Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-07-09
Ransomware·2026-07-09

Ransomware Watch · Jul 9, 2026

⚠️ Data source note: in this run the RansomLook API (/api/posts?days=1) was unreachable (sandbox egress blocked, curl exit 56), and the RSS fallback did not yield per-post data either. The tables below are an aggregate picture based on public reporting, not same-day real-time victim details. Per-item details will be backfilled once the API recovers.

Overview

  • Same-day per-post details: unavailable(source degraded)
  • Landscape (past 30 days, public reporting): Qilin most active, Akira second, RansomHub third
  • Watchlist hits (by group/sector): Qilin, Akira, and RansomHub are all on the watchlist; healthcare / critical infrastructure highlighted on the sector side

Watchlist Hits (landscape-level, not per-post)

GroupNotesSector focusHitSource
QilinMost active of 2026, ~1,871 cumulative victims; frequently ranks first worldwide in weekly new victimshealthcare / critical-infragroup:qilin, sector:healthcareBarracuda
AkiraSecond worldwide, ~1,357 cumulative victimsmanufacturing / generalgroup:akiraCybelAngel
RansomHub~842 cumulative victimsgeneralgroup:ransomhubSOCRadar

All New Posts

GroupVictimSectorGeoDiscoveredLink
—Per-item details unavailable (RansomLook source degraded)——2026-07-09ransomware.live

Around Jul 7 new victims were listed by Qilin, Akira, and other groups (multi-source reporting), but structured per-item data could not be pulled from the API this run, so they are not listed individually to avoid errors.

Anomalies / Trend Notes

  • Qilin's dominance continues: after RansomHub's contraction, Qilin absorbed much of the affiliate traffic and keeps leading weekly new-victim counts; healthcare and public services are its high-risk targets (including the patient harm caused by the earlier London healthcare incident).
  • Initial access coupled to KEV: in-the-wild exploitation of SharePoint CVE-2026-45659 has been observed for initial access followed by ransomware/tool deployment — the linkage between the vulnerability side and the ransomware side is worth continued tracking.
  • Data-source resilience: this repo needs a stable fallback for when direct RansomLook access is unavailable (RSS / mirrors / ransomware.live cross-checks); recommend verifying API reachability first on the next run.

Watchlist config: intel/ransomware/watchlist.yaml

← Prev
Ransomware Watch · Jul 8, 2026
Next →
Ransomware Watch · Jul 10, 2026