- How it starts
- Attackers scan and exploit Fortinet, WatchGuard, BeyondTrust, and other exposed edge systems, including both newly disclosed and older unpatched vulnerabilities.
- Attacker outcome
- Pre-authentication execution, privileged control, credential theft, reverse shells, persistent access, lateral movement, and ransomware deployment.
- What to monitor
- Exact product/version inventory, management exposure, exploit requests, unexpected processes, reverse shells, new accounts, RDP enablement, and post-patch historical indicators.
Arete Cyber Threat & Incident Response Rolling Intelligence Card
A source-cited rolling one-year synthesis of Arete's crimeware and incident-response research from 27 July 2025 through 26 July 2026. The card uses the Q3 2025, 2025 Annual, and Q1 2026 Crimeware Reports plus monthly and technical updates to show how actor concentration, access methods, victimology, payment pressure, and defensive priorities changed across the full window. The Q1 2026 report remains the highest-weight current analytic source, and every observation period is kept distinct from the date Arete published it.
Research Framing
| Field | Value | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| User Topic | What Arete's public research says about current crimeware and incident-response pressure: who is operating, how access is obtained, which technologies and trust relationships are being abused, what business impact follows, and what defenders should change. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Interpreted Questions | How did Arete's actor mix, access paths, affected sectors, payment outcomes, and operating techniques change across the entire rolling year? Which dates describe observed activity versus later publication? Which actor relationships are assessed versus confirmed, and what should defenders validate now? | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Initial Observations | The complete window shows a meaningful arc that the earlier two-month timeline missed. Akira surged from 32.1% of Arete's July 2025 engagements to 52.9% in August before easing to 18.3% in Q1 2026; Qilin remained a persistent second pole and overtook Akira in April 2026. Arete's annual evidence identifies vulnerability exploitation, compromised credentials, and social engineering as the recurring access classes, while later reporting adds SaaS-token abuse, BYOVD, ClickFix, identity-led SharePoint extortion, and FortiBleed credential exposure. Q1 2026 remains the most current weighted baseline for economics and victimology.[1][2][3][4][5][6][7][8][9][10][11][12][13][14][15][16][17][18][19][20][21]First cited source Sep 8, 2025 · Latest cited source Jul 17, 2026 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Source Coverage |
Complete Tier 0–8 counts are shown here. The 21 retained sources and their claim treatment are identified in Citations. Planned integrations are not counted as checked or selected. |
Reporting-Period Statistics
Rolling 1-Year Intelligence Snapshot
At-a-glance measures from the retained evidence set. Citations identify the source controlling each statistic.
Period Coverage
Jul 29, 2025–Jul 28, 2026
365 calendar days, inclusive. Records are included by their first-observed date inside this window; the period does not imply that every underlying incident began or was confirmed during it.
31%[2]
Q1 Ransom Payment Rate
Arete-handled Q1 ransomware and extortion engagements; down from 33% in Q1 2025.Evidence dated Jun 3, 2026
$571K[2]
Q1 Median Demand
Arete's Q1 engagement population; below the $600K full-year 2025 median.Evidence dated Jun 3, 2026
$250K[2]
Q1 Median Payment
Up from $100K in Q1 2025 and $152,750 for full-year 2025.Evidence dated Jun 3, 2026
32.6%[2]
Akira + Qilin Share
18.3% Akira plus 14.3% Qilin in Arete's Q1 engagement chart.Evidence dated Jun 3, 2026
21.6%[2]
Leading Sector
Professional, scientific, and technical services share of Arete Q1 engagements.Evidence dated Jun 3, 2026
38[2]
Named Threat Actors
Named actor labels in Arete's Q1 population, plus 10 unnamed actors; not unique legal persons.Evidence dated Jun 3, 2026
81 + 52[17]
2025 Actor Labels
Named plus unnamed actor labels across Arete's full-year 2025 engagement population.Evidence dated Mar 27, 2026
31.6%[17]
2025 Payment Rate
Share of Arete's full-year 2025 ransomware and extortion engagements resulting in payment.Evidence dated Mar 27, 2026
Arete Q1 2026 Threat-Group Share
Share of Arete ransomware and extortion engagements for the five leading named groups shown in the Q1 report. These are handled engagements, not leak-site victim totals.[2]Evidence dated Jun 3, 2026
Ransom Payment Rate
The proportion of Arete engagements resulting in payment declined slightly across the comparison periods.[2]Evidence dated Jun 3, 2026
Median Ransom Demand
Arete's median demand increased year over year but remained below the full-year 2025 median.[2]Evidence dated Jun 3, 2026
Median Ransom Payment
The median paid amount in Arete engagements rose sharply even as the overall payment rate edged lower.[2]Evidence dated Jun 3, 2026
Most Impacted Q1 Sectors
Leading NAICS sector shares in Arete's Q1 engagement population. Arete assesses most activity as opportunistic and access-driven rather than sector-exclusive.[2]Evidence dated Jun 3, 2026
Akira Share Across the Rolling Year
Arete engagement share at selected observation periods. This shows the August 2025 surge and subsequent normalization rather than implying one static annual threat level.[9][17][2]First cited source Dec 3, 2025 · Latest cited source Jun 3, 2026
Arete 2025 Threat-Group Share
Leading named groups in Arete's full-year 2025 engagement population. The annual report identified 81 named and 52 unnamed labels overall.[17]Evidence dated Mar 27, 2026
Most Impacted 2025 Sectors
Leading sector shares in Arete's full-year 2025 engagement population, retained separately from the Q1 2026 sector chart.[17]Evidence dated Mar 27, 2026
Evidence-Prioritized Access Paths
Top Initial Access & Account-Takeover Vectors
Arete explicitly identifies vulnerability exploitation, compromised credentials, and social engineering as the leading Q1 initial-access classes. The ranked operational view below expands those categories with the concrete technologies and workflows documented in the full report and later Arete updates; it does not invent percentage shares that Arete did not publish.
- How it starts
- Botnets brute-force common accounts or attackers reuse credentials obtained from configurations, infostealers, or earlier compromises.
- Attacker outcome
- Valid VPN or administrative access that can blend into normal authentication.
- What to monitor
- Password spraying, impossible travel, new devices, dormant-account activation, configuration export, unusual VPN sessions, and service-account use.
Publisher-observed access path
Vishing and trusted-person impersonation[3]Evidence dated Jul 17, 2026
Retained Arete evidence; local exposure and prevalence require validation
- How it starts
- An attacker impersonates a manager or trusted party and pressures the user through a voice channel.
- Attacker outcome
- User-assisted completion of a device-code or authentication workflow.
- What to monitor
- Unusual voice-driven access requests, help-desk changes, new device registrations, and suspicious cloud sessions.
Publisher-observed access path
Teams help-desk impersonation and remote assistance[2]Evidence dated Jun 3, 2026
Retained Arete evidence; local exposure and prevalence require validation
- How it starts
- Email bombing or phishing is followed by cross-tenant Teams contact from an attacker posing as internal IT and directing OAuth consent or Quick Assist access.
- Attacker outcome
- Identity-backed remote control, persistent sessions, and data access through legitimate services.
- What to monitor
- External-tenant chats, guest access, unusual support contacts, Quick Assist launches, OAuth consent, new MFA registration, and follow-on exports.
- How it starts
- The victim completes an attacker-controlled device authentication flow.
- Attacker outcome
- Valid cloud session access without traditional password-only compromise.
- What to monitor
- Device-code grants, unfamiliar user agents, session reuse, and SharePoint enumeration.
Publisher-observed access path
ClickFix and deceptive command execution[2]Evidence dated Jun 3, 2026
Retained Arete evidence; local exposure and prevalence require validation
- How it starts
- Fake CAPTCHA, browser-error, troubleshooting, or sponsored-install prompts convince a user to paste commands or install malicious software.
- Attacker outcome
- RAT, infostealer, or ransomware delivery using legitimate interpreters and user action.
- What to monitor
- Clipboard-to-shell behavior, terminal launches from browsers, PowerShell/Python execution, suspicious installers, browser crashes, and new remote-control tooling.
- How it starts
- Internet scanning, password spraying, SSH brute force, and configuration extraction target FortiGate systems.
- Attacker outcome
- Reusable administrative and VPN credentials plus persistent access.
- What to monitor
- High-volume failures followed by success, config export, admin creation, and unusual VPN access.
Publisher-observed access path
OAuth and trusted integration abuse[5]Evidence dated Jul 6, 2026
Retained Arete evidence; local exposure and prevalence require validation
- How it starts
- Tokens are stolen from a provider or connected application.
- Attacker outcome
- Downstream access to customer SaaS data through existing trust.
