IntelliOS Threat Intel Operating System
IntelliOSRolling Intelligence|AIRolling Arete Intelligence Watch

Arete Cyber Threat & Incident Response Rolling Intelligence Card

A source-cited rolling one-year synthesis of Arete's crimeware and incident-response research from 27 July 2025 through 26 July 2026. The card uses the Q3 2025, 2025 Annual, and Q1 2026 Crimeware Reports plus monthly and technical updates to show how actor concentration, access methods, victimology, payment pressure, and defensive priorities changed across the full window. The Q1 2026 report remains the highest-weight current analytic source, and every observation period is kept distinct from the date Arete published it.

Coverage
Jul 29, 2025–Jul 28, 2026
Record Version
v4
Updated
Jul 28, 2026
AI Monitor
Weekly · Mon midday ET
Evidence
21 Retained Sources
Product
Rolling Intelligence Card
Classification
TLP:CLEAR

Research Framing

Reporting-Period Statistics

Rolling 1-Year Intelligence Snapshot

At-a-glance measures from the retained evidence set. Citations identify the source controlling each statistic.

Period Coverage

Jul 29, 2025Jul 28, 2026

365 calendar days, inclusive. Records are included by their first-observed date inside this window; the period does not imply that every underlying incident began or was confirmed during it.

365-day windowWeekly on Monday at midday ET

31%[2]

Q1 Ransom Payment Rate

Arete-handled Q1 ransomware and extortion engagements; down from 33% in Q1 2025.Evidence dated Jun 3, 2026

$571K[2]

Q1 Median Demand

Arete's Q1 engagement population; below the $600K full-year 2025 median.Evidence dated Jun 3, 2026

$250K[2]

Q1 Median Payment

Up from $100K in Q1 2025 and $152,750 for full-year 2025.Evidence dated Jun 3, 2026

32.6%[2]

Akira + Qilin Share

18.3% Akira plus 14.3% Qilin in Arete's Q1 engagement chart.Evidence dated Jun 3, 2026

21.6%[2]

Leading Sector

Professional, scientific, and technical services share of Arete Q1 engagements.Evidence dated Jun 3, 2026

38[2]

Named Threat Actors

Named actor labels in Arete's Q1 population, plus 10 unnamed actors; not unique legal persons.Evidence dated Jun 3, 2026

81 + 52[17]

2025 Actor Labels

Named plus unnamed actor labels across Arete's full-year 2025 engagement population.Evidence dated Mar 27, 2026

31.6%[17]

2025 Payment Rate

Share of Arete's full-year 2025 ransomware and extortion engagements resulting in payment.Evidence dated Mar 27, 2026

Arete Q1 2026 Threat-Group Share

Share of Arete ransomware and extortion engagements for the five leading named groups shown in the Q1 report. These are handled engagements, not leak-site victim totals.[2]Evidence dated Jun 3, 2026

percent

Ransom Payment Rate

The proportion of Arete engagements resulting in payment declined slightly across the comparison periods.[2]Evidence dated Jun 3, 2026

percent

Median Ransom Demand

Arete's median demand increased year over year but remained below the full-year 2025 median.[2]Evidence dated Jun 3, 2026

USD

Median Ransom Payment

The median paid amount in Arete engagements rose sharply even as the overall payment rate edged lower.[2]Evidence dated Jun 3, 2026

USD

Most Impacted Q1 Sectors

Leading NAICS sector shares in Arete's Q1 engagement population. Arete assesses most activity as opportunistic and access-driven rather than sector-exclusive.[2]Evidence dated Jun 3, 2026

percent

Akira Share Across the Rolling Year

Arete engagement share at selected observation periods. This shows the August 2025 surge and subsequent normalization rather than implying one static annual threat level.[9][17][2]First cited source Dec 3, 2025 · Latest cited source Jun 3, 2026

percent

Arete 2025 Threat-Group Share

Leading named groups in Arete's full-year 2025 engagement population. The annual report identified 81 named and 52 unnamed labels overall.[17]Evidence dated Mar 27, 2026

percent

Most Impacted 2025 Sectors

Leading sector shares in Arete's full-year 2025 engagement population, retained separately from the Q1 2026 sector chart.[17]Evidence dated Mar 27, 2026

percent

Evidence-Prioritized Access Paths

Top Initial Access & Account-Takeover Vectors

Arete explicitly identifies vulnerability exploitation, compromised credentials, and social engineering as the leading Q1 initial-access classes. The ranked operational view below expands those categories with the concrete technologies and workflows documented in the full report and later Arete updates; it does not invent percentage shares that Arete did not publish.

1

Publisher-observed access path

Internet-facing firewall and remote-support exploitation[2][4][6]First cited source Jun 3, 2026 · Latest cited source Jul 14, 2026

Retained Arete evidence; local exposure and prevalence require validation

How it starts
Attackers scan and exploit Fortinet, WatchGuard, BeyondTrust, and other exposed edge systems, including both newly disclosed and older unpatched vulnerabilities.
Attacker outcome
Pre-authentication execution, privileged control, credential theft, reverse shells, persistent access, lateral movement, and ransomware deployment.
What to monitor
Exact product/version inventory, management exposure, exploit requests, unexpected processes, reverse shells, new accounts, RDP enablement, and post-patch historical indicators.
2

Publisher-observed access path

Compromised and reused credentials[2][4][6]First cited source Jun 3, 2026 · Latest cited source Jul 14, 2026

Retained Arete evidence; local exposure and prevalence require validation

How it starts
Botnets brute-force common accounts or attackers reuse credentials obtained from configurations, infostealers, or earlier compromises.
Attacker outcome
Valid VPN or administrative access that can blend into normal authentication.
What to monitor
Password spraying, impossible travel, new devices, dormant-account activation, configuration export, unusual VPN sessions, and service-account use.
3

Publisher-observed access path

Vishing and trusted-person impersonation[3]Evidence dated Jul 17, 2026

Retained Arete evidence; local exposure and prevalence require validation

How it starts
An attacker impersonates a manager or trusted party and pressures the user through a voice channel.
Attacker outcome
User-assisted completion of a device-code or authentication workflow.
What to monitor
Unusual voice-driven access requests, help-desk changes, new device registrations, and suspicious cloud sessions.
4

Publisher-observed access path

Teams help-desk impersonation and remote assistance[2]Evidence dated Jun 3, 2026

Retained Arete evidence; local exposure and prevalence require validation

How it starts
Email bombing or phishing is followed by cross-tenant Teams contact from an attacker posing as internal IT and directing OAuth consent or Quick Assist access.
Attacker outcome
Identity-backed remote control, persistent sessions, and data access through legitimate services.
What to monitor
External-tenant chats, guest access, unusual support contacts, Quick Assist launches, OAuth consent, new MFA registration, and follow-on exports.
5

Publisher-observed access path

Device-code phishing and MFA abuse[2][3]First cited source Jun 3, 2026 · Latest cited source Jul 17, 2026

Retained Arete evidence; local exposure and prevalence require validation

How it starts
The victim completes an attacker-controlled device authentication flow.
Attacker outcome
Valid cloud session access without traditional password-only compromise.
What to monitor
Device-code grants, unfamiliar user agents, session reuse, and SharePoint enumeration.
6

Publisher-observed access path

ClickFix and deceptive command execution[2]Evidence dated Jun 3, 2026

Retained Arete evidence; local exposure and prevalence require validation

How it starts
Fake CAPTCHA, browser-error, troubleshooting, or sponsored-install prompts convince a user to paste commands or install malicious software.
Attacker outcome
RAT, infostealer, or ransomware delivery using legitimate interpreters and user action.
What to monitor
Clipboard-to-shell behavior, terminal launches from browsers, PowerShell/Python execution, suspicious installers, browser crashes, and new remote-control tooling.
7

Publisher-observed access path

Edge credential harvesting[4][6]First cited source Jun 30, 2026 · Latest cited source Jul 14, 2026

Retained Arete evidence; local exposure and prevalence require validation

How it starts
Internet scanning, password spraying, SSH brute force, and configuration extraction target FortiGate systems.
Attacker outcome
Reusable administrative and VPN credentials plus persistent access.
What to monitor
High-volume failures followed by success, config export, admin creation, and unusual VPN access.
8

Publisher-observed access path

OAuth and trusted integration abuse[5]Evidence dated Jul 6, 2026

Retained Arete evidence; local exposure and prevalence require validation

How it starts
Tokens are stolen from a provider or connected application.
Attacker outcome
Downstream access to customer SaaS data through existing trust.
What to monitor
New grants, unusual API access, mass exports, token reuse, and third-party anomalies.
9

Publisher-observed access path

Vulnerable-driver execution[2][5]First cited source Jun 3, 2026 · Latest cited source Jul 6, 2026

Retained Arete evidence; local exposure and prevalence require validation

How it starts
Attackers load a signed but vulnerable driver or EDR-disabling utility.
Attacker outcome
Security-control impairment and a path to ransomware or broader post-exploitation.
What to monitor
Unexpected driver loads, service stops, kernel events, and policy changes.

Intended Reader and Decision Context

Persona / Audience

Who this brief is written for, the geographic and organizational lens it uses, and how readers should apply the intelligence.

Audience fieldPrimary audienceAssessmentExecutives, CISOs, CIOs, incident-response leaders, threat-intelligence teams, SOC leaders, risk owners, and business-continuity leaders who need a decision-ready view of one publisher's strongest public research.
Audience fieldDecision useAssessmentUse the card to identify recurring access paths, actor and campaign changes, affected technologies, likely business impact, and control priorities that deserve validation inside the reader's own environment.
Audience fieldSource postureAssessmentArete is the controlling source for publisher-specific observations. External facts repeated in a publication retain the original attribution and are not upgraded into independently verified IntelliOS findings.
Audience fieldUpdate modelAssessmentA dedicated publisher agent checks the complete monitored corpus weekly on monday at midday et, keeps a cumulative rolling one-year window, and sends Page Alerts only for material source-backed changes.

