Ransomware Watch · Jul 22, 2026
Overview
- Total new posts: 5(RansomLook
?days=1) - Groups involved: 4(qilin / krybit / gunra / blackout)
- Watchlist hits: 2
- Data freshness note: the 5 items returned by
?days=1this run are identical to those of 2026-07-21 (discovered timestamps still 07-18 / 07-19), with no posts appearing after 07-20. Assessed as lag or a stale window on the RansomLook collection pipeline, notan actual zero-additions day on the leak sites. The RSS fallback sourcehttps://www.ransomlook.io/rss.xmlreturned binary content this run and could not be parsed. To be re-checked tomorrow.
Watchlist Hits (read first)
| Group | Victim | Sector | Geo | Hit | Link |
|---|---|---|---|---|---|
| qilin | Famesa | Manufacturing / munitions & defense | PE (Peru, inferred) | group:qilin | RansomLook |
| qilin | City Ambulance Service | Healthcare / pre-hospital emergency care | US (inferred) | group:qilin | RansomLook |
The two entries were discovered less than a second apart (2026-07-19T15:58:56 / :57), the classic signature of a batch upload to a leak site.
All New Posts
| Group | Victim | Sector | Geo | Discovered | Link |
|---|---|---|---|---|---|
| krybit | euroins.bg | Insurance | BG | 2026-07-18T18:55:04Z | RansomLook |
| gunra | Dissinger and Dissinger Law Firm | Legal services | US | 2026-07-18T21:56:59Z | RansomLook |
| blackout | bluebellgroup.com | Consumer goods / retail (inferred) | UK (inferred) | 2026-07-18T22:56:15Z | RansomLook |
| ⭐ qilin | Famesa | Manufacturing / defense | PE | 2026-07-19T15:58:56Z | RansomLook |
| ⭐ qilin | City Ambulance Service | Healthcare / emergency services | US | 2026-07-19T15:58:57Z | RansomLook |
Sector and Geo are inferred from victim names; the RansomLook
?days=1endpoint returns only the three fieldsgroup_name/post_title/discovered.
Anomalies / Trend Notes
- New intelligence on Qilin's initial access: news reporting today describes attackers exploiting a critical Palo Alto PAN-OS vulnerabilityto gain initial access to enterprise networks and deploy Qilinransomware. This corroborates qilin's sustained leak-site posting — edge devices (VPN / firewall) leading to ransomware remains the most consistent attack chain of 2026. If you have PAN-OS in your estate, verify patch status today.
BleepingComputer - Another edge-device-to-ransomware thread: the SonicWall SMA1000 dual zero-days (CVE-2026-15409, CVSS 10.0 / CVE-2026-15410) have been exploited in the wild by UTA0533 since 6/22, dropping ROOTRUN / KNUCKLEBALL / ORANGETAIL. Public reporting currently attributes this to espionage rather than ransomware, but entry points of this kind have historically been resold to ransomware affiliates; worth continuous tracking.
Volexity· Rapid7 - New-face groups:
krybit,blackoutandgunraappear infrequently in this workbench's historical archive; recommend establishing a baseline observation (new group or rebrand?). - Data pipeline: two consecutive days returning the same batch of posts → consider adding a backup source in
sources.yaml(ransomware.liveis already configured butenabled: false) to cross-validate and cover the blind spot when RansomLook stops updating.
Data source: RansomLook API · watchlist at intel/ransomware/watchlist.yaml