- What to monitor
- New grants, unusual API access, mass exports, token reuse, and third-party anomalies.
- How it starts
- Attackers load a signed but vulnerable driver or EDR-disabling utility.
- Attacker outcome
- Security-control impairment and a path to ransomware or broader post-exploitation.
- What to monitor
- Unexpected driver loads, service stops, kernel events, and policy changes.
| Vector / Evidence | How It Starts | Attacker Outcome | What to Monitor |
|---|---|---|---|
| Attackers scan and exploit Fortinet, WatchGuard, BeyondTrust, and other exposed edge systems, including both newly disclosed and older unpatched vulnerabilities. | Pre-authentication execution, privileged control, credential theft, reverse shells, persistent access, lateral movement, and ransomware deployment. | Exact product/version inventory, management exposure, exploit requests, unexpected processes, reverse shells, new accounts, RDP enablement, and post-patch historical indicators. | |
| Botnets brute-force common accounts or attackers reuse credentials obtained from configurations, infostealers, or earlier compromises. | Valid VPN or administrative access that can blend into normal authentication. | Password spraying, impossible travel, new devices, dormant-account activation, configuration export, unusual VPN sessions, and service-account use. | |
3 Publisher-observed access path Vishing and trusted-person impersonation[3]Evidence dated Jul 17, 2026 Retained Arete evidence; local exposure and prevalence require validation | An attacker impersonates a manager or trusted party and pressures the user through a voice channel. | User-assisted completion of a device-code or authentication workflow. | Unusual voice-driven access requests, help-desk changes, new device registrations, and suspicious cloud sessions. |
4 Publisher-observed access path Teams help-desk impersonation and remote assistance[2]Evidence dated Jun 3, 2026 Retained Arete evidence; local exposure and prevalence require validation | Email bombing or phishing is followed by cross-tenant Teams contact from an attacker posing as internal IT and directing OAuth consent or Quick Assist access. | Identity-backed remote control, persistent sessions, and data access through legitimate services. | External-tenant chats, guest access, unusual support contacts, Quick Assist launches, OAuth consent, new MFA registration, and follow-on exports. |
| The victim completes an attacker-controlled device authentication flow. | Valid cloud session access without traditional password-only compromise. | Device-code grants, unfamiliar user agents, session reuse, and SharePoint enumeration. | |
6 Publisher-observed access path ClickFix and deceptive command execution[2]Evidence dated Jun 3, 2026 Retained Arete evidence; local exposure and prevalence require validation | Fake CAPTCHA, browser-error, troubleshooting, or sponsored-install prompts convince a user to paste commands or install malicious software. | RAT, infostealer, or ransomware delivery using legitimate interpreters and user action. | Clipboard-to-shell behavior, terminal launches from browsers, PowerShell/Python execution, suspicious installers, browser crashes, and new remote-control tooling. |
| Internet scanning, password spraying, SSH brute force, and configuration extraction target FortiGate systems. | Reusable administrative and VPN credentials plus persistent access. | High-volume failures followed by success, config export, admin creation, and unusual VPN access. | |
8 Publisher-observed access path OAuth and trusted integration abuse[5]Evidence dated Jul 6, 2026 Retained Arete evidence; local exposure and prevalence require validation | Tokens are stolen from a provider or connected application. | Downstream access to customer SaaS data through existing trust. | New grants, unusual API access, mass exports, token reuse, and third-party anomalies. |
| Attackers load a signed but vulnerable driver or EDR-disabling utility. | Security-control impairment and a path to ransomware or broader post-exploitation. | Unexpected driver loads, service stops, kernel events, and policy changes. |
Intended Reader and Decision Context
Persona / Audience
Who this brief is written for, the geographic and organizational lens it uses, and how readers should apply the intelligence.
| Audience Field | Assessment |
|---|---|
| Audience fieldPrimary audience | AssessmentExecutives, CISOs, CIOs, incident-response leaders, threat-intelligence teams, SOC leaders, risk owners, and business-continuity leaders who need a decision-ready view of one publisher's strongest public research. |
| Audience fieldDecision use | AssessmentUse the card to identify recurring access paths, actor and campaign changes, affected technologies, likely business impact, and control priorities that deserve validation inside the reader's own environment. |
| Audience fieldSource posture | AssessmentArete is the controlling source for publisher-specific observations. External facts repeated in a publication retain the original attribution and are not upgraded into independently verified IntelliOS findings. |
| Audience fieldUpdate model | AssessmentA dedicated publisher agent checks the complete monitored corpus weekly on monday at midday et, keeps a cumulative rolling one-year window, and sends Page Alerts only for material source-backed changes. |
Chronology and Decision Milestones
Timeline of Notable Activity
Entries are ordered from oldest to newest across the full rolling year. Monthly and quarterly findings use the end of Arete's stated observation period; Citations preserve the later publication date. One-off technical research and official actions use their public date, and no entry is treated as the date an intrusion necessarily began.
July observation · actor concentration
Akira entered the window as the clear volume leader, but not as a monopoly
Arete's Q3 report assigns Akira 32.1% of July engagements, followed by Qilin at 11.3% and Sinobi at 9.4%. The opening month already supports a multi-actor playbook even before Akira's August surge.[9]
August observation · actor surge
Akira rose above half of Arete's August engagements
Akira reached 52.9% in August, while Qilin represented 15.3% and PLAY 5.9%. Arete tied the spike partly to exploitation and legacy credentials around SonicWall environments, making edge history and credential hygiene central response questions.[9][10]
August observation · SaaS supply chain
Salesloft Drift token theft turned a trusted integration into downstream access
Arete's Q3 analysis describes theft of Salesforce OAuth and refresh tokens associated with the Salesloft Drift campaign. Connected-app inventory, token revocation, and downstream log review are necessary when a SaaS provider is compromised.[9][10]
September observation · enterprise extortion
CL0P began an Oracle EBS extortion wave tied to CVE-2025-61882
Arete records extortion emails beginning on 29 September following exploitation of Oracle E-Business Suite. The sequence demonstrates why application remediation must include retrospective data-access review and preparation for delayed extortion contact.[9]
September observation · actor mix
Akira receded while PLAY and World Leaks gained share
Arete's Q3 report places Akira at 36.6%, Qilin at 11.3%, and both PLAY and World Leaks at 7.0% in September. Extortion-only operations became a larger part of the visible mix even as the leading ransomware brands persisted.[9][11]
October observation · parallel campaigns
Edge exploitation and SaaS extortion were active at the same time
Arete kept Akira and Qilin among October's leaders while tracking CL0P's Oracle EBS campaign and the Scattered Lapsus$ Hunters/Salesloft activity. Response planning must cover appliance compromise, enterprise applications, and trusted cloud integrations concurrently.[12]
Law-enforcement action · malware infrastructure
Operation Endgame removed infrastructure at scale without ending the crimeware market
Arete's account of Season 3 attributes more than 1,000 server disruptions, 20 seized domains, an operator arrest, and millions of stolen credentials to the coordinated action. The takedown imposed cost, but Arete did not treat it as proof that ransomware access supply had stopped.[13]
Full-year observation · actor landscape
Akira led 2025, but Arete still observed a fragmented operator ecosystem
Arete's annual report places Akira at 28.4% and Qilin at 12.8% across 81 named and 52 unnamed actor labels. Akira's Q3 surge mattered, but the number of labels shows why a durable defense cannot depend on a single-brand watchlist.[17]
December observation · renewed concentration
Akira exceeded one-third of December activity as RansomHouse returned
Arete reports Akira above one-third of December observations and the top three groups at 57%, alongside RansomHouse's return and emerging React2Shell and MongoBleed exposure. Actor concentration and fast-moving vulnerability response were linked operational concerns.[14][17]
January observation · broader actor mix
The top three fell to 34% as LockBit 5 and ClickFix entered the watchlist
Arete identified 17 groups in January, with Akira at 17% and the top three representing only about one-third. LockBit 5 activity and ClickFix/CrashFix social engineering reinforced the need to follow behaviors across changing brands.[15]
February observation · edge and endpoint defense
Akira and Qilin again approached half of activity while access paths diversified
Arete's February review places Akira and Qilin at nearly half of observations and highlights Qilin exploitation of WatchGuard CVE-2025-14733 plus Hotta Killer BYOVD activity. Edge remediation and protection against security-driver tampering belong in the same program.[16]