Chronology and Decision Milestones

Timeline of Notable Activity

Entries are ordered from oldest to newest across the full rolling year. Monthly and quarterly findings use the end of Arete's stated observation period; Citations preserve the later publication date. One-off technical research and official actions use their public date, and no entry is treated as the date an intrusion necessarily began.

  1. July observation · actor concentration

    Akira entered the window as the clear volume leader, but not as a monopoly

    Arete's Q3 report assigns Akira 32.1% of July engagements, followed by Qilin at 11.3% and Sinobi at 9.4%. The opening month already supports a multi-actor playbook even before Akira's August surge.[9]

  2. August observation · actor surge

    Akira rose above half of Arete's August engagements

    Akira reached 52.9% in August, while Qilin represented 15.3% and PLAY 5.9%. Arete tied the spike partly to exploitation and legacy credentials around SonicWall environments, making edge history and credential hygiene central response questions.[9][10]

  3. August observation · SaaS supply chain

    Salesloft Drift token theft turned a trusted integration into downstream access

    Arete's Q3 analysis describes theft of Salesforce OAuth and refresh tokens associated with the Salesloft Drift campaign. Connected-app inventory, token revocation, and downstream log review are necessary when a SaaS provider is compromised.[9][10]

  4. September observation · enterprise extortion

    CL0P began an Oracle EBS extortion wave tied to CVE-2025-61882

    Arete records extortion emails beginning on 29 September following exploitation of Oracle E-Business Suite. The sequence demonstrates why application remediation must include retrospective data-access review and preparation for delayed extortion contact.[9]

  5. September observation · actor mix

    Akira receded while PLAY and World Leaks gained share

    Arete's Q3 report places Akira at 36.6%, Qilin at 11.3%, and both PLAY and World Leaks at 7.0% in September. Extortion-only operations became a larger part of the visible mix even as the leading ransomware brands persisted.[9][11]

  6. October observation · parallel campaigns

    Edge exploitation and SaaS extortion were active at the same time

    Arete kept Akira and Qilin among October's leaders while tracking CL0P's Oracle EBS campaign and the Scattered Lapsus$ Hunters/Salesloft activity. Response planning must cover appliance compromise, enterprise applications, and trusted cloud integrations concurrently.[12]

  7. Law-enforcement action · malware infrastructure

    Operation Endgame removed infrastructure at scale without ending the crimeware market

    Arete's account of Season 3 attributes more than 1,000 server disruptions, 20 seized domains, an operator arrest, and millions of stolen credentials to the coordinated action. The takedown imposed cost, but Arete did not treat it as proof that ransomware access supply had stopped.[13]

  8. Full-year observation · actor landscape

    Akira led 2025, but Arete still observed a fragmented operator ecosystem

    Arete's annual report places Akira at 28.4% and Qilin at 12.8% across 81 named and 52 unnamed actor labels. Akira's Q3 surge mattered, but the number of labels shows why a durable defense cannot depend on a single-brand watchlist.[17]

  9. December observation · renewed concentration

    Akira exceeded one-third of December activity as RansomHouse returned

    Arete reports Akira above one-third of December observations and the top three groups at 57%, alongside RansomHouse's return and emerging React2Shell and MongoBleed exposure. Actor concentration and fast-moving vulnerability response were linked operational concerns.[14][17]

  10. January observation · broader actor mix

    The top three fell to 34% as LockBit 5 and ClickFix entered the watchlist

    Arete identified 17 groups in January, with Akira at 17% and the top three representing only about one-third. LockBit 5 activity and ClickFix/CrashFix social engineering reinforced the need to follow behaviors across changing brands.[15]

  11. February observation · edge and endpoint defense

    Akira and Qilin again approached half of activity while access paths diversified

    Arete's February review places Akira and Qilin at nearly half of observations and highlights Qilin exploitation of WatchGuard CVE-2025-14733 plus Hotta Killer BYOVD activity. Edge remediation and protection against security-driver tampering belong in the same program.[16]

  12. Q1 observation · ransom economics

    Payments became less frequent but materially larger when victims paid

    Arete reports a 31% Q1 2026 payment rate, down from 33% in Q1 2025, while the median payment rose from $100,000 to $250,000. The Q1 median demand was $571,000. Lower payment frequency therefore did not reduce the financial severity of the paid cases in Arete's engagement population.[2]

  13. Q1 observation · actor concentration

    Akira and Qilin produced almost one-third of Arete's Q1 engagements

    Akira represented 18.3% and Qilin 14.3% of Q1 activity in Arete's chart. Their combined share remained important but declined from more than half in each of Q3 and Q4 2025, showing concentration easing without eliminating either actor as a priority.[2]

  14. Q1 observation · payment leverage

    Akira combined high volume with unusually strong payment conversion

    Arete reports Akira median demands of $700,000, median payments of $300,000, and payment in almost 48% of Akira engagements. More than half of those paying victims purchased data suppression without a decryptor, showing that stolen-data pressure can drive payment even when recovery is not the objective.[2]

  15. Q1 observation · victimology

    Professional services led a broad, access-driven victim population

    Professional, scientific, and technical services accounted for 21.6% of Arete engagements, followed by manufacturing at 13.6%, wholesale trade at 10.4%, healthcare and social assistance at 8.8%, retail at 8.0%, and construction at 7.2%. Arete assesses most groups as opportunistic and access-vector-driven rather than sector-exclusive.[2]

  16. Q1 observation · initial access

    Edge exploitation, compromised credentials, and social engineering formed the Q1 access triad

    Arete identifies vulnerability exploits, compromised credentials, and social engineering as the leading initial-access classes. Firewalls and VPN systems concentrate risk because they are internet-facing, authentication-connected, and capable of exposing internal enterprise access after compromise.[2]

  17. Q1 observation · identity-first intrusion

    Teams impersonation, device-code abuse, and ClickFix moved social engineering beyond ordinary phishing

    Arete observed renewed cross-tenant Microsoft Teams help-desk impersonation, OAuth and Quick Assist workflows, and ClickFix campaigns across Windows and macOS. Akira, INC Ransom, Payouts King, and Chaos used Teams-style tactics, while Akira, Qilin, and Interlock adopted ClickFix.[2]

  18. Q1 observation · edge vulnerabilities

    Fortinet, WatchGuard, and BeyondTrust weaknesses were operational entry paths—not inventory trivia

    The report documents Fortinet authentication bypass and older-flaw exploitation, Qilin exploitation of WatchGuard CVE-2025-14733, and Arete-confirmed exploitation of BeyondTrust CVE-2026-1731 linked to a Medusa-associated cluster. Edge remediation must pair patching with access review and hunting.[2]

  19. Q1 observation · actor persistence

    The top tier remained stable even as new ransomware brands emerged

    Akira, Qilin, PLAY, and INC Ransom remained among Arete's top five groups in every quarter since the second half of 2025. NightSpire posted more than 100 Q1 disclosures, BravoX posted nine while building credibility, and Schrodinger Cat formalized its brand, but established operators still drove most handled activity.[2]

  20. Q1 observation · RaaS evolution

    DragonForce's cartel model and leaked-code reuse lower the cost of operational change

    Arete describes DragonForce shifting toward a decentralized partnership model and identifies Conti-derived implementation overlap. Its appendix reports identical ChaCha-like encryption logic, shared command-line behavior, a common mutex, and 99% BinDiff similarity between compared 32-bit DragonForce and Devman samples.[2]

  21. Q1 observation · AI evidence boundary

    Most adversarial AI use remained generative and assistive—not autonomous

    Arete observed AI accelerating stolen-data analysis, victim prioritization, social engineering, and extortion strategy, while its outlook says most current use remained generative rather than agentic. Defenders should act on measurable workflow acceleration without claiming autonomous intrusions the evidence does not establish.[2]

  22. March observation · distribution shift

    Twenty-one groups diluted the leading brands and widened the response burden

    Arete observed 21 groups in March versus 15 in February, with Akira and Qilin falling from nearly half to just over one-quarter. FortiGate exploitation and Teams/Quick Assist social engineering show that actor-share changes do not simplify the access problem.[18]

  23. April observation · leadership change

    Qilin overtook Akira while four groups generated about half of activity

    Arete reports Qilin moving ahead of Akira in April, with Akira, Qilin, INC Ransom, and DragonForce together accounting for roughly half. DragonForce's rise and continued BYOVD use show both concentration and tactical adaptation.[19]

  24. Technical campaign · deceptive files

    Fake JPEG delivery concealed PowerShell and remote-management access

    Arete describes attackers using a fake image workflow to execute PowerShell and deploy a trojanized ScreenConnect path. File extension, content, user action, script execution, and remote-tool behavior must be correlated.[21]

  25. Technical campaign · web compromise

    A Ghost CMS flaw exposed more than 700 sites to ClickFix delivery

    Arete's research connects CVE-2026-26980 exploitation across education and technology sites to a ClickFix campaign. A compromised website can become social-engineering infrastructure even when the visitor is not the original intrusion target.[20]

  26. AI-assisted offense

    Later Arete analysis sharpened how AI shortens malware development and EDR testing

    Arete describes threat actors using agent-based AI workflows for Active Directory discovery, iterative development, lab reproduction, and evasion testing. It found no evidence that AI was embedded as an autonomous operator inside victim environments.[8]

  27. Criminal infrastructure disruption

    AudiA6 shows ransomware depends on professional laundering infrastructure

    Arete's account of the Europol-backed action describes arrests, more than 30 servers, 25 domains, and over €778,000 in frozen or seized cryptocurrency. Financial services, mule accounts, and marketplace infrastructure belong in the ransomware ecosystem map.[7]

