Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-07-22
Ransomware·2026-07-22

Ransomware Watch · Jul 22, 2026

Overview

  • Total new posts: 5(RansomLook ?days=1)
  • Groups involved: 4(qilin / krybit / gunra / blackout)
  • Watchlist hits: 2
  • Data freshness note: the 5 items returned by ?days=1this run are identical to those of 2026-07-21 (discovered timestamps still 07-18 / 07-19), with no posts appearing after 07-20. Assessed as lag or a stale window on the RansomLook collection pipeline, notan actual zero-additions day on the leak sites. The RSS fallback source https://www.ransomlook.io/rss.xmlreturned binary content this run and could not be parsed. To be re-checked tomorrow.

Watchlist Hits (read first)

GroupVictimSectorGeoHitLink
qilinFamesaManufacturing / munitions & defensePE (Peru, inferred)group:qilinRansomLook
qilinCity Ambulance ServiceHealthcare / pre-hospital emergency careUS (inferred)group:qilinRansomLook

The two entries were discovered less than a second apart (2026-07-19T15:58:56 / :57), the classic signature of a batch upload to a leak site.

All New Posts

GroupVictimSectorGeoDiscoveredLink
krybiteuroins.bgInsuranceBG2026-07-18T18:55:04ZRansomLook
gunraDissinger and Dissinger Law FirmLegal servicesUS2026-07-18T21:56:59ZRansomLook
blackoutbluebellgroup.comConsumer goods / retail (inferred)UK (inferred)2026-07-18T22:56:15ZRansomLook
⭐ qilinFamesaManufacturing / defensePE2026-07-19T15:58:56ZRansomLook
⭐ qilinCity Ambulance ServiceHealthcare / emergency servicesUS2026-07-19T15:58:57ZRansomLook

Sector and Geo are inferred from victim names; the RansomLook ?days=1 endpoint returns only the three fields group_name / post_title / discovered.

Anomalies / Trend Notes

  • New intelligence on Qilin's initial access: news reporting today describes attackers exploiting a critical Palo Alto PAN-OS vulnerabilityto gain initial access to enterprise networks and deploy Qilinransomware. This corroborates qilin's sustained leak-site posting — edge devices (VPN / firewall) leading to ransomware remains the most consistent attack chain of 2026. If you have PAN-OS in your estate, verify patch status today.
    BleepingComputer
  • Another edge-device-to-ransomware thread: the SonicWall SMA1000 dual zero-days (CVE-2026-15409, CVSS 10.0 / CVE-2026-15410) have been exploited in the wild by UTA0533 since 6/22, dropping ROOTRUN / KNUCKLEBALL / ORANGETAIL. Public reporting currently attributes this to espionage rather than ransomware, but entry points of this kind have historically been resold to ransomware affiliates; worth continuous tracking.
    Volexity· Rapid7
  • New-face groups: krybit, blackoutand gunraappear infrequently in this workbench's historical archive; recommend establishing a baseline observation (new group or rebrand?).
  • Data pipeline: two consecutive days returning the same batch of posts → consider adding a backup source in sources.yaml(ransomware.liveis already configured but enabled: false) to cross-validate and cover the blind spot when RansomLook stops updating.

Data source: RansomLook API · watchlist at intel/ransomware/watchlist.yaml

← Prev
Ransomware Watch · Jul 21, 2026
Next →
Ransomware Watch · Jul 23, 2026