Q1 observation · ransom economics
Payments became less frequent but materially larger when victims paid
Arete reports a 31% Q1 2026 payment rate, down from 33% in Q1 2025, while the median payment rose from $100,000 to $250,000. The Q1 median demand was $571,000. Lower payment frequency therefore did not reduce the financial severity of the paid cases in Arete's engagement population.[2]
Q1 observation · actor concentration
Akira and Qilin produced almost one-third of Arete's Q1 engagements
Akira represented 18.3% and Qilin 14.3% of Q1 activity in Arete's chart. Their combined share remained important but declined from more than half in each of Q3 and Q4 2025, showing concentration easing without eliminating either actor as a priority.[2]
Q1 observation · payment leverage
Akira combined high volume with unusually strong payment conversion
Arete reports Akira median demands of $700,000, median payments of $300,000, and payment in almost 48% of Akira engagements. More than half of those paying victims purchased data suppression without a decryptor, showing that stolen-data pressure can drive payment even when recovery is not the objective.[2]
Q1 observation · victimology
Professional services led a broad, access-driven victim population
Professional, scientific, and technical services accounted for 21.6% of Arete engagements, followed by manufacturing at 13.6%, wholesale trade at 10.4%, healthcare and social assistance at 8.8%, retail at 8.0%, and construction at 7.2%. Arete assesses most groups as opportunistic and access-vector-driven rather than sector-exclusive.[2]
Q1 observation · initial access
Edge exploitation, compromised credentials, and social engineering formed the Q1 access triad
Arete identifies vulnerability exploits, compromised credentials, and social engineering as the leading initial-access classes. Firewalls and VPN systems concentrate risk because they are internet-facing, authentication-connected, and capable of exposing internal enterprise access after compromise.[2]
Q1 observation · identity-first intrusion
Teams impersonation, device-code abuse, and ClickFix moved social engineering beyond ordinary phishing
Arete observed renewed cross-tenant Microsoft Teams help-desk impersonation, OAuth and Quick Assist workflows, and ClickFix campaigns across Windows and macOS. Akira, INC Ransom, Payouts King, and Chaos used Teams-style tactics, while Akira, Qilin, and Interlock adopted ClickFix.[2]
Q1 observation · edge vulnerabilities
Fortinet, WatchGuard, and BeyondTrust weaknesses were operational entry paths—not inventory trivia
The report documents Fortinet authentication bypass and older-flaw exploitation, Qilin exploitation of WatchGuard CVE-2025-14733, and Arete-confirmed exploitation of BeyondTrust CVE-2026-1731 linked to a Medusa-associated cluster. Edge remediation must pair patching with access review and hunting.[2]
Q1 observation · actor persistence
The top tier remained stable even as new ransomware brands emerged
Akira, Qilin, PLAY, and INC Ransom remained among Arete's top five groups in every quarter since the second half of 2025. NightSpire posted more than 100 Q1 disclosures, BravoX posted nine while building credibility, and Schrodinger Cat formalized its brand, but established operators still drove most handled activity.[2]
Q1 observation · RaaS evolution
DragonForce's cartel model and leaked-code reuse lower the cost of operational change
Arete describes DragonForce shifting toward a decentralized partnership model and identifies Conti-derived implementation overlap. Its appendix reports identical ChaCha-like encryption logic, shared command-line behavior, a common mutex, and 99% BinDiff similarity between compared 32-bit DragonForce and Devman samples.[2]
Q1 observation · AI evidence boundary
Most adversarial AI use remained generative and assistive—not autonomous
Arete observed AI accelerating stolen-data analysis, victim prioritization, social engineering, and extortion strategy, while its outlook says most current use remained generative rather than agentic. Defenders should act on measurable workflow acceleration without claiming autonomous intrusions the evidence does not establish.[2]
March observation · distribution shift
Twenty-one groups diluted the leading brands and widened the response burden
Arete observed 21 groups in March versus 15 in February, with Akira and Qilin falling from nearly half to just over one-quarter. FortiGate exploitation and Teams/Quick Assist social engineering show that actor-share changes do not simplify the access problem.[18]
April observation · leadership change
Qilin overtook Akira while four groups generated about half of activity
Arete reports Qilin moving ahead of Akira in April, with Akira, Qilin, INC Ransom, and DragonForce together accounting for roughly half. DragonForce's rise and continued BYOVD use show both concentration and tactical adaptation.[19]
Technical campaign · deceptive files
Fake JPEG delivery concealed PowerShell and remote-management access
Arete describes attackers using a fake image workflow to execute PowerShell and deploy a trojanized ScreenConnect path. File extension, content, user action, script execution, and remote-tool behavior must be correlated.[21]
Technical campaign · web compromise
A Ghost CMS flaw exposed more than 700 sites to ClickFix delivery
Arete's research connects CVE-2026-26980 exploitation across education and technology sites to a ClickFix campaign. A compromised website can become social-engineering infrastructure even when the visitor is not the original intrusion target.[20]
AI-assisted offense
Later Arete analysis sharpened how AI shortens malware development and EDR testing
Arete describes threat actors using agent-based AI workflows for Active Directory discovery, iterative development, lab reproduction, and evasion testing. It found no evidence that AI was embedded as an autonomous operator inside victim environments.[8]
Criminal infrastructure disruption
AudiA6 shows ransomware depends on professional laundering infrastructure
Arete's account of the Europol-backed action describes arrests, more than 30 servers, 25 domains, and over €778,000 in frozen or seized cryptocurrency. Financial services, mule accounts, and marketplace infrastructure belong in the ransomware ecosystem map.[7]
Credential exposure
FortiBleed is a credential-compromise problem, not a patch-only problem
Arete's update describes password spraying, configuration exfiltration, packet sniffing, and harvested credentials affecting more than 86,000 devices across 194 countries. Credential resets, historical log review, management-plane restriction, and hunting are required alongside fixes.[6]
June observation · crimeware trend
June activity remained distributed despite Akira leading Arete's observations
Arete identified 17 unique groups during June and kept Akira, Qilin, and INC Ransom among the most active. The decision is to maintain a behavior-led watchlist instead of anchoring response plans to one brand.[5]
June observation · trusted software abuse
BYOVD is being used to disable or evade endpoint defenses
Arete reports Akira and DragonForce using vulnerable drivers in engagements and describes GentleKiller as a framework targeting multiple security products. Driver loading and security-control tampering should be high-priority detection events.[5]
June observation · SaaS supply chain
OAuth tokens can propagate one provider breach into many customer environments
Arete's June review uses the Klue incident to show how stolen Salesforce integration tokens can extend an intrusion through trusted SaaS relationships. Token inventory, revocation, and connected-app telemetry are incident-response requirements.[5]
Ransomware access ecosystem
FortiBleed links stolen edge credentials to INC and Lynx operations
Arete reports evidence connecting the credential-harvesting campaign to INC and Lynx ransomware operations, including a shared operator and exposed workflow infrastructure. Organizations with affected FortiGate history should investigate credentials and administrative activity even after patching.[4][6]
Identity-led extortion
Helix makes Microsoft 365 identity the extortion perimeter
Arete describes Helix using vishing, device-code phishing, MFA abuse, and trusted-person impersonation to reach SharePoint Online and exfiltrate data. The practical control boundary is the identity session and cloud application—not only the endpoint.[3]
Actor identity boundary
Helix may overlap ShinyHunters and BlackFile ecosystems, but the relationship is unresolved
Arete notes operational similarities and possible shared ecosystems while explicitly keeping the connection unconfirmed. Defenders can correlate behaviors without collapsing separate names into one attribution.[3]
Bottom Line Up Front
BLUF
Payments became less frequent but materially larger when victims paid: Arete reports a 31% Q1 2026 payment rate, down from 33% in Q1 2025, while the median payment rose from $100,000 to $250,000. The Q1 median demand was $571,000. Lower payment frequency therefore did not reduce the financial severity of the paid cases in Arete's engagement population.[2]Evidence dated Jun 3, 2026
Akira and Qilin produced almost one-third of Arete's Q1 engagements: Akira represented 18.3% and Qilin 14.3% of Q1 activity in Arete's chart. Their combined share remained important but declined from more than half in each of Q3 and Q4 2025, showing concentration easing without eliminating either actor as a priority.[2]Evidence dated Jun 3, 2026