  28. Credential exposure

    FortiBleed is a credential-compromise problem, not a patch-only problem

    Arete's update describes password spraying, configuration exfiltration, packet sniffing, and harvested credentials affecting more than 86,000 devices across 194 countries. Credential resets, historical log review, management-plane restriction, and hunting are required alongside fixes.[6]

  29. June observation · crimeware trend

    June activity remained distributed despite Akira leading Arete's observations

    Arete identified 17 unique groups during June and kept Akira, Qilin, and INC Ransom among the most active. The decision is to maintain a behavior-led watchlist instead of anchoring response plans to one brand.[5]

  30. June observation · trusted software abuse

    BYOVD is being used to disable or evade endpoint defenses

    Arete reports Akira and DragonForce using vulnerable drivers in engagements and describes GentleKiller as a framework targeting multiple security products. Driver loading and security-control tampering should be high-priority detection events.[5]

  31. June observation · SaaS supply chain

    OAuth tokens can propagate one provider breach into many customer environments

    Arete's June review uses the Klue incident to show how stolen Salesforce integration tokens can extend an intrusion through trusted SaaS relationships. Token inventory, revocation, and connected-app telemetry are incident-response requirements.[5]

  32. Ransomware access ecosystem

    FortiBleed links stolen edge credentials to INC and Lynx operations

    Arete reports evidence connecting the credential-harvesting campaign to INC and Lynx ransomware operations, including a shared operator and exposed workflow infrastructure. Organizations with affected FortiGate history should investigate credentials and administrative activity even after patching.[4][6]

  33. Identity-led extortion

    Helix makes Microsoft 365 identity the extortion perimeter

    Arete describes Helix using vishing, device-code phishing, MFA abuse, and trusted-person impersonation to reach SharePoint Online and exfiltrate data. The practical control boundary is the identity session and cloud application—not only the endpoint.[3]

  34. Actor identity boundary

    Helix may overlap ShinyHunters and BlackFile ecosystems, but the relationship is unresolved

    Arete notes operational similarities and possible shared ecosystems while explicitly keeping the connection unconfirmed. Defenders can correlate behaviors without collapsing separate names into one attribution.[3]

Bottom Line Up Front

BLUF

Coverage periodJul 29, 2025Jul 28, 2026365 calendar days, inclusiveUpdated Jul 28, 2026
  • Payments became less frequent but materially larger when victims paid: Arete reports a 31% Q1 2026 payment rate, down from 33% in Q1 2025, while the median payment rose from $100,000 to $250,000. The Q1 median demand was $571,000. Lower payment frequency therefore did not reduce the financial severity of the paid cases in Arete's engagement population.[2]Evidence dated Jun 3, 2026

  • Akira and Qilin produced almost one-third of Arete's Q1 engagements: Akira represented 18.3% and Qilin 14.3% of Q1 activity in Arete's chart. Their combined share remained important but declined from more than half in each of Q3 and Q4 2025, showing concentration easing without eliminating either actor as a priority.[2]Evidence dated Jun 3, 2026

  • Akira combined high volume with unusually strong payment conversion: Arete reports Akira median demands of $700,000, median payments of $300,000, and payment in almost 48% of Akira engagements. More than half of those paying victims purchased data suppression without a decryptor, showing that stolen-data pressure can drive payment even when recovery is not the objective.[2]Evidence dated Jun 3, 2026

  • Professional services led a broad, access-driven victim population: Professional, scientific, and technical services accounted for 21.6% of Arete engagements, followed by manufacturing at 13.6%, wholesale trade at 10.4%, healthcare and social assistance at 8.8%, retail at 8.0%, and construction at 7.2%. Arete assesses most groups as opportunistic and access-vector-driven rather than sector-exclusive.[2]Evidence dated Jun 3, 2026

  • Edge exploitation, compromised credentials, and social engineering formed the Q1 access triad: Arete identifies vulnerability exploits, compromised credentials, and social engineering as the leading initial-access classes. Firewalls and VPN systems concentrate risk because they are internet-facing, authentication-connected, and capable of exposing internal enterprise access after compromise.[2]Evidence dated Jun 3, 2026

  • Teams impersonation, device-code abuse, and ClickFix moved social engineering beyond ordinary phishing: Arete observed renewed cross-tenant Microsoft Teams help-desk impersonation, OAuth and Quick Assist workflows, and ClickFix campaigns across Windows and macOS. Akira, INC Ransom, Payouts King, and Chaos used Teams-style tactics, while Akira, Qilin, and Interlock adopted ClickFix.[2]Evidence dated Jun 3, 2026

Decision Context

Executive Summary

Coverage periodJul 29, 2025Jul 28, 2026365 calendar days, inclusiveUpdated Jul 28, 2026

Across the full rolling year, Arete's evidence shows both persistence and rotation. Akira rose from 32.1% of July engagements to 52.9% in August, led full-year 2025 at 28.4%, then fell to 18.3% in Q1 2026; Qilin remained consistently important and overtook Akira in April. That movement argues for maintaining proven playbooks for durable operators while using access behavior—not a monthly brand ranking—as the primary organizing principle.[9][10][17][2][19]First cited source Sep 8, 2025 · Latest cited source Jun 3, 2026

Arete's Q1 2026 Crimeware Report is the strongest source in this edition because it combines first-hand ransomware and extortion response, forensics, restoration, threat hunting, actor communications, and malware analysis. Its statistics include only incidents where a victim was extorted, with or without encryption; pre-ransomware disruptions do not enter the totals. The sample is weighted toward cyber-insured organizations, so the findings are a decision-quality view of Arete's casework—not a global ransomware census.[2]Evidence dated Jun 3, 2026

The actor landscape was concentrated but not monopolized. Akira accounted for 18.3% and Qilin 14.3% of Q1 engagements, down from a combined majority in the prior two quarters. Akira, Qilin, PLAY, and INC Ransom nevertheless remained in Arete's top five in every quarter since the second half of 2025. The operational lesson is to maintain durable playbooks for established groups while watching new brands such as NightSpire, BravoX, and Schrodinger Cat for credible shifts in access, tooling, and affiliate adoption.[2]Evidence dated Jun 3, 2026

Payment economics moved in opposite directions. Arete's Q1 payment rate fell slightly to 31%, yet the median paid amount rose to $250,000 from $100,000 a year earlier; the median demand was $571,000. Akira was more effective than the portfolio average, with a $700,000 median demand, $300,000 median payment, and payment in almost 48% of engagements. More than half of paying Akira victims bought data suppression without a decryptor, demonstrating that exfiltration can retain leverage even when operations are recoverable.[2]Evidence dated Jun 3, 2026

Victimology supports an access-first interpretation. Professional, scientific, and technical services led at 21.6%, followed by manufacturing, wholesale trade, healthcare, retail, and construction. Arete characterizes most active groups as opportunistic, exploiting reachable edge products, credentials, and human workflows rather than selecting one sector. Sector controls should therefore start with externally reachable technology, identity exposure, trusted service providers, and recovery dependence, then account for sector-specific interruption and data consequences.[2]Evidence dated Jun 3, 2026

Initial access is converging across vulnerabilities, identity, and social engineering. Arete documents Fortinet, WatchGuard, and BeyondTrust exploitation; credentials obtained through brute force, reuse, and infostealers; Teams help-desk impersonation; OAuth and device-code abuse; Quick Assist; and ClickFix lures on Windows and macOS. These methods exploit systems and workflows that look legitimate, so prevention and detection must extend beyond malware signatures to authentication path, session behavior, external collaboration, driver loading, and user-directed command execution.[2]Evidence dated Jun 3, 2026

Later Arete publications show how the Q1 baseline evolved. FortiBleed connects edge credential harvesting to possible ransomware follow-on activity; Helix moves extortion into Microsoft 365 identity and SharePoint; Klue demonstrates downstream SaaS-token exposure; BYOVD targets endpoint defenses; and AudiA6 illustrates the laundering infrastructure supporting monetization. These updates are most useful when interpreted against the report's case-derived access and actor baseline.[3][4][5][6][7]First cited source Jun 23, 2026 · Latest cited source Jul 17, 2026

Arete's AI conclusion requires precision. The Q1 report describes AI accelerating stolen-data analysis, victim prioritization, personalized deception, and ransom strategy, but says most current adversarial use remains generative rather than agentic. Later Arete analysis adds AI-assisted development and EDR testing without showing an autonomous operator inside a victim. Executives should secure AI inputs and data flows while improving identity, edge, SaaS, endpoint-tamper, evidence-retention, and recovery controls that address the observed attack paths today.[2][8]First cited source Jun 3, 2026 · Latest cited source Jun 12, 2026

Executive Briefing Priorities

Top 10 Briefing Points

  1. 1

    Payments became less frequent but materially larger when victims paidArete reports a 31% Q1 2026 payment rate, down from 33% in Q1 2025, while the median payment rose from $100,000 to $250,000. The Q1 median demand was $571,000. Lower payment frequency therefore did not reduce the financial severity of the paid cases in Arete's engagement population.[2]Evidence dated Jun 3, 2026

  2. 2

    Akira and Qilin produced almost one-third of Arete's Q1 engagementsAkira represented 18.3% and Qilin 14.3% of Q1 activity in Arete's chart. Their combined share remained important but declined from more than half in each of Q3 and Q4 2025, showing concentration easing without eliminating either actor as a priority.[2]Evidence dated Jun 3, 2026

  3. 3

    Akira combined high volume with unusually strong payment conversionArete reports Akira median demands of $700,000, median payments of $300,000, and payment in almost 48% of Akira engagements. More than half of those paying victims purchased data suppression without a decryptor, showing that stolen-data pressure can drive payment even when recovery is not the objective.[2]Evidence dated Jun 3, 2026

