Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-07-01
Ransomware·2026-07-01

Ransomware Watch · Jul 1, 2026

Overview

  • Total new posts (RansomLook API, days=1): 6 (stalled, identical to 06-28 → 06-30)
  • Groups involved: 5 (redact, play, safepay, cmd organization)
  • Watchlist hits: 2 (both from the play group, carried over)
  • Data status: the latest discoveredon RansomLook days=1is frozen at 2026-06-28T12:52Z, a third consecutive day without movement. The tables below are a carried-over snapshot; the API returned nothing new today.

Watchlist Hits (read these first)

GroupVictimSectorGeoHitLink
playKuhnlinemanufacturing (inferred)US (inferred)group:playRansomLook
playJ&J GaminggamingUS (inferred)group:playRansomLook

All New Posts (RansomLook API snapshot, carried over)

GroupVictimSectorGeoDiscoveredLink
redactFCCI Insurance GroupinsuranceUS2026-06-27T20:20ZRansomLook
redactHologicmedical/diagnosticsUS2026-06-27T20:22ZRansomLook
playKuhnlinemanufacturingUS2026-06-27T20:59ZRansomLook
playJ&J GaminggamingUS2026-06-27T20:59ZRansomLook
safepayhellmold-plank.demanufacturingDE2026-06-27T20:59ZRansomLook
cmd organizationFidelity Security Groupsecurity services—2026-06-28T12:52ZRansomLook

Open-Source Reporting Supplement (beyond the API; today's WebSearch)

  • The Gentlemen (RaaS)— by publicly claimed victim count the group has risen to second most active(182 distinct victims), and is building a full EDR-killer toolset around the GentleKillerframework. Worth continued cross-source tracking.
  • Qilin → KUNERT Fashion— a textile/fashion sector victim reported on 6/30, attributed to Qilin.

Anomalies / Trend Notes

  • RansomLook API stalled for 3 consecutive days(06-28 → 07-01 return the same payload) — apparently a feed/collection-side issue. Today's ransomware picture should be based on open-source reporting (The Gentlemen, Qilin); do not misread "no new posts" as a decline in activity.
  • Industrialized EDR killers: The Gentlemen's GentleKiller continues the 2025-2026 RaaS trend of shipping driver-level defence evasion tooling. Verify EDR tamper-protection configuration.
  • Dormant/surging groups: this snapshot carries no reliable "sudden surge" signal, owing to the stalled data.

Data sources: RansomLook API/RSS plus open-source reporting; watchlist: see intel/ransomware/watchlist.yaml

← Prev
Ransomware Watch · Jun 30, 2026
Next →
Ransomware Watch · Jul 2, 2026