Akira combined high volume with unusually strong payment conversion: Arete reports Akira median demands of $700,000, median payments of $300,000, and payment in almost 48% of Akira engagements. More than half of those paying victims purchased data suppression without a decryptor, showing that stolen-data pressure can drive payment even when recovery is not the objective.[2]Evidence dated Jun 3, 2026
Professional services led a broad, access-driven victim population: Professional, scientific, and technical services accounted for 21.6% of Arete engagements, followed by manufacturing at 13.6%, wholesale trade at 10.4%, healthcare and social assistance at 8.8%, retail at 8.0%, and construction at 7.2%. Arete assesses most groups as opportunistic and access-vector-driven rather than sector-exclusive.[2]Evidence dated Jun 3, 2026
Edge exploitation, compromised credentials, and social engineering formed the Q1 access triad: Arete identifies vulnerability exploits, compromised credentials, and social engineering as the leading initial-access classes. Firewalls and VPN systems concentrate risk because they are internet-facing, authentication-connected, and capable of exposing internal enterprise access after compromise.[2]Evidence dated Jun 3, 2026
Teams impersonation, device-code abuse, and ClickFix moved social engineering beyond ordinary phishing: Arete observed renewed cross-tenant Microsoft Teams help-desk impersonation, OAuth and Quick Assist workflows, and ClickFix campaigns across Windows and macOS. Akira, INC Ransom, Payouts King, and Chaos used Teams-style tactics, while Akira, Qilin, and Interlock adopted ClickFix.[2]Evidence dated Jun 3, 2026
Decision Context
Executive Summary
Across the full rolling year, Arete's evidence shows both persistence and rotation. Akira rose from 32.1% of July engagements to 52.9% in August, led full-year 2025 at 28.4%, then fell to 18.3% in Q1 2026; Qilin remained consistently important and overtook Akira in April. That movement argues for maintaining proven playbooks for durable operators while using access behavior—not a monthly brand ranking—as the primary organizing principle.[9][10][17][2][19]First cited source Sep 8, 2025 · Latest cited source Jun 3, 2026
Arete's Q1 2026 Crimeware Report is the strongest source in this edition because it combines first-hand ransomware and extortion response, forensics, restoration, threat hunting, actor communications, and malware analysis. Its statistics include only incidents where a victim was extorted, with or without encryption; pre-ransomware disruptions do not enter the totals. The sample is weighted toward cyber-insured organizations, so the findings are a decision-quality view of Arete's casework—not a global ransomware census.[2]Evidence dated Jun 3, 2026
The actor landscape was concentrated but not monopolized. Akira accounted for 18.3% and Qilin 14.3% of Q1 engagements, down from a combined majority in the prior two quarters. Akira, Qilin, PLAY, and INC Ransom nevertheless remained in Arete's top five in every quarter since the second half of 2025. The operational lesson is to maintain durable playbooks for established groups while watching new brands such as NightSpire, BravoX, and Schrodinger Cat for credible shifts in access, tooling, and affiliate adoption.[2]Evidence dated Jun 3, 2026
Payment economics moved in opposite directions. Arete's Q1 payment rate fell slightly to 31%, yet the median paid amount rose to $250,000 from $100,000 a year earlier; the median demand was $571,000. Akira was more effective than the portfolio average, with a $700,000 median demand, $300,000 median payment, and payment in almost 48% of engagements. More than half of paying Akira victims bought data suppression without a decryptor, demonstrating that exfiltration can retain leverage even when operations are recoverable.[2]Evidence dated Jun 3, 2026
Victimology supports an access-first interpretation. Professional, scientific, and technical services led at 21.6%, followed by manufacturing, wholesale trade, healthcare, retail, and construction. Arete characterizes most active groups as opportunistic, exploiting reachable edge products, credentials, and human workflows rather than selecting one sector. Sector controls should therefore start with externally reachable technology, identity exposure, trusted service providers, and recovery dependence, then account for sector-specific interruption and data consequences.[2]Evidence dated Jun 3, 2026
Initial access is converging across vulnerabilities, identity, and social engineering. Arete documents Fortinet, WatchGuard, and BeyondTrust exploitation; credentials obtained through brute force, reuse, and infostealers; Teams help-desk impersonation; OAuth and device-code abuse; Quick Assist; and ClickFix lures on Windows and macOS. These methods exploit systems and workflows that look legitimate, so prevention and detection must extend beyond malware signatures to authentication path, session behavior, external collaboration, driver loading, and user-directed command execution.[2]Evidence dated Jun 3, 2026
Later Arete publications show how the Q1 baseline evolved. FortiBleed connects edge credential harvesting to possible ransomware follow-on activity; Helix moves extortion into Microsoft 365 identity and SharePoint; Klue demonstrates downstream SaaS-token exposure; BYOVD targets endpoint defenses; and AudiA6 illustrates the laundering infrastructure supporting monetization. These updates are most useful when interpreted against the report's case-derived access and actor baseline.[3][4][5][6][7]First cited source Jun 23, 2026 · Latest cited source Jul 17, 2026
Arete's AI conclusion requires precision. The Q1 report describes AI accelerating stolen-data analysis, victim prioritization, personalized deception, and ransom strategy, but says most current adversarial use remains generative rather than agentic. Later Arete analysis adds AI-assisted development and EDR testing without showing an autonomous operator inside a victim. Executives should secure AI inputs and data flows while improving identity, edge, SaaS, endpoint-tamper, evidence-retention, and recovery controls that address the observed attack paths today.[2][8]First cited source Jun 3, 2026 · Latest cited source Jun 12, 2026
Executive Briefing Priorities
Top 10 Briefing Points
- 1
Payments became less frequent but materially larger when victims paid — Arete reports a 31% Q1 2026 payment rate, down from 33% in Q1 2025, while the median payment rose from $100,000 to $250,000. The Q1 median demand was $571,000. Lower payment frequency therefore did not reduce the financial severity of the paid cases in Arete's engagement population.[2]Evidence dated Jun 3, 2026
- 2
Akira and Qilin produced almost one-third of Arete's Q1 engagements — Akira represented 18.3% and Qilin 14.3% of Q1 activity in Arete's chart. Their combined share remained important but declined from more than half in each of Q3 and Q4 2025, showing concentration easing without eliminating either actor as a priority.[2]Evidence dated Jun 3, 2026
- 3
Akira combined high volume with unusually strong payment conversion — Arete reports Akira median demands of $700,000, median payments of $300,000, and payment in almost 48% of Akira engagements. More than half of those paying victims purchased data suppression without a decryptor, showing that stolen-data pressure can drive payment even when recovery is not the objective.[2]Evidence dated Jun 3, 2026
- 4
Professional services led a broad, access-driven victim population — Professional, scientific, and technical services accounted for 21.6% of Arete engagements, followed by manufacturing at 13.6%, wholesale trade at 10.4%, healthcare and social assistance at 8.8%, retail at 8.0%, and construction at 7.2%. Arete assesses most groups as opportunistic and access-vector-driven rather than sector-exclusive.[2]Evidence dated Jun 3, 2026
- 5
Edge exploitation, compromised credentials, and social engineering formed the Q1 access triad — Arete identifies vulnerability exploits, compromised credentials, and social engineering as the leading initial-access classes. Firewalls and VPN systems concentrate risk because they are internet-facing, authentication-connected, and capable of exposing internal enterprise access after compromise.[2]Evidence dated Jun 3, 2026
- 6
Teams impersonation, device-code abuse, and ClickFix moved social engineering beyond ordinary phishing — Arete observed renewed cross-tenant Microsoft Teams help-desk impersonation, OAuth and Quick Assist workflows, and ClickFix campaigns across Windows and macOS. Akira, INC Ransom, Payouts King, and Chaos used Teams-style tactics, while Akira, Qilin, and Interlock adopted ClickFix.[2]Evidence dated Jun 3, 2026
- 7
Fortinet, WatchGuard, and BeyondTrust weaknesses were operational entry paths—not inventory trivia — The report documents Fortinet authentication bypass and older-flaw exploitation, Qilin exploitation of WatchGuard CVE-2025-14733, and Arete-confirmed exploitation of BeyondTrust CVE-2026-1731 linked to a Medusa-associated cluster. Edge remediation must pair patching with access review and hunting.[2]Evidence dated Jun 3, 2026
- 8
The top tier remained stable even as new ransomware brands emerged — Akira, Qilin, PLAY, and INC Ransom remained among Arete's top five groups in every quarter since the second half of 2025. NightSpire posted more than 100 Q1 disclosures, BravoX posted nine while building credibility, and Schrodinger Cat formalized its brand, but established operators still drove most handled activity.[2]Evidence dated Jun 3, 2026
- 9
DragonForce's cartel model and leaked-code reuse lower the cost of operational change — Arete describes DragonForce shifting toward a decentralized partnership model and identifies Conti-derived implementation overlap. Its appendix reports identical ChaCha-like encryption logic, shared command-line behavior, a common mutex, and 99% BinDiff similarity between compared 32-bit DragonForce and Devman samples.[2]Evidence dated Jun 3, 2026