  4. 4

    Professional services led a broad, access-driven victim populationProfessional, scientific, and technical services accounted for 21.6% of Arete engagements, followed by manufacturing at 13.6%, wholesale trade at 10.4%, healthcare and social assistance at 8.8%, retail at 8.0%, and construction at 7.2%. Arete assesses most groups as opportunistic and access-vector-driven rather than sector-exclusive.[2]Evidence dated Jun 3, 2026

  5. 5

    Edge exploitation, compromised credentials, and social engineering formed the Q1 access triadArete identifies vulnerability exploits, compromised credentials, and social engineering as the leading initial-access classes. Firewalls and VPN systems concentrate risk because they are internet-facing, authentication-connected, and capable of exposing internal enterprise access after compromise.[2]Evidence dated Jun 3, 2026

  6. 6

    Teams impersonation, device-code abuse, and ClickFix moved social engineering beyond ordinary phishingArete observed renewed cross-tenant Microsoft Teams help-desk impersonation, OAuth and Quick Assist workflows, and ClickFix campaigns across Windows and macOS. Akira, INC Ransom, Payouts King, and Chaos used Teams-style tactics, while Akira, Qilin, and Interlock adopted ClickFix.[2]Evidence dated Jun 3, 2026

  7. 7

    Fortinet, WatchGuard, and BeyondTrust weaknesses were operational entry paths—not inventory triviaThe report documents Fortinet authentication bypass and older-flaw exploitation, Qilin exploitation of WatchGuard CVE-2025-14733, and Arete-confirmed exploitation of BeyondTrust CVE-2026-1731 linked to a Medusa-associated cluster. Edge remediation must pair patching with access review and hunting.[2]Evidence dated Jun 3, 2026

  8. 8

    The top tier remained stable even as new ransomware brands emergedAkira, Qilin, PLAY, and INC Ransom remained among Arete's top five groups in every quarter since the second half of 2025. NightSpire posted more than 100 Q1 disclosures, BravoX posted nine while building credibility, and Schrodinger Cat formalized its brand, but established operators still drove most handled activity.[2]Evidence dated Jun 3, 2026

  9. 9

    DragonForce's cartel model and leaked-code reuse lower the cost of operational changeArete describes DragonForce shifting toward a decentralized partnership model and identifies Conti-derived implementation overlap. Its appendix reports identical ChaCha-like encryption logic, shared command-line behavior, a common mutex, and 99% BinDiff similarity between compared 32-bit DragonForce and Devman samples.[2]Evidence dated Jun 3, 2026

  10. 10

    Most adversarial AI use remained generative and assistive—not autonomousArete observed AI accelerating stolen-data analysis, victim prioritization, social engineering, and extortion strategy, while its outlook says most current use remained generative rather than agentic. Defenders should act on measurable workflow acceleration without claiming autonomous intrusions the evidence does not establish.[2]Evidence dated Jun 3, 2026

  11. 11

    Later Arete analysis sharpened how AI shortens malware development and EDR testingArete describes threat actors using agent-based AI workflows for Active Directory discovery, iterative development, lab reproduction, and evasion testing. It found no evidence that AI was embedded as an autonomous operator inside victim environments.[8]Evidence dated Jun 12, 2026

  12. 12

    AudiA6 shows ransomware depends on professional laundering infrastructureArete's account of the Europol-backed action describes arrests, more than 30 servers, 25 domains, and over €778,000 in frozen or seized cryptocurrency. Financial services, mule accounts, and marketplace infrastructure belong in the ransomware ecosystem map.[7]Evidence dated Jun 23, 2026

  13. 13

    FortiBleed is a credential-compromise problem, not a patch-only problemArete's update describes password spraying, configuration exfiltration, packet sniffing, and harvested credentials affecting more than 86,000 devices across 194 countries. Credential resets, historical log review, management-plane restriction, and hunting are required alongside fixes.[6]Evidence dated Jun 30, 2026

  14. 14

    June activity remained distributed despite Akira leading Arete's observationsArete identified 17 unique groups during June and kept Akira, Qilin, and INC Ransom among the most active. The decision is to maintain a behavior-led watchlist instead of anchoring response plans to one brand.[5]Evidence dated Jul 6, 2026

  15. 15

    BYOVD is being used to disable or evade endpoint defensesArete reports Akira and DragonForce using vulnerable drivers in engagements and describes GentleKiller as a framework targeting multiple security products. Driver loading and security-control tampering should be high-priority detection events.[5]Evidence dated Jul 6, 2026

  16. 16

    OAuth tokens can propagate one provider breach into many customer environmentsArete's June review uses the Klue incident to show how stolen Salesforce integration tokens can extend an intrusion through trusted SaaS relationships. Token inventory, revocation, and connected-app telemetry are incident-response requirements.[5]Evidence dated Jul 6, 2026

  17. 17

    FortiBleed links stolen edge credentials to INC and Lynx operationsArete reports evidence connecting the credential-harvesting campaign to INC and Lynx ransomware operations, including a shared operator and exposed workflow infrastructure. Organizations with affected FortiGate history should investigate credentials and administrative activity even after patching.[4][6]First cited source Jun 30, 2026 · Latest cited source Jul 14, 2026

  18. 18

    Helix makes Microsoft 365 identity the extortion perimeterArete describes Helix using vishing, device-code phishing, MFA abuse, and trusted-person impersonation to reach SharePoint Online and exfiltrate data. The practical control boundary is the identity session and cloud application—not only the endpoint.[3]Evidence dated Jul 17, 2026

  19. 19

    Helix may overlap ShinyHunters and BlackFile ecosystems, but the relationship is unresolvedArete notes operational similarities and possible shared ecosystems while explicitly keeping the connection unconfirmed. Defenders can correlate behaviors without collapsing separate names into one attribution.[3]Evidence dated Jul 17, 2026

  20. 20

    Akira entered the window as the clear volume leader, but not as a monopolyArete's Q3 report assigns Akira 32.1% of July engagements, followed by Qilin at 11.3% and Sinobi at 9.4%. The opening month already supports a multi-actor playbook even before Akira's August surge.[9]Evidence dated Dec 3, 2025

  21. 21

    Akira rose above half of Arete's August engagementsAkira reached 52.9% in August, while Qilin represented 15.3% and PLAY 5.9%. Arete tied the spike partly to exploitation and legacy credentials around SonicWall environments, making edge history and credential hygiene central response questions.[9][10]First cited source Sep 8, 2025 · Latest cited source Dec 3, 2025

  22. 22

    Salesloft Drift token theft turned a trusted integration into downstream accessArete's Q3 analysis describes theft of Salesforce OAuth and refresh tokens associated with the Salesloft Drift campaign. Connected-app inventory, token revocation, and downstream log review are necessary when a SaaS provider is compromised.[9][10]First cited source Sep 8, 2025 · Latest cited source Dec 3, 2025

  23. 23

    CL0P began an Oracle EBS extortion wave tied to CVE-2025-61882Arete records extortion emails beginning on 29 September following exploitation of Oracle E-Business Suite. The sequence demonstrates why application remediation must include retrospective data-access review and preparation for delayed extortion contact.[9]Evidence dated Dec 3, 2025

  24. 24

    Akira receded while PLAY and World Leaks gained shareArete's Q3 report places Akira at 36.6%, Qilin at 11.3%, and both PLAY and World Leaks at 7.0% in September. Extortion-only operations became a larger part of the visible mix even as the leading ransomware brands persisted.[9][11]First cited source Oct 6, 2025 · Latest cited source Dec 3, 2025

  25. 25

    Edge exploitation and SaaS extortion were active at the same timeArete kept Akira and Qilin among October's leaders while tracking CL0P's Oracle EBS campaign and the Scattered Lapsus$ Hunters/Salesloft activity. Response planning must cover appliance compromise, enterprise applications, and trusted cloud integrations concurrently.[12]Evidence dated Nov 7, 2025

  26. 26

    Operation Endgame removed infrastructure at scale without ending the crimeware marketArete's account of Season 3 attributes more than 1,000 server disruptions, 20 seized domains, an operator arrest, and millions of stolen credentials to the coordinated action. The takedown imposed cost, but Arete did not treat it as proof that ransomware access supply had stopped.[13]Evidence dated Nov 21, 2025

  27. 27

    Akira led 2025, but Arete still observed a fragmented operator ecosystemArete's annual report places Akira at 28.4% and Qilin at 12.8% across 81 named and 52 unnamed actor labels. Akira's Q3 surge mattered, but the number of labels shows why a durable defense cannot depend on a single-brand watchlist.[17]Evidence dated Mar 27, 2026

  28. 28

    Akira exceeded one-third of December activity as RansomHouse returnedArete reports Akira above one-third of December observations and the top three groups at 57%, alongside RansomHouse's return and emerging React2Shell and MongoBleed exposure. Actor concentration and fast-moving vulnerability response were linked operational concerns.[14][17]First cited source Jan 12, 2026 · Latest cited source Mar 27, 2026

  29. 29

    The top three fell to 34% as LockBit 5 and ClickFix entered the watchlistArete identified 17 groups in January, with Akira at 17% and the top three representing only about one-third. LockBit 5 activity and ClickFix/CrashFix social engineering reinforced the need to follow behaviors across changing brands.[15]Evidence dated Feb 5, 2026

  30. 30

    Akira and Qilin again approached half of activity while access paths diversifiedArete's February review places Akira and Qilin at nearly half of observations and highlights Qilin exploitation of WatchGuard CVE-2025-14733 plus Hotta Killer BYOVD activity. Edge remediation and protection against security-driver tampering belong in the same program.[16]Evidence dated Mar 9, 2026

