past 24 hours (RansomLook /api/posts?days=1, covering 2026-06-08 16:49 → 2026-06-09 14:50 UTC, Monday-into-Tuesday weekday catch-up)
✅ Data basis: this cycle the public RansomLook API was directly reachable (/api/posts?days=1 returned JSON). ⚠️ However, this payload contained only the group_nameand discoveredfields — no post_title, victim, sector, or geo. Per-victim detail therefore cannot be provided this cycle; the tables below aggregate by group and time. The RSS feed (rss.xml) returned binary content that the fetch tool could not parse as text, and ransomware.live /v2/recentvictims was not directly reachable due to provenance restrictions, so victim names could not be cross-filled.

Overview

  • Total new posts: 32
  • Groups involved: 7(lockbit5, qilin, akira, ransomhouse, termite, stormous, nova)
  • Watchlist hits: 25(lockbit5 17 + qilin 6 + akira 2; all matching the groupslist)

Watchlist hits (read first)

Only group-level data is available this cycle (no victim names), so hits are aggregated by group.

GroupPostsHitWindow (UTC)Link
lockbit517group:lockbit (rebrand → LockBit 5.0)2026-06-09 14:50:08 → 14:50:25 (posted in a burst of about 17 seconds)ransomlook.io/group/lockbit5
qilin6group:qilin2026-06-08 16:49 → 2026-06-09 01:48ransomlook.io/group/qilin
akira2group:akira2026-06-08 16:49 / 2026-06-09 14:46ransomlook.io/group/akira

All new posts (24h, aggregated by group)

GroupPostsFirst seen (UTC)Last seen (UTC)Link
lockbit5172026-06-09 14:50:082026-06-09 14:50:25ransomlook.io
qilin62026-06-08 16:49:592026-06-09 01:48:12ransomlook.io
akira22026-06-08 16:49:342026-06-09 14:46:55ransomlook.io
ransomhouse22026-06-08 20:48:062026-06-08 22:49:38ransomlook.io
termite22026-06-09 01:48:162026-06-09 01:48:17ransomlook.io
stormous22026-06-09 14:47:182026-06-09 14:47:19ransomlook.io
nova12026-06-09 13:45:212026-06-09 13:45:21ransomlook.io

Anomalies / trend notes

  • LockBit5 comeback burst: a single group posted 17 entries within roughly 17 secondsat 14:50 UTC on 6/9, accounting for 53% of all posts that day. This kind of bulk dump usually means a previously accumulated backlog of victims is being published at once, and it matches Check Point / Arete intelligence on the revival of LockBit 5.0(announced on RAMP in September 2025, internal codename "ChuongDong," risen to #4 in Q1 2026 with 163 victims, up 106% quarter over quarter). Worth close tracking: are these genuinely new victims, or repopulated old data to pad the site? LockBit has historically filled its leak site with old breaches.
  • Qilin remains the steadiest group: 6 posts in the window, evenly distributed from throughout 6/8 into the early hours of 6/9, continuing the #1 position it has held for three consecutive quarters in Q1.
  • Low-frequency / new group names: termite, stormous, ransomhouse, and novaeach contributed 1–2 posts in this window; the paired, tightly spaced postings from termite and stormous (within the same second) suggest automated bulk publishing.
  • Data-basis reminder: the victim dimension is missing this cycle (sector and geography cannot be determined, so watchlist sectors/ geoshits cannot be evaluated) and only the groupsdimension is assessable. Tomorrow, using the RansomLook /recentpage or the /api/group/<name>endpoint to backfill victim names is recommended, or cross-referencing ransomware.live where provenance allows.
← Prev
Ransomware Watch · Jun 9, 2026
Next →
Ransomware Watch · Jun 11, 2026