- 10
Most adversarial AI use remained generative and assistive—not autonomous — Arete observed AI accelerating stolen-data analysis, victim prioritization, social engineering, and extortion strategy, while its outlook says most current use remained generative rather than agentic. Defenders should act on measurable workflow acceleration without claiming autonomous intrusions the evidence does not establish.[2]Evidence dated Jun 3, 2026
- 11
Later Arete analysis sharpened how AI shortens malware development and EDR testing — Arete describes threat actors using agent-based AI workflows for Active Directory discovery, iterative development, lab reproduction, and evasion testing. It found no evidence that AI was embedded as an autonomous operator inside victim environments.[8]Evidence dated Jun 12, 2026
- 12
AudiA6 shows ransomware depends on professional laundering infrastructure — Arete's account of the Europol-backed action describes arrests, more than 30 servers, 25 domains, and over €778,000 in frozen or seized cryptocurrency. Financial services, mule accounts, and marketplace infrastructure belong in the ransomware ecosystem map.[7]Evidence dated Jun 23, 2026
- 13
FortiBleed is a credential-compromise problem, not a patch-only problem — Arete's update describes password spraying, configuration exfiltration, packet sniffing, and harvested credentials affecting more than 86,000 devices across 194 countries. Credential resets, historical log review, management-plane restriction, and hunting are required alongside fixes.[6]Evidence dated Jun 30, 2026
- 14
June activity remained distributed despite Akira leading Arete's observations — Arete identified 17 unique groups during June and kept Akira, Qilin, and INC Ransom among the most active. The decision is to maintain a behavior-led watchlist instead of anchoring response plans to one brand.[5]Evidence dated Jul 6, 2026
- 15
BYOVD is being used to disable or evade endpoint defenses — Arete reports Akira and DragonForce using vulnerable drivers in engagements and describes GentleKiller as a framework targeting multiple security products. Driver loading and security-control tampering should be high-priority detection events.[5]Evidence dated Jul 6, 2026
- 16
OAuth tokens can propagate one provider breach into many customer environments — Arete's June review uses the Klue incident to show how stolen Salesforce integration tokens can extend an intrusion through trusted SaaS relationships. Token inventory, revocation, and connected-app telemetry are incident-response requirements.[5]Evidence dated Jul 6, 2026
- 17
FortiBleed links stolen edge credentials to INC and Lynx operations — Arete reports evidence connecting the credential-harvesting campaign to INC and Lynx ransomware operations, including a shared operator and exposed workflow infrastructure. Organizations with affected FortiGate history should investigate credentials and administrative activity even after patching.[4][6]First cited source Jun 30, 2026 · Latest cited source Jul 14, 2026
- 18
Helix makes Microsoft 365 identity the extortion perimeter — Arete describes Helix using vishing, device-code phishing, MFA abuse, and trusted-person impersonation to reach SharePoint Online and exfiltrate data. The practical control boundary is the identity session and cloud application—not only the endpoint.[3]Evidence dated Jul 17, 2026
- 19
Helix may overlap ShinyHunters and BlackFile ecosystems, but the relationship is unresolved — Arete notes operational similarities and possible shared ecosystems while explicitly keeping the connection unconfirmed. Defenders can correlate behaviors without collapsing separate names into one attribution.[3]Evidence dated Jul 17, 2026
- 20
Akira entered the window as the clear volume leader, but not as a monopoly — Arete's Q3 report assigns Akira 32.1% of July engagements, followed by Qilin at 11.3% and Sinobi at 9.4%. The opening month already supports a multi-actor playbook even before Akira's August surge.[9]Evidence dated Dec 3, 2025
- 21
Akira rose above half of Arete's August engagements — Akira reached 52.9% in August, while Qilin represented 15.3% and PLAY 5.9%. Arete tied the spike partly to exploitation and legacy credentials around SonicWall environments, making edge history and credential hygiene central response questions.[9][10]First cited source Sep 8, 2025 · Latest cited source Dec 3, 2025
- 22
Salesloft Drift token theft turned a trusted integration into downstream access — Arete's Q3 analysis describes theft of Salesforce OAuth and refresh tokens associated with the Salesloft Drift campaign. Connected-app inventory, token revocation, and downstream log review are necessary when a SaaS provider is compromised.[9][10]First cited source Sep 8, 2025 · Latest cited source Dec 3, 2025
- 23
CL0P began an Oracle EBS extortion wave tied to CVE-2025-61882 — Arete records extortion emails beginning on 29 September following exploitation of Oracle E-Business Suite. The sequence demonstrates why application remediation must include retrospective data-access review and preparation for delayed extortion contact.[9]Evidence dated Dec 3, 2025
- 24
Akira receded while PLAY and World Leaks gained share — Arete's Q3 report places Akira at 36.6%, Qilin at 11.3%, and both PLAY and World Leaks at 7.0% in September. Extortion-only operations became a larger part of the visible mix even as the leading ransomware brands persisted.[9][11]First cited source Oct 6, 2025 · Latest cited source Dec 3, 2025
- 25
Edge exploitation and SaaS extortion were active at the same time — Arete kept Akira and Qilin among October's leaders while tracking CL0P's Oracle EBS campaign and the Scattered Lapsus$ Hunters/Salesloft activity. Response planning must cover appliance compromise, enterprise applications, and trusted cloud integrations concurrently.[12]Evidence dated Nov 7, 2025
- 26
Operation Endgame removed infrastructure at scale without ending the crimeware market — Arete's account of Season 3 attributes more than 1,000 server disruptions, 20 seized domains, an operator arrest, and millions of stolen credentials to the coordinated action. The takedown imposed cost, but Arete did not treat it as proof that ransomware access supply had stopped.[13]Evidence dated Nov 21, 2025
- 27
Akira led 2025, but Arete still observed a fragmented operator ecosystem — Arete's annual report places Akira at 28.4% and Qilin at 12.8% across 81 named and 52 unnamed actor labels. Akira's Q3 surge mattered, but the number of labels shows why a durable defense cannot depend on a single-brand watchlist.[17]Evidence dated Mar 27, 2026
- 28
Akira exceeded one-third of December activity as RansomHouse returned — Arete reports Akira above one-third of December observations and the top three groups at 57%, alongside RansomHouse's return and emerging React2Shell and MongoBleed exposure. Actor concentration and fast-moving vulnerability response were linked operational concerns.[14][17]First cited source Jan 12, 2026 · Latest cited source Mar 27, 2026
- 29
The top three fell to 34% as LockBit 5 and ClickFix entered the watchlist — Arete identified 17 groups in January, with Akira at 17% and the top three representing only about one-third. LockBit 5 activity and ClickFix/CrashFix social engineering reinforced the need to follow behaviors across changing brands.[15]Evidence dated Feb 5, 2026
- 30
Akira and Qilin again approached half of activity while access paths diversified — Arete's February review places Akira and Qilin at nearly half of observations and highlights Qilin exploitation of WatchGuard CVE-2025-14733 plus Hotta Killer BYOVD activity. Edge remediation and protection against security-driver tampering belong in the same program.[16]Evidence dated Mar 9, 2026
- 31
Twenty-one groups diluted the leading brands and widened the response burden — Arete observed 21 groups in March versus 15 in February, with Akira and Qilin falling from nearly half to just over one-quarter. FortiGate exploitation and Teams/Quick Assist social engineering show that actor-share changes do not simplify the access problem.[18]Evidence dated Apr 6, 2026
- 32
Qilin overtook Akira while four groups generated about half of activity — Arete reports Qilin moving ahead of Akira in April, with Akira, Qilin, INC Ransom, and DragonForce together accounting for roughly half. DragonForce's rise and continued BYOVD use show both concentration and tactical adaptation.[19]Evidence dated May 4, 2026
- 33
Fake JPEG delivery concealed PowerShell and remote-management access — Arete describes attackers using a fake image workflow to execute PowerShell and deploy a trojanized ScreenConnect path. File extension, content, user action, script execution, and remote-tool behavior must be correlated.[21]Evidence dated May 26, 2026
- 34
A Ghost CMS flaw exposed more than 700 sites to ClickFix delivery — Arete's research connects CVE-2026-26980 exploitation across education and technology sites to a ClickFix campaign. A compromised website can become social-engineering infrastructure even when the visitor is not the original intrusion target.[20]Evidence dated May 29, 2026
Source-Bound Exposure and Targeting
Victimology Matrix
This is not a raw victim list. Publicly named organizations are shown when reliable sources identify them, with confirmation and attribution boundaries preserved. Where no defensible name exists, IntelliOS uses the narrowest supported exposure population. Sector or geography matches remain scoping signals; they do not prove compromise.