  31. 31

    Twenty-one groups diluted the leading brands and widened the response burdenArete observed 21 groups in March versus 15 in February, with Akira and Qilin falling from nearly half to just over one-quarter. FortiGate exploitation and Teams/Quick Assist social engineering show that actor-share changes do not simplify the access problem.[18]Evidence dated Apr 6, 2026

  32. 32

    Qilin overtook Akira while four groups generated about half of activityArete reports Qilin moving ahead of Akira in April, with Akira, Qilin, INC Ransom, and DragonForce together accounting for roughly half. DragonForce's rise and continued BYOVD use show both concentration and tactical adaptation.[19]Evidence dated May 4, 2026

  33. 33

    Fake JPEG delivery concealed PowerShell and remote-management accessArete describes attackers using a fake image workflow to execute PowerShell and deploy a trojanized ScreenConnect path. File extension, content, user action, script execution, and remote-tool behavior must be correlated.[21]Evidence dated May 26, 2026

  34. 34

    A Ghost CMS flaw exposed more than 700 sites to ClickFix deliveryArete's research connects CVE-2026-26980 exploitation across education and technology sites to a ClickFix campaign. A compromised website can become social-engineering infrastructure even when the visitor is not the original intrusion target.[20]Evidence dated May 29, 2026

Source-Bound Exposure and Targeting

Victimology Matrix

This is not a raw victim list. Publicly named organizations are shown when reliable sources identify them, with confirmation and attribution boundaries preserved. Where no defensible name exists, IntelliOS uses the narrowest supported exposure population. Sector or geography matches remain scoping signals; they do not prove compromise.

Victim / exposure populationProfessional, scientific, and technical services[2]Evidence dated Jun 3, 2026SectorsNAICS professional, scientific, and technical servicesGeographyArete Q1 engagement populationConfirmation status21.6% of Arete engagements; cyber-insured casework sampleHow companies should use itProtect client data, privileged SaaS, remote administration, professional credentials, and time-sensitive delivery systems.
Victim / exposure populationManufacturing organizations[2]Evidence dated Jun 3, 2026SectorsManufacturingGeographyArete Q1 engagement populationConfirmation status13.6% of engagementsHow companies should use itSegment production, validate identity and edge access, preserve manual operations, and test recovery without trusted-domain availability.
Victim / exposure populationWholesale trade organizations[2]Evidence dated Jun 3, 2026SectorsWholesale tradeGeographyArete Q1 engagement populationConfirmation status10.4% of engagementsHow companies should use itProtect warehouse, logistics, payment, supplier, and customer-integrated workflows from interruption and fraud.
Victim / exposure populationHealthcare and social-assistance organizations[2]Evidence dated Jun 3, 2026SectorsHealthcare and social assistanceGeographyArete Q1 engagement populationConfirmation status8.8% of engagementsHow companies should use itPrioritize care continuity, regulated-data exposure, identity, vendor access, and downtime decision authority.
Victim / exposure populationRetail and construction organizations[2]Evidence dated Jun 3, 2026SectorsRetail trade; constructionGeographyArete Q1 engagement populationConfirmation status8.0% retail and 7.2% constructionHow companies should use itSecure distributed identities, payments, remote sites, contractors, VPN access, and recovery-critical cloud services.
Victim / exposure populationMicrosoft 365 and SharePoint users[3]Evidence dated Jul 17, 2026SectorsCross-industryGeographyNot bounded by Arete to one regionConfirmation statusTargeting and method reported; individual victim claims require verificationHow companies should use itPrioritize vishing-resistant help-desk controls, device-code restrictions, session review, and SharePoint exfiltration telemetry.
Victim / exposure populationInternet-facing FortiGate and SSL-VPN operators[4][5][6]First cited source Jun 30, 2026 · Latest cited source Jul 14, 2026SectorsCross-industry, including managed and distributed environmentsGeography194 countries in cited exposure reportingConfirmation statusExposure and credential collection do not prove downstream intrusionHow companies should use itReset credentials, review historical administrative access, restrict management interfaces, and investigate configuration changes.
Victim / exposure populationSaaS customers connected through trusted integrations[5]Evidence dated Jul 6, 2026SectorsTechnology, professional services, data-rich organizationsGeographyGlobalConfirmation statusKlue disclosed an incident; downstream scope remains company-specificHow companies should use itInventory OAuth grants and third-party applications, revoke affected tokens, and retain audit logs.
Victim / exposure populationOrganizations dependent on endpoint security controls[2][5][8]First cited source Jun 3, 2026 · Latest cited source Jul 6, 2026SectorsCross-industryGeographyGlobalConfirmation statusArete reports BYOVD observations in engagementsHow companies should use itBlock vulnerable drivers and alert on security-service disablement, kernel-driver loading, and policy tampering.

Distinct Operational Records

Arete Research Themes & Operations

Akira's high-conversion ransomware operation

Akira led Arete's Q1 activity at 18.3%, carried a $700,000 median demand and $300,000 median payment, and received payment in almost 48% of engagements. More than half of paying victims purchased data suppression without a decryptor.[2]Evidence dated Jun 3, 2026

Qilin exploitation of WatchGuard Firebox

Arete observed Qilin exploiting WatchGuard CVE-2025-14733 in Q1 to gain initial access and facilitate ransomware deployment.[2]Evidence dated Jun 3, 2026

Cross-tenant Teams help-desk impersonation

Akira, INC Ransom, Payouts King, and Chaos used refined Teams interactions, email bombing, OAuth flows, and Quick Assist to turn trusted collaboration into initial access.[2]Evidence dated Jun 3, 2026

ClickFix, CrashFix, and InstallFix evolution

Arete describes urgent fake prompts, browser crashes, sponsored malicious installers, Python RAT delivery, infostealers, and expanded Windows/macOS targeting adopted by Akira, Qilin, and Interlock.[2]Evidence dated Jun 3, 2026

FortiBleed credential harvesting

Password spraying, configuration theft, packet sniffing, credential reuse, and possible ransomware follow-on activity.[4][6]First cited source Jun 30, 2026 · Latest cited source Jul 14, 2026

Helix SharePoint extortion

Vishing and device-code phishing provide cloud access followed by SharePoint discovery and data theft.[3]Evidence dated Jul 17, 2026

June ransomware operations

Akira led a distributed field that also included Qilin, INC Ransom, KryBit, Settra, and Icarus in Arete's observations.[5]Evidence dated Jul 6, 2026

AudiA6 financial infrastructure

A law-enforcement action targeted laundering, servers, domains, and mule-account infrastructure supporting cybercrime monetization.[7]Evidence dated Jun 23, 2026

Source-Bound Actor Context

Threat Actors, Operators & Decision Owners

Akira

Arete's leading Q1 actor at 18.3% of engagements, with unusually high payment conversion and later BYOVD observations. Activity normalized from its Q3 2025 surge but remained the largest monthly share through Q1.[2][5]First cited source Jun 3, 2026 · Latest cited source Jul 6, 2026

Qilin

Second in Q1 at 14.3%; Arete observed a February increase tied to WatchGuard Firebox targeting, especially CVE-2025-14733.[2][5]First cited source Jun 3, 2026 · Latest cited source Jul 6, 2026

PLAY

Represented 7.1% of Q1 engagements and remained a top-five group since the second half of 2025, yet collected payment in only 11% of Arete engagements.[2]Evidence dated Jun 3, 2026

DragonForce

Represented 5.6% of Q1 activity. Arete describes a cartel-style affiliate model, Conti-derived code overlap, zero Q1 payments in its engagements, and later BYOVD use.[2][5]First cited source Jun 3, 2026 · Latest cited source Jul 6, 2026

INC Ransom and Lynx

Arete reports operational and malware-lineage connections relevant to FortiBleed follow-on risk.[4]Evidence dated Jul 14, 2026

NightSpire

Emerging operator that posted more than 100 Q1 victim disclosures; Arete describes evidence suggesting an Rbfs rebrand, but leak-site counts remain actor claims rather than incident totals.[2]Evidence dated Jun 3, 2026

BravoX

Early-stage RaaS brand that posted nine Q1 victims while building a standalone leak platform and seeking credibility; future affiliate traction remained uncertain.[2]Evidence dated Jun 3, 2026

Schrodinger Cat

GlobeImposter-associated subgroup formalizing its brand and leak site while focusing on enterprise encryption and extortion.[2]Evidence dated Jun 3, 2026

Helix

Newly reported identity-led extortion group focused on Microsoft 365 and SharePoint data.[3]Evidence dated Jul 17, 2026

DragonForce and The Gentlemen

Appear in Arete's discussion of BYOVD and EDR-disabling tradecraft.[5]Evidence dated Jul 6, 2026

Enterprise Exposure

Affected Technologies & Trust Boundaries

Fortinet FortiGate and FortiCloud SSO

Arete highlights authentication-bypass, pre-authentication, older unpatched flaws, brute force, credential reuse, infostealer datasets, and secondary RDP access as a combined edge-risk problem.[2][4][5][6]First cited source Jun 3, 2026 · Latest cited source Jul 14, 2026

WatchGuard Firebox and Fireware OS

CVE-2025-14733 and CVE-2025-9242 created unauthenticated RCE risk in edge infrastructure; Arete observed Qilin incorporating WatchGuard exploitation into intrusion workflows.[2]Evidence dated Jun 3, 2026

BeyondTrust Remote Support and Privileged Remote Access

Arete confirmed Q1 exploitation of CVE-2026-1731 with reverse shells and post-exploitation tooling and linked the activity to a Medusa-associated cluster.[2]Evidence dated Jun 3, 2026

Microsoft Teams, OAuth, device code, and Quick Assist

Cross-tenant messaging and legitimate assistance/authentication workflows let attackers impersonate support staff and establish identity-backed access.[2][3]First cited source Jun 3, 2026 · Latest cited source Jul 17, 2026

Windows, macOS, browsers, and terminal workflows

ClickFix variants use fake CAPTCHAs, browser crashes, troubleshooting prompts, sponsored installers, and clipboard-driven commands across platforms.[2]Evidence dated Jun 3, 2026

FortiGate and SSL-VPN

Treat prior credential exposure and configuration access as an investigation trigger, not only a patch task.[4][5][6]First cited source Jun 30, 2026 · Latest cited source Jul 14, 2026

Microsoft 365 and SharePoint Online

Device-code phishing, session abuse, and automated data exfiltration move the control plane into cloud identity.[3]Evidence dated Jul 17, 2026

OAuth-connected SaaS platforms

Stolen integration tokens can create downstream customer impact without exploiting each customer directly.[5]Evidence dated Jul 6, 2026

Endpoint drivers and EDR controls

Vulnerable-driver abuse and AI-assisted testing target the reliability of endpoint defenses.[2][5][8]First cited source Jun 3, 2026 · Latest cited source Jul 6, 2026

Conti, DragonForce, and Devman ransomware code

Arete's appendix documents shared encryption, hashing, command-line, mutex, SMB propagation, and decryption characteristics while distinguishing newer Devman divergence.[2]Evidence dated Jun 3, 2026

Current Carry-Forward Watchlist

Top 10 Specific Threats to Monitor

Prioritized source-backed developments that convert the rolling activity record into named operational monitoring requirements.

1Threat / Category

Q1 observation · ransom economics

Payments became less frequent but materially larger when victims paid[2]Evidence dated Jun 3, 2026

Why it mattersArete reports a 31% Q1 2026 payment rate, down from 33% in Q1 2025, while the median payment rose from $100,000 to $250,000. The Q1 median demand was $571,000. Lower payment frequency therefore did not reduce the financial severity of the paid cases in Arete's engagement population.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
2Threat / Category

Q1 observation · actor concentration

Akira and Qilin produced almost one-third of Arete's Q1 engagements[2]Evidence dated Jun 3, 2026

Why it mattersAkira represented 18.3% and Qilin 14.3% of Q1 activity in Arete's chart. Their combined share remained important but declined from more than half in each of Q3 and Q4 2025, showing concentration easing without eliminating either actor as a priority.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
3Threat / Category

Q1 observation · payment leverage

Akira combined high volume with unusually strong payment conversion[2]Evidence dated Jun 3, 2026

Why it mattersArete reports Akira median demands of $700,000, median payments of $300,000, and payment in almost 48% of Akira engagements. More than half of those paying victims purchased data suppression without a decryptor, showing that stolen-data pressure can drive payment even when recovery is not the objective.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
4Threat / Category

Q1 observation · victimology

Professional services led a broad, access-driven victim population[2]Evidence dated Jun 3, 2026

Why it mattersProfessional, scientific, and technical services accounted for 21.6% of Arete engagements, followed by manufacturing at 13.6%, wholesale trade at 10.4%, healthcare and social assistance at 8.8%, retail at 8.0%, and construction at 7.2%. Arete assesses most groups as opportunistic and access-vector-driven rather than sector-exclusive.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
5Threat / Category

Q1 observation · initial access

Edge exploitation, compromised credentials, and social engineering formed the Q1 access triad[2]Evidence dated Jun 3, 2026

Why it mattersArete identifies vulnerability exploits, compromised credentials, and social engineering as the leading initial-access classes. Firewalls and VPN systems concentrate risk because they are internet-facing, authentication-connected, and capable of exposing internal enterprise access after compromise.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
6Threat / Category

Q1 observation · identity-first intrusion

Teams impersonation, device-code abuse, and ClickFix moved social engineering beyond ordinary phishing[2]Evidence dated Jun 3, 2026

Why it mattersArete observed renewed cross-tenant Microsoft Teams help-desk impersonation, OAuth and Quick Assist workflows, and ClickFix campaigns across Windows and macOS. Akira, INC Ransom, Payouts King, and Chaos used Teams-style tactics, while Akira, Qilin, and Interlock adopted ClickFix.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
7Threat / Category

Q1 observation · edge vulnerabilities

Fortinet, WatchGuard, and BeyondTrust weaknesses were operational entry paths—not inventory trivia[2]Evidence dated Jun 3, 2026

Why it mattersThe report documents Fortinet authentication bypass and older-flaw exploitation, Qilin exploitation of WatchGuard CVE-2025-14733, and Arete-confirmed exploitation of BeyondTrust CVE-2026-1731 linked to a Medusa-associated cluster. Edge remediation must pair patching with access review and hunting.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
8Threat / Category

Q1 observation · actor persistence

The top tier remained stable even as new ransomware brands emerged[2]Evidence dated Jun 3, 2026

Why it mattersAkira, Qilin, PLAY, and INC Ransom remained among Arete's top five groups in every quarter since the second half of 2025. NightSpire posted more than 100 Q1 disclosures, BravoX posted nine while building credibility, and Schrodinger Cat formalized its brand, but established operators still drove most handled activity.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
9Threat / Category

Q1 observation · RaaS evolution

DragonForce's cartel model and leaked-code reuse lower the cost of operational change[2]Evidence dated Jun 3, 2026

Why it mattersArete describes DragonForce shifting toward a decentralized partnership model and identifies Conti-derived implementation overlap. Its appendix reports identical ChaCha-like encryption logic, shared command-line behavior, a common mutex, and 99% BinDiff similarity between compared 32-bit DragonForce and Devman samples.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
10Threat / Category

Q1 observation · AI evidence boundary

Most adversarial AI use remained generative and assistive—not autonomous[2]Evidence dated Jun 3, 2026

Why it mattersArete observed AI accelerating stolen-data analysis, victim prioritization, social engineering, and extortion strategy, while its outlook says most current use remained generative rather than agentic. Defenders should act on measurable workflow acceleration without claiming autonomous intrusions the evidence does not establish.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
11Threat / Category

AI-assisted offense

Later Arete analysis sharpened how AI shortens malware development and EDR testing[8]Evidence dated Jun 12, 2026

Why it mattersArete describes threat actors using agent-based AI workflows for Active Directory discovery, iterative development, lab reproduction, and evasion testing. It found no evidence that AI was embedded as an autonomous operator inside victim environments.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
12Threat / Category

Criminal infrastructure disruption

AudiA6 shows ransomware depends on professional laundering infrastructure[7]Evidence dated Jun 23, 2026

Why it mattersArete's account of the Europol-backed action describes arrests, more than 30 servers, 25 domains, and over €778,000 in frozen or seized cryptocurrency. Financial services, mule accounts, and marketplace infrastructure belong in the ransomware ecosystem map.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
13Threat / Category

Credential exposure

FortiBleed is a credential-compromise problem, not a patch-only problem[6]Evidence dated Jun 30, 2026

Why it mattersArete's update describes password spraying, configuration exfiltration, packet sniffing, and harvested credentials affecting more than 86,000 devices across 194 countries. Credential resets, historical log review, management-plane restriction, and hunting are required alongside fixes.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
14Threat / Category

June observation · crimeware trend

June activity remained distributed despite Akira leading Arete's observations[5]Evidence dated Jul 6, 2026

Why it mattersArete identified 17 unique groups during June and kept Akira, Qilin, and INC Ransom among the most active. The decision is to maintain a behavior-led watchlist instead of anchoring response plans to one brand.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
15Threat / Category

June observation · trusted software abuse

BYOVD is being used to disable or evade endpoint defenses[5]Evidence dated Jul 6, 2026

Why it mattersArete reports Akira and DragonForce using vulnerable drivers in engagements and describes GentleKiller as a framework targeting multiple security products. Driver loading and security-control tampering should be high-priority detection events.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
16Threat / Category

June observation · SaaS supply chain

OAuth tokens can propagate one provider breach into many customer environments[5]Evidence dated Jul 6, 2026

Why it mattersArete's June review uses the Klue incident to show how stolen Salesforce integration tokens can extend an intrusion through trusted SaaS relationships. Token inventory, revocation, and connected-app telemetry are incident-response requirements.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
17Threat / Category

Ransomware access ecosystem

FortiBleed links stolen edge credentials to INC and Lynx operations[4][6]First cited source Jun 30, 2026 · Latest cited source Jul 14, 2026

Why it mattersArete reports evidence connecting the credential-harvesting campaign to INC and Lynx ransomware operations, including a shared operator and exposed workflow infrastructure. Organizations with affected FortiGate history should investigate credentials and administrative activity even after patching.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
18Threat / Category

Identity-led extortion

Helix makes Microsoft 365 identity the extortion perimeter[3]Evidence dated Jul 17, 2026

Why it mattersArete describes Helix using vishing, device-code phishing, MFA abuse, and trusted-person impersonation to reach SharePoint Online and exfiltrate data. The practical control boundary is the identity session and cloud application—not only the endpoint.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
19Threat / Category

Actor identity boundary

Helix may overlap ShinyHunters and BlackFile ecosystems, but the relationship is unresolved[3]Evidence dated Jul 17, 2026

Why it mattersArete notes operational similarities and possible shared ecosystems while explicitly keeping the connection unconfirmed. Defenders can correlate behaviors without collapsing separate names into one attribution.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
20Threat / Category

July observation · actor concentration

Akira entered the window as the clear volume leader, but not as a monopoly[9]Evidence dated Dec 3, 2025

Why it mattersArete's Q3 report assigns Akira 32.1% of July engagements, followed by Qilin at 11.3% and Sinobi at 9.4%. The opening month already supports a multi-actor playbook even before Akira's August surge.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
21Threat / Category

August observation · actor surge

Akira rose above half of Arete's August engagements[9][10]First cited source Sep 8, 2025 · Latest cited source Dec 3, 2025