| Victim / exposure population | Sectors | Geography | Confirmation status | How companies should use it |
|---|---|---|---|---|
| Victim / exposure populationProfessional, scientific, and technical services[2]Evidence dated Jun 3, 2026 | SectorsNAICS professional, scientific, and technical services | GeographyArete Q1 engagement population | Confirmation status21.6% of Arete engagements; cyber-insured casework sample | How companies should use itProtect client data, privileged SaaS, remote administration, professional credentials, and time-sensitive delivery systems. |
| Victim / exposure populationManufacturing organizations[2]Evidence dated Jun 3, 2026 | SectorsManufacturing | GeographyArete Q1 engagement population | Confirmation status13.6% of engagements | How companies should use itSegment production, validate identity and edge access, preserve manual operations, and test recovery without trusted-domain availability. |
| Victim / exposure populationWholesale trade organizations[2]Evidence dated Jun 3, 2026 | SectorsWholesale trade | GeographyArete Q1 engagement population | Confirmation status10.4% of engagements | How companies should use itProtect warehouse, logistics, payment, supplier, and customer-integrated workflows from interruption and fraud. |
| Victim / exposure populationHealthcare and social-assistance organizations[2]Evidence dated Jun 3, 2026 | SectorsHealthcare and social assistance | GeographyArete Q1 engagement population | Confirmation status8.8% of engagements | How companies should use itPrioritize care continuity, regulated-data exposure, identity, vendor access, and downtime decision authority. |
| Victim / exposure populationRetail and construction organizations[2]Evidence dated Jun 3, 2026 | SectorsRetail trade; construction | GeographyArete Q1 engagement population | Confirmation status8.0% retail and 7.2% construction | How companies should use itSecure distributed identities, payments, remote sites, contractors, VPN access, and recovery-critical cloud services. |
| Victim / exposure populationMicrosoft 365 and SharePoint users[3]Evidence dated Jul 17, 2026 | SectorsCross-industry | GeographyNot bounded by Arete to one region | Confirmation statusTargeting and method reported; individual victim claims require verification | How companies should use itPrioritize vishing-resistant help-desk controls, device-code restrictions, session review, and SharePoint exfiltration telemetry. |
| Victim / exposure populationInternet-facing FortiGate and SSL-VPN operators[4][5][6]First cited source Jun 30, 2026 · Latest cited source Jul 14, 2026 | SectorsCross-industry, including managed and distributed environments | Geography194 countries in cited exposure reporting | Confirmation statusExposure and credential collection do not prove downstream intrusion | How companies should use itReset credentials, review historical administrative access, restrict management interfaces, and investigate configuration changes. |
| Victim / exposure populationSaaS customers connected through trusted integrations[5]Evidence dated Jul 6, 2026 | SectorsTechnology, professional services, data-rich organizations | GeographyGlobal | Confirmation statusKlue disclosed an incident; downstream scope remains company-specific | How companies should use itInventory OAuth grants and third-party applications, revoke affected tokens, and retain audit logs. |
| Victim / exposure populationOrganizations dependent on endpoint security controls[2][5][8]First cited source Jun 3, 2026 · Latest cited source Jul 6, 2026 | SectorsCross-industry | GeographyGlobal | Confirmation statusArete reports BYOVD observations in engagements | How companies should use itBlock vulnerable drivers and alert on security-service disablement, kernel-driver loading, and policy tampering. |
Distinct Operational Records
Arete Research Themes & Operations
Akira's high-conversion ransomware operation
Akira led Arete's Q1 activity at 18.3%, carried a $700,000 median demand and $300,000 median payment, and received payment in almost 48% of engagements. More than half of paying victims purchased data suppression without a decryptor.[2]Evidence dated Jun 3, 2026
Qilin exploitation of WatchGuard Firebox
Arete observed Qilin exploiting WatchGuard CVE-2025-14733 in Q1 to gain initial access and facilitate ransomware deployment.[2]Evidence dated Jun 3, 2026
Cross-tenant Teams help-desk impersonation
Akira, INC Ransom, Payouts King, and Chaos used refined Teams interactions, email bombing, OAuth flows, and Quick Assist to turn trusted collaboration into initial access.[2]Evidence dated Jun 3, 2026
ClickFix, CrashFix, and InstallFix evolution
Arete describes urgent fake prompts, browser crashes, sponsored malicious installers, Python RAT delivery, infostealers, and expanded Windows/macOS targeting adopted by Akira, Qilin, and Interlock.[2]Evidence dated Jun 3, 2026
FortiBleed credential harvesting
Password spraying, configuration theft, packet sniffing, credential reuse, and possible ransomware follow-on activity.[4][6]First cited source Jun 30, 2026 · Latest cited source Jul 14, 2026
Helix SharePoint extortion
Vishing and device-code phishing provide cloud access followed by SharePoint discovery and data theft.[3]Evidence dated Jul 17, 2026
June ransomware operations
Akira led a distributed field that also included Qilin, INC Ransom, KryBit, Settra, and Icarus in Arete's observations.[5]Evidence dated Jul 6, 2026
AudiA6 financial infrastructure
A law-enforcement action targeted laundering, servers, domains, and mule-account infrastructure supporting cybercrime monetization.[7]Evidence dated Jun 23, 2026
Source-Bound Actor Context
Threat Actors, Operators & Decision Owners
Akira
Arete's leading Q1 actor at 18.3% of engagements, with unusually high payment conversion and later BYOVD observations. Activity normalized from its Q3 2025 surge but remained the largest monthly share through Q1.[2][5]First cited source Jun 3, 2026 · Latest cited source Jul 6, 2026
Qilin
Second in Q1 at 14.3%; Arete observed a February increase tied to WatchGuard Firebox targeting, especially CVE-2025-14733.[2][5]First cited source Jun 3, 2026 · Latest cited source Jul 6, 2026
PLAY
Represented 7.1% of Q1 engagements and remained a top-five group since the second half of 2025, yet collected payment in only 11% of Arete engagements.[2]Evidence dated Jun 3, 2026
DragonForce
Represented 5.6% of Q1 activity. Arete describes a cartel-style affiliate model, Conti-derived code overlap, zero Q1 payments in its engagements, and later BYOVD use.[2][5]First cited source Jun 3, 2026 · Latest cited source Jul 6, 2026
INC Ransom and Lynx
Arete reports operational and malware-lineage connections relevant to FortiBleed follow-on risk.[4]Evidence dated Jul 14, 2026
NightSpire
Emerging operator that posted more than 100 Q1 victim disclosures; Arete describes evidence suggesting an Rbfs rebrand, but leak-site counts remain actor claims rather than incident totals.[2]Evidence dated Jun 3, 2026
BravoX
Early-stage RaaS brand that posted nine Q1 victims while building a standalone leak platform and seeking credibility; future affiliate traction remained uncertain.[2]Evidence dated Jun 3, 2026
Schrodinger Cat
GlobeImposter-associated subgroup formalizing its brand and leak site while focusing on enterprise encryption and extortion.[2]Evidence dated Jun 3, 2026
Helix
Newly reported identity-led extortion group focused on Microsoft 365 and SharePoint data.[3]Evidence dated Jul 17, 2026
DragonForce and The Gentlemen
Appear in Arete's discussion of BYOVD and EDR-disabling tradecraft.[5]Evidence dated Jul 6, 2026
Enterprise Exposure
Affected Technologies & Trust Boundaries
Fortinet FortiGate and FortiCloud SSO
Arete highlights authentication-bypass, pre-authentication, older unpatched flaws, brute force, credential reuse, infostealer datasets, and secondary RDP access as a combined edge-risk problem.[2][4][5][6]First cited source Jun 3, 2026 · Latest cited source Jul 14, 2026
WatchGuard Firebox and Fireware OS
CVE-2025-14733 and CVE-2025-9242 created unauthenticated RCE risk in edge infrastructure; Arete observed Qilin incorporating WatchGuard exploitation into intrusion workflows.[2]Evidence dated Jun 3, 2026
BeyondTrust Remote Support and Privileged Remote Access
Arete confirmed Q1 exploitation of CVE-2026-1731 with reverse shells and post-exploitation tooling and linked the activity to a Medusa-associated cluster.[2]Evidence dated Jun 3, 2026
Microsoft Teams, OAuth, device code, and Quick Assist
Cross-tenant messaging and legitimate assistance/authentication workflows let attackers impersonate support staff and establish identity-backed access.[2][3]First cited source Jun 3, 2026 · Latest cited source Jul 17, 2026
Windows, macOS, browsers, and terminal workflows
ClickFix variants use fake CAPTCHAs, browser crashes, troubleshooting prompts, sponsored installers, and clipboard-driven commands across platforms.[2]Evidence dated Jun 3, 2026
FortiGate and SSL-VPN
Treat prior credential exposure and configuration access as an investigation trigger, not only a patch task.[4][5][6]First cited source Jun 30, 2026 · Latest cited source Jul 14, 2026
Microsoft 365 and SharePoint Online
Device-code phishing, session abuse, and automated data exfiltration move the control plane into cloud identity.[3]Evidence dated Jul 17, 2026
OAuth-connected SaaS platforms
Stolen integration tokens can create downstream customer impact without exploiting each customer directly.[5]Evidence dated Jul 6, 2026
Endpoint drivers and EDR controls
Vulnerable-driver abuse and AI-assisted testing target the reliability of endpoint defenses.[2][5][8]First cited source Jun 3, 2026 · Latest cited source Jul 6, 2026
Conti, DragonForce, and Devman ransomware code
Arete's appendix documents shared encryption, hashing, command-line, mutex, SMB propagation, and decryption characteristics while distinguishing newer Devman divergence.[2]Evidence dated Jun 3, 2026
Current Carry-Forward Watchlist
Top 10 Specific Threats to Monitor
Prioritized source-backed developments that convert the rolling activity record into named operational monitoring requirements.