Why it mattersAkira reached 52.9% in August, while Qilin represented 15.3% and PLAY 5.9%. Arete tied the spike partly to exploitation and legacy credentials around SonicWall environments, making edge history and credential hygiene central response questions.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
22Threat / Category

August observation · SaaS supply chain

Salesloft Drift token theft turned a trusted integration into downstream access[9][10]First cited source Sep 8, 2025 · Latest cited source Dec 3, 2025

Why it mattersArete's Q3 analysis describes theft of Salesforce OAuth and refresh tokens associated with the Salesloft Drift campaign. Connected-app inventory, token revocation, and downstream log review are necessary when a SaaS provider is compromised.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
23Threat / Category

September observation · enterprise extortion

CL0P began an Oracle EBS extortion wave tied to CVE-2025-61882[9]Evidence dated Dec 3, 2025

Why it mattersArete records extortion emails beginning on 29 September following exploitation of Oracle E-Business Suite. The sequence demonstrates why application remediation must include retrospective data-access review and preparation for delayed extortion contact.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
24Threat / Category

September observation · actor mix

Akira receded while PLAY and World Leaks gained share[9][11]First cited source Oct 6, 2025 · Latest cited source Dec 3, 2025

Why it mattersArete's Q3 report places Akira at 36.6%, Qilin at 11.3%, and both PLAY and World Leaks at 7.0% in September. Extortion-only operations became a larger part of the visible mix even as the leading ransomware brands persisted.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
25Threat / Category

October observation · parallel campaigns

Edge exploitation and SaaS extortion were active at the same time[12]Evidence dated Nov 7, 2025

Why it mattersArete kept Akira and Qilin among October's leaders while tracking CL0P's Oracle EBS campaign and the Scattered Lapsus$ Hunters/Salesloft activity. Response planning must cover appliance compromise, enterprise applications, and trusted cloud integrations concurrently.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
26Threat / Category

Law-enforcement action · malware infrastructure

Operation Endgame removed infrastructure at scale without ending the crimeware market[13]Evidence dated Nov 21, 2025

Why it mattersArete's account of Season 3 attributes more than 1,000 server disruptions, 20 seized domains, an operator arrest, and millions of stolen credentials to the coordinated action. The takedown imposed cost, but Arete did not treat it as proof that ransomware access supply had stopped.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
27Threat / Category

Full-year observation · actor landscape

Akira led 2025, but Arete still observed a fragmented operator ecosystem[17]Evidence dated Mar 27, 2026

Why it mattersArete's annual report places Akira at 28.4% and Qilin at 12.8% across 81 named and 52 unnamed actor labels. Akira's Q3 surge mattered, but the number of labels shows why a durable defense cannot depend on a single-brand watchlist.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
28Threat / Category

December observation · renewed concentration

Akira exceeded one-third of December activity as RansomHouse returned[14][17]First cited source Jan 12, 2026 · Latest cited source Mar 27, 2026

Why it mattersArete reports Akira above one-third of December observations and the top three groups at 57%, alongside RansomHouse's return and emerging React2Shell and MongoBleed exposure. Actor concentration and fast-moving vulnerability response were linked operational concerns.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
29Threat / Category

January observation · broader actor mix

The top three fell to 34% as LockBit 5 and ClickFix entered the watchlist[15]Evidence dated Feb 5, 2026

Why it mattersArete identified 17 groups in January, with Akira at 17% and the top three representing only about one-third. LockBit 5 activity and ClickFix/CrashFix social engineering reinforced the need to follow behaviors across changing brands.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
30Threat / Category

February observation · edge and endpoint defense

Akira and Qilin again approached half of activity while access paths diversified[16]Evidence dated Mar 9, 2026

Why it mattersArete's February review places Akira and Qilin at nearly half of observations and highlights Qilin exploitation of WatchGuard CVE-2025-14733 plus Hotta Killer BYOVD activity. Edge remediation and protection against security-driver tampering belong in the same program.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
31Threat / Category

March observation · distribution shift

Twenty-one groups diluted the leading brands and widened the response burden[18]Evidence dated Apr 6, 2026

Why it mattersArete observed 21 groups in March versus 15 in February, with Akira and Qilin falling from nearly half to just over one-quarter. FortiGate exploitation and Teams/Quick Assist social engineering show that actor-share changes do not simplify the access problem.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
32Threat / Category

April observation · leadership change

Qilin overtook Akira while four groups generated about half of activity[19]Evidence dated May 4, 2026

Why it mattersArete reports Qilin moving ahead of Akira in April, with Akira, Qilin, INC Ransom, and DragonForce together accounting for roughly half. DragonForce's rise and continued BYOVD use show both concentration and tactical adaptation.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
33Threat / Category

Technical campaign · deceptive files

Fake JPEG delivery concealed PowerShell and remote-management access[21]Evidence dated May 26, 2026

Why it mattersArete describes attackers using a fake image workflow to execute PowerShell and deploy a trojanized ScreenConnect path. File extension, content, user action, script execution, and remote-tool behavior must be correlated.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
34Threat / Category

Technical campaign · web compromise

A Ghost CMS flaw exposed more than 700 sites to ClickFix delivery[20]Evidence dated May 29, 2026

Why it mattersArete's research connects CVE-2026-26980 exploitation across education and technology sites to a ClickFix campaign. A compromised website can become social-engineering infrastructure even when the visitor is not the original intrusion target.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage

Operational Standards from the Evidence

Best Practices and Lessons Learned

The practices below convert the retained public evidence into repeatable executive standards. Each lesson remains bounded to its cited sources.

Coverage periodJul 29, 2025Jul 28, 2026365 calendar days, inclusiveUpdated Jul 28, 2026
  1. 1

    Best Practice

    Use the report's population correctly[2]Evidence dated Jun 3, 2026

    Lesson Learned

    Arete's statistics describe anonymized extortion engagements, primarily among cyber-insured organizations, and exclude pre-ransomware disruptions from the totals.

    Minimum Operating Standard

    Label every number as Arete engagement data; preserve the reporting period, denominator, inclusion rules, and bias statement in executive use.

  2. 2

    Best Practice

    Prioritize the access path before the actor brand[2]Evidence dated Jun 3, 2026

    Lesson Learned

    Arete finds most groups opportunistic and focused on exploitable vectors rather than one sector.

    Minimum Operating Standard

    Rank internet-facing edge systems, identity workflows, credentials, collaboration platforms, trusted integrations, and recovery dependencies by reachability and consequence.

  3. 3

    Best Practice

    Predefine ransom-decision evidence[2]Evidence dated Jun 3, 2026

    Lesson Learned

    Payment frequency fell while median paid amounts rose, and many Akira payments bought suppression rather than decryption.

    Minimum Operating Standard

    Require verified impact, recovery feasibility, stolen-data scope, legal/sanctions review, actor-specific reliability, negotiation authority, and documented alternatives before considering payment.

  4. 4

    Best Practice

    Treat exposed credentials as an incident lead[4][6]First cited source Jun 30, 2026 · Latest cited source Jul 14, 2026

    Lesson Learned

    Patching does not revoke credentials already harvested.

    Minimum Operating Standard

    Require resets, historical authentication review, administrative configuration review, and documented closure criteria.

  5. 5

    Best Practice

    Make cloud sessions first-class evidence[2][3][5]First cited source Jun 3, 2026 · Latest cited source Jul 17, 2026

    Lesson Learned

    Identity-led extortion can avoid conventional endpoint malware.

    Minimum Operating Standard

    Retain sign-in, token, connected-app, SharePoint, mailbox, Teams, and remote-assistance evidence long enough to investigate delayed discovery.

  6. 6

    Best Practice

    Control device-code, Teams, and help-desk workflows[2][3]First cited source Jun 3, 2026 · Latest cited source Jul 17, 2026

    Lesson Learned

    Attackers exploit legitimate authentication, collaboration, and trusted voices.

    Minimum Operating Standard

    Restrict device-code flows and external collaboration, require phishing-resistant MFA, verify callbacks, govern Quick Assist, and rehearse help-desk impersonation.

  7. 7

    Best Practice

    Contain ClickFix-style user execution[2]Evidence dated Jun 3, 2026

    Lesson Learned

    Urgent fake prompts can bypass traditional controls by convincing users to run legitimate tools themselves.

    Minimum Operating Standard

    Block browser-to-shell patterns, control interpreters and unsigned installers, detect clipboard-driven execution, and train users to stop when instructions demand terminal commands.

  8. 8

    Best Practice

    Block vulnerable drivers[2][5]First cited source Jun 3, 2026 · Latest cited source Jul 6, 2026

    Lesson Learned

    Signed drivers can become an EDR bypass path.

    Minimum Operating Standard

    Maintain a blocklist, monitor kernel-driver loading, and test alerts for endpoint-control disablement.

  9. 9

    Best Practice

    Map laundering and extortion dependencies[7]Evidence dated Jun 23, 2026

    Lesson Learned

    Ransomware operations depend on infrastructure beyond the encryptor.

    Minimum Operating Standard

    Include wallets, negotiation portals, mule accounts, infrastructure, and law-enforcement coordination in the incident playbook.

  10. 10

    Best Practice

    Describe AI assistance precisely[2][8]First cited source Jun 3, 2026 · Latest cited source Jun 12, 2026

    Lesson Learned

    Arete's evidence supports generative and workflow acceleration more strongly than autonomous victim-side operation.

    Minimum Operating Standard

    State what the model did, where it operated, and what evidence supports the conclusion; treat AI inputs as untrusted and monitor AI data flows.

Automation Transparency

AI Agent Run Status

AgentArete Rolling Intelligence Card Publisher
StatusActive · rolling one-year automation
CadenceWeekly on Monday at midday ET
Previous run26 Jul 2026 · material revision · Run arete-publisher-activity-2026-07-26-one-year-archive-backfill
Previous resultBackfilled Arete's complete rolling-year archive with the Q3 2025 and 2025 Annual Crimeware Reports, monthly July 2025–June 2026 observations, and May technical research; rebuilt the chronology around observation-period dates while retaining publication dates in Citations.
What the previous run found
  • Enumerated the monitored Arete collection pages and retained individual publications that control displayed conclusions.
  • Created 34 source-cited briefing points plus a publication chronology, victimology, actor, campaign, technology, access, and response sections.
  • Kept first-party observations, third-party claims, survey data, and product statements in their proper evidence classes.
  • Enabled subscriber alerts for material revisions and suppressed routine no-change email.
Next runWeekly on Monday at midday ET
Sources monitored
  • Arete Cybersecurity Resources and Reports — https://areteir.com/resources/list
  • PETRA report database query constrained to the active rolling one-year publication window; duplicate matches are reconciled to the direct publisher source
Publication and alert policyCheck weekly on monday at midday et. Publish and alert only when a new Arete publication materially changes an actor, campaign, technology, initial-access, victimology, impact, response, resilience, or executive conclusion. No-change checks are logged but do not email subscribers.

Related Intelligence and CARDS Records

Other IntelliOS Products

Publication History

Version Change Log

Versionv1Date26 Jul 2026ChangeCreated the Arete rolling one-year publisher card with Research Framing, Timeline, BLUF, Executive Summary, top-ten findings, victimology, campaigns, actors, technologies, access vectors, operational practices, AI agent status, and citations.MonitoringWeekly on Monday at midday ET; material-change-only Page Alerts.
Versionv3Date26 Jul 2026ChangeBackfilled Arete's complete rolling-year archive with the Q3 2025 and 2025 Annual Crimeware Reports, monthly July 2025–June 2026 observations, and May technical research; rebuilt the chronology around observation-period dates while retaining publication dates in Citations.MonitoringWeekly on Monday at midday ET; material-change-only Page Alerts.

Citations

Retained Sources and Claim Treatment

Source1PublisherAretePublishedNot availablePublication / evidenceSource indexecosystem monitorWhy used / claim treatmentAuthoritative first-party corpus index monitored weekly. Individual publications control factual claims.SourceArete Cybersecurity Resources and Reports

https://areteir.com/resources/list

Source2PublisherAretePublished2026-06-03Publication / evidenceSource indexincident responseWhy used / claim treatmentPrimary analytic source for this edition. Arete derives its statistics from anonymized ransomware and extortion incident-response engagements and excludes pre-ransomware disruptions from the statistical population. The sample primarily represents cyber-insured organizations and is not a global incident census. External research cited inside the report remains third-party evidence.SourceArete's 2026 Q1 Crimeware Report — Full Report

https://6288364.fs1.hubspotusercontent-na1.net/hubfs/6288364/Threat%20Intel%20Reports/Arete_Crimeware_Report%20_Q1_2026.pdf

Source3PublisherAretePublished2026-07-17Publication / evidenceSource indexprimary researchWhy used / claim treatmentSource-qualified analysis of a newly reported extortion group. Relationships to other actor ecosystems remain unconfirmed.SourceHelix Extortion Group Debuts in SharePoint Data Theft Attacks

https://areteir.com/resources/helix-extortion-group-debuts-in-sharepoint-data-theft-attacks

Source4PublisherAretePublished2026-07-14Publication / evidenceSource indexprimary researchWhy used / claim treatmentArete synthesis of reported campaign evidence. Device and attribution counts remain qualified to the cited research.SourceFortiBleed Campaign Linked to INC and Lynx Ransomware Operations

https://areteir.com/resources/fortibleed-campaign-linked-to-inc-and-lynx-ransomware-operations

Source5PublisherAretePublished2026-07-06Publication / evidenceSource indexincident responseWhy used / claim treatmentMonthly Arete observations and internally sourced trend statements; activity counts are not a universal ransomware census.SourceRansomware Trends & Data Insights: June 2026

https://areteir.com/resources/ransomware-trends-data-insights-june-2026

Source6PublisherAretePublished2026-06-30Publication / evidenceSource indexprimary researchWhy used / claim treatmentCampaign update combining public reporting with Arete's defensive interpretation. Exposure is not proof of compromise.SourceUpdate on FortiBleed Credential Exposure

https://areteir.com/resources/update-on-fortibleed-credential-exposure

Source7PublisherAretePublished2026-06-23Publication / evidenceSource indexprimary researchWhy used / claim treatmentArete analysis of an official disruption. Seizure, arrest, and processing figures remain attributed to authorities.SourceEuropol Disrupts AudiA6 Crypto Laundering Service

https://areteir.com/resources/europol-disrupts-audia6-crypto-laundering-service

Source8PublisherAretePublished2026-06-12Publication / evidenceSource indexprimary researchWhy used / claim treatmentSource-qualified analysis of AI-assisted development and evasion. It does not establish autonomous AI inside victim environments.SourceThreat Actors Leverage AI for EDR Evasion

https://areteir.com/resources/threat-actors-leverage-ai-for-edr-evasion

Source9PublisherAretePublished2025-12-03Publication / evidenceSource indexincident responseWhy used / claim treatmentPrimary first-party evidence for Arete-handled activity observed from 1 July through 30 September 2025. Percentages describe Arete's engagement population, not global ransomware prevalence.SourceArete Q3 2025 Crimeware Report — Full Report

https://6288364.fs1.hubspotusercontent-na1.net/hubfs/6288364/Threat%20Intel%20Reports/Arete_Q3_2025_Crimeware_Report.pdf

Source10PublisherAretePublished2025-09-08Publication / evidenceSource indexincident responseWhy used / claim treatmentMonthly Arete observations for August 2025. Publication followed the observation month; counts are not a universal census.SourceRansomware Trends & Data Insights: August 2025

https://areteir.com/resources/august-2025-ransomware-trends-data-insights

Source11PublisherAretePublished2025-10-06Publication / evidenceSource indexincident responseWhy used / claim treatmentMonthly Arete observations for September 2025. Extortion-only and actor-share statements remain bounded to Arete's evidence.SourceRansomware Trends & Data Insights: September 2025

https://areteir.com/resources/ransomware-trends-data-insights-september-2025

Source12PublisherAretePublished2025-11-07Publication / evidenceSource indexincident responseWhy used / claim treatmentMonthly Arete observations for October 2025, including attributed campaign context. External actor claims remain qualified.SourceRansomware Trends & Data Insights: October 2025

https://areteir.com/resources/october-2025-ransomware-trends-data-insights

Source13PublisherAretePublished2025-11-21Publication / evidenceSource indexprimary researchWhy used / claim treatmentArete analysis of official law-enforcement action. Infrastructure, arrest, and credential figures remain attributed to the participating authorities.SourceOperation Endgame Season 3

https://areteir.com/article/operation-endgame-season-3/

Source14PublisherAretePublished2026-01-12Publication / evidenceSource indexincident responseWhy used / claim treatmentMonthly Arete observations for December 2025. Vulnerability and actor reporting establishes defensive relevance, not local compromise.SourceRansomware Trends & Data Insights: December 2025

https://areteir.com/resources/ransomware-trends-data-insights-december-2025

Source15PublisherAretePublished2026-02-05Publication / evidenceSource indexincident responseWhy used / claim treatmentMonthly Arete observations for January 2026. Group shares describe Arete's stated population.SourceRansomware Trends & Data Insights: January 2026

https://areteir.com/resources/ransomware-trends-data-insights-january-2026

Source16PublisherAretePublished2026-03-09Publication / evidenceSource indexincident responseWhy used / claim treatmentMonthly Arete observations for February 2026, including source-qualified vulnerability and BYOVD reporting.SourceRansomware Trends & Data Insights: February 2026

https://areteir.com/resources/ransomware-trends-data-insights-february-2026

Source17PublisherAretePublished2026-03-27Publication / evidenceSource indexincident responseWhy used / claim treatmentFirst-party annual synthesis of Arete's 2025 ransomware and extortion engagement population. Actor, sector, demand, payment, and disclosure statistics are not a global incident census.SourceArete 2025 Annual Crimeware Report — Full Report

https://6288364.fs1.hubspotusercontent-na1.net/hubfs/6288364/Threat%20Intel%20Reports/Arete_Annual_Report%20_2025.pdf

Source18PublisherAretePublished2026-04-06Publication / evidenceSource indexincident responseWhy used / claim treatmentMonthly Arete observations for March 2026. Actor and access findings remain bounded to Arete's stated evidence.SourceRansomware Trends & Data Insights: March 2026

https://areteir.com/resources/ransomware-trends-data-insights-march-2026

Source19PublisherAretePublished2026-05-04Publication / evidenceSource indexincident responseWhy used / claim treatmentMonthly Arete observations for April 2026, including group-share and BYOVD findings.SourceRansomware Trends & Data Insights: April 2026

https://areteir.com/resources/ransomware-trends-data-insights-april-2026

Source20PublisherAretePublished2026-05-29Publication / evidenceSource indexprimary researchWhy used / claim treatmentTechnical campaign analysis of compromised websites and ClickFix delivery. Affected-site observations do not establish downstream victim compromise.SourceCMS Vulnerability Leads to ClickFix Campaign

https://areteir.com/resources/cms-vulnerability-leads-to-clickfix-campaign

Source21PublisherAretePublished2026-05-26Publication / evidenceSource indexprimary researchWhy used / claim treatmentTechnical campaign analysis of PowerShell-based delivery and remote-management-tool abuse. Campaign indicators do not establish local compromise.SourceThreat Actors Leverage Fake JPEG Files for Initial Access

https://areteir.com/resources/threat-actors-leverage-fake-jpeg-files-for-initial-access