| # | Threat / Category | Why It Matters | What to Monitor | IntelliOS Coverage |
|---|---|---|---|---|
| 1 | Threat / Category Q1 observation · ransom economics Payments became less frequent but materially larger when victims paid[2]Evidence dated Jun 3, 2026 | Why it mattersArete reports a 31% Q1 2026 payment rate, down from 33% in Q1 2025, while the median payment rose from $100,000 to $250,000. The Q1 median demand was $571,000. Lower payment frequency therefore did not reduce the financial severity of the paid cases in Arete's engagement population. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 2 | Threat / Category Q1 observation · actor concentration Akira and Qilin produced almost one-third of Arete's Q1 engagements[2]Evidence dated Jun 3, 2026 | Why it mattersAkira represented 18.3% and Qilin 14.3% of Q1 activity in Arete's chart. Their combined share remained important but declined from more than half in each of Q3 and Q4 2025, showing concentration easing without eliminating either actor as a priority. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 3 | Threat / Category Q1 observation · payment leverage Akira combined high volume with unusually strong payment conversion[2]Evidence dated Jun 3, 2026 | Why it mattersArete reports Akira median demands of $700,000, median payments of $300,000, and payment in almost 48% of Akira engagements. More than half of those paying victims purchased data suppression without a decryptor, showing that stolen-data pressure can drive payment even when recovery is not the objective. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 4 | Threat / Category Q1 observation · victimology Professional services led a broad, access-driven victim population[2]Evidence dated Jun 3, 2026 | Why it mattersProfessional, scientific, and technical services accounted for 21.6% of Arete engagements, followed by manufacturing at 13.6%, wholesale trade at 10.4%, healthcare and social assistance at 8.8%, retail at 8.0%, and construction at 7.2%. Arete assesses most groups as opportunistic and access-vector-driven rather than sector-exclusive. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 5 | Threat / Category Q1 observation · initial access Edge exploitation, compromised credentials, and social engineering formed the Q1 access triad[2]Evidence dated Jun 3, 2026 | Why it mattersArete identifies vulnerability exploits, compromised credentials, and social engineering as the leading initial-access classes. Firewalls and VPN systems concentrate risk because they are internet-facing, authentication-connected, and capable of exposing internal enterprise access after compromise. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 6 | Threat / Category Q1 observation · identity-first intrusion Teams impersonation, device-code abuse, and ClickFix moved social engineering beyond ordinary phishing[2]Evidence dated Jun 3, 2026 | Why it mattersArete observed renewed cross-tenant Microsoft Teams help-desk impersonation, OAuth and Quick Assist workflows, and ClickFix campaigns across Windows and macOS. Akira, INC Ransom, Payouts King, and Chaos used Teams-style tactics, while Akira, Qilin, and Interlock adopted ClickFix. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 7 | Threat / Category Q1 observation · edge vulnerabilities Fortinet, WatchGuard, and BeyondTrust weaknesses were operational entry paths—not inventory trivia[2]Evidence dated Jun 3, 2026 | Why it mattersThe report documents Fortinet authentication bypass and older-flaw exploitation, Qilin exploitation of WatchGuard CVE-2025-14733, and Arete-confirmed exploitation of BeyondTrust CVE-2026-1731 linked to a Medusa-associated cluster. Edge remediation must pair patching with access review and hunting. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 8 | Threat / Category Q1 observation · actor persistence The top tier remained stable even as new ransomware brands emerged[2]Evidence dated Jun 3, 2026 | Why it mattersAkira, Qilin, PLAY, and INC Ransom remained among Arete's top five groups in every quarter since the second half of 2025. NightSpire posted more than 100 Q1 disclosures, BravoX posted nine while building credibility, and Schrodinger Cat formalized its brand, but established operators still drove most handled activity. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 9 | Threat / Category Q1 observation · RaaS evolution DragonForce's cartel model and leaked-code reuse lower the cost of operational change[2]Evidence dated Jun 3, 2026 | Why it mattersArete describes DragonForce shifting toward a decentralized partnership model and identifies Conti-derived implementation overlap. Its appendix reports identical ChaCha-like encryption logic, shared command-line behavior, a common mutex, and 99% BinDiff similarity between compared 32-bit DragonForce and Devman samples. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 10 | Threat / Category Q1 observation · AI evidence boundary Most adversarial AI use remained generative and assistive—not autonomous[2]Evidence dated Jun 3, 2026 | Why it mattersArete observed AI accelerating stolen-data analysis, victim prioritization, social engineering, and extortion strategy, while its outlook says most current use remained generative rather than agentic. Defenders should act on measurable workflow acceleration without claiming autonomous intrusions the evidence does not establish. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 11 | Threat / Category AI-assisted offense Later Arete analysis sharpened how AI shortens malware development and EDR testing[8]Evidence dated Jun 12, 2026 | Why it mattersArete describes threat actors using agent-based AI workflows for Active Directory discovery, iterative development, lab reproduction, and evasion testing. It found no evidence that AI was embedded as an autonomous operator inside victim environments. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 12 | Threat / Category Criminal infrastructure disruption AudiA6 shows ransomware depends on professional laundering infrastructure[7]Evidence dated Jun 23, 2026 | Why it mattersArete's account of the Europol-backed action describes arrests, more than 30 servers, 25 domains, and over €778,000 in frozen or seized cryptocurrency. Financial services, mule accounts, and marketplace infrastructure belong in the ransomware ecosystem map. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 13 | Threat / Category Credential exposure FortiBleed is a credential-compromise problem, not a patch-only problem[6]Evidence dated Jun 30, 2026 | Why it mattersArete's update describes password spraying, configuration exfiltration, packet sniffing, and harvested credentials affecting more than 86,000 devices across 194 countries. Credential resets, historical log review, management-plane restriction, and hunting are required alongside fixes. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 14 | Threat / Category June observation · crimeware trend June activity remained distributed despite Akira leading Arete's observations[5]Evidence dated Jul 6, 2026 | Why it mattersArete identified 17 unique groups during June and kept Akira, Qilin, and INC Ransom among the most active. The decision is to maintain a behavior-led watchlist instead of anchoring response plans to one brand. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 15 | Threat / Category June observation · trusted software abuse BYOVD is being used to disable or evade endpoint defenses[5]Evidence dated Jul 6, 2026 | Why it mattersArete reports Akira and DragonForce using vulnerable drivers in engagements and describes GentleKiller as a framework targeting multiple security products. Driver loading and security-control tampering should be high-priority detection events. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 16 | Threat / Category June observation · SaaS supply chain OAuth tokens can propagate one provider breach into many customer environments[5]Evidence dated Jul 6, 2026 | Why it mattersArete's June review uses the Klue incident to show how stolen Salesforce integration tokens can extend an intrusion through trusted SaaS relationships. Token inventory, revocation, and connected-app telemetry are incident-response requirements. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 17 | Threat / Category Ransomware access ecosystem FortiBleed links stolen edge credentials to INC and Lynx operations[4][6]First cited source Jun 30, 2026 · Latest cited source Jul 14, 2026 | Why it mattersArete reports evidence connecting the credential-harvesting campaign to INC and Lynx ransomware operations, including a shared operator and exposed workflow infrastructure. Organizations with affected FortiGate history should investigate credentials and administrative activity even after patching. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 18 | Threat / Category Identity-led extortion Helix makes Microsoft 365 identity the extortion perimeter[3]Evidence dated Jul 17, 2026 | Why it mattersArete describes Helix using vishing, device-code phishing, MFA abuse, and trusted-person impersonation to reach SharePoint Online and exfiltrate data. The practical control boundary is the identity session and cloud application—not only the endpoint. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 19 | Threat / Category Actor identity boundary Helix may overlap ShinyHunters and BlackFile ecosystems, but the relationship is unresolved[3]Evidence dated Jul 17, 2026 | Why it mattersArete notes operational similarities and possible shared ecosystems while explicitly keeping the connection unconfirmed. Defenders can correlate behaviors without collapsing separate names into one attribution. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 20 | Threat / Category July observation · actor concentration Akira entered the window as the clear volume leader, but not as a monopoly[9]Evidence dated Dec 3, 2025 | Why it mattersArete's Q3 report assigns Akira 32.1% of July engagements, followed by Qilin at 11.3% and Sinobi at 9.4%. The opening month already supports a multi-actor playbook even before Akira's August surge. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 21 | Threat / Category August observation · actor surge Akira rose above half of Arete's August engagements[9][10]First cited source Sep 8, 2025 · Latest cited source Dec 3, 2025 | Why it mattersAkira reached 52.9% in August, while Qilin represented 15.3% and PLAY 5.9%. Arete tied the spike partly to exploitation and legacy credentials around SonicWall environments, making edge history and credential hygiene central response questions. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 22 | Threat / Category August observation · SaaS supply chain Salesloft Drift token theft turned a trusted integration into downstream access[9][10]First cited source Sep 8, 2025 · Latest cited source Dec 3, 2025 | Why it mattersArete's Q3 analysis describes theft of Salesforce OAuth and refresh tokens associated with the Salesloft Drift campaign. Connected-app inventory, token revocation, and downstream log review are necessary when a SaaS provider is compromised. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 23 | Threat / Category September observation · enterprise extortion CL0P began an Oracle EBS extortion wave tied to CVE-2025-61882[9]Evidence dated Dec 3, 2025 | Why it mattersArete records extortion emails beginning on 29 September following exploitation of Oracle E-Business Suite. The sequence demonstrates why application remediation must include retrospective data-access review and preparation for delayed extortion contact. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 24 | Threat / Category September observation · actor mix Akira receded while PLAY and World Leaks gained share[9][11]First cited source Oct 6, 2025 · Latest cited source Dec 3, 2025 | Why it mattersArete's Q3 report places Akira at 36.6%, Qilin at 11.3%, and both PLAY and World Leaks at 7.0% in September. Extortion-only operations became a larger part of the visible mix even as the leading ransomware brands persisted. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 25 | Threat / Category October observation · parallel campaigns Edge exploitation and SaaS extortion were active at the same time[12]Evidence dated Nov 7, 2025 | Why it mattersArete kept Akira and Qilin among October's leaders while tracking CL0P's Oracle EBS campaign and the Scattered Lapsus$ Hunters/Salesloft activity. Response planning must cover appliance compromise, enterprise applications, and trusted cloud integrations concurrently. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 26 | Threat / Category Law-enforcement action · malware infrastructure Operation Endgame removed infrastructure at scale without ending the crimeware market[13]Evidence dated Nov 21, 2025 | Why it mattersArete's account of Season 3 attributes more than 1,000 server disruptions, 20 seized domains, an operator arrest, and millions of stolen credentials to the coordinated action. The takedown imposed cost, but Arete did not treat it as proof that ransomware access supply had stopped. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 27 | Threat / Category Full-year observation · actor landscape Akira led 2025, but Arete still observed a fragmented operator ecosystem[17]Evidence dated Mar 27, 2026 | Why it mattersArete's annual report places Akira at 28.4% and Qilin at 12.8% across 81 named and 52 unnamed actor labels. Akira's Q3 surge mattered, but the number of labels shows why a durable defense cannot depend on a single-brand watchlist. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 28 | Threat / Category December observation · renewed concentration Akira exceeded one-third of December activity as RansomHouse returned[14][17]First cited source Jan 12, 2026 · Latest cited source Mar 27, 2026 | Why it mattersArete reports Akira above one-third of December observations and the top three groups at 57%, alongside RansomHouse's return and emerging React2Shell and MongoBleed exposure. Actor concentration and fast-moving vulnerability response were linked operational concerns. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 29 | Threat / Category January observation · broader actor mix The top three fell to 34% as LockBit 5 and ClickFix entered the watchlist[15]Evidence dated Feb 5, 2026 | Why it mattersArete identified 17 groups in January, with Akira at 17% and the top three representing only about one-third. LockBit 5 activity and ClickFix/CrashFix social engineering reinforced the need to follow behaviors across changing brands. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 30 | Threat / Category February observation · edge and endpoint defense Akira and Qilin again approached half of activity while access paths diversified[16]Evidence dated Mar 9, 2026 | Why it mattersArete's February review places Akira and Qilin at nearly half of observations and highlights Qilin exploitation of WatchGuard CVE-2025-14733 plus Hotta Killer BYOVD activity. Edge remediation and protection against security-driver tampering belong in the same program. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 31 | Threat / Category March observation · distribution shift Twenty-one groups diluted the leading brands and widened the response burden[18]Evidence dated Apr 6, 2026 | Why it mattersArete observed 21 groups in March versus 15 in February, with Akira and Qilin falling from nearly half to just over one-quarter. FortiGate exploitation and Teams/Quick Assist social engineering show that actor-share changes do not simplify the access problem. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 32 | Threat / Category April observation · leadership change Qilin overtook Akira while four groups generated about half of activity[19]Evidence dated May 4, 2026 | Why it mattersArete reports Qilin moving ahead of Akira in April, with Akira, Qilin, INC Ransom, and DragonForce together accounting for roughly half. DragonForce's rise and continued BYOVD use show both concentration and tactical adaptation. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 33 | Threat / Category Technical campaign · deceptive files Fake JPEG delivery concealed PowerShell and remote-management access[21]Evidence dated May 26, 2026 | Why it mattersArete describes attackers using a fake image workflow to execute PowerShell and deploy a trojanized ScreenConnect path. File extension, content, user action, script execution, and remote-tool behavior must be correlated. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 34 | Threat / Category Technical campaign · web compromise A Ghost CMS flaw exposed more than 700 sites to ClickFix delivery[20]Evidence dated May 29, 2026 | Why it mattersArete's research connects CVE-2026-26980 exploitation across education and technology sites to a ClickFix campaign. A compromised website can become social-engineering infrastructure even when the visitor is not the original intrusion target. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Arete exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
Operational Standards from the Evidence
Best Practices and Lessons Learned
The practices below convert the retained public evidence into repeatable executive standards. Each lesson remains bounded to its cited sources.
- 1
Best Practice
Use the report's population correctly[2]Evidence dated Jun 3, 2026
Lesson Learned
Arete's statistics describe anonymized extortion engagements, primarily among cyber-insured organizations, and exclude pre-ransomware disruptions from the totals.
Minimum Operating Standard
Label every number as Arete engagement data; preserve the reporting period, denominator, inclusion rules, and bias statement in executive use.
- 2
Best Practice
Prioritize the access path before the actor brand[2]Evidence dated Jun 3, 2026
Lesson Learned
Arete finds most groups opportunistic and focused on exploitable vectors rather than one sector.
Minimum Operating Standard
Rank internet-facing edge systems, identity workflows, credentials, collaboration platforms, trusted integrations, and recovery dependencies by reachability and consequence.
- 3
Best Practice
Predefine ransom-decision evidence[2]Evidence dated Jun 3, 2026
Lesson Learned
Payment frequency fell while median paid amounts rose, and many Akira payments bought suppression rather than decryption.
Minimum Operating Standard
Require verified impact, recovery feasibility, stolen-data scope, legal/sanctions review, actor-specific reliability, negotiation authority, and documented alternatives before considering payment.
- 4
Best Practice
Treat exposed credentials as an incident lead[4][6]First cited source Jun 30, 2026 · Latest cited source Jul 14, 2026
Lesson Learned
Patching does not revoke credentials already harvested.
Minimum Operating Standard
Require resets, historical authentication review, administrative configuration review, and documented closure criteria.
- 5
Best Practice
Make cloud sessions first-class evidence[2][3][5]First cited source Jun 3, 2026 · Latest cited source Jul 17, 2026
Lesson Learned
Identity-led extortion can avoid conventional endpoint malware.
Minimum Operating Standard
Retain sign-in, token, connected-app, SharePoint, mailbox, Teams, and remote-assistance evidence long enough to investigate delayed discovery.
- 6
Best Practice
Control device-code, Teams, and help-desk workflows[2][3]First cited source Jun 3, 2026 · Latest cited source Jul 17, 2026
Lesson Learned
Attackers exploit legitimate authentication, collaboration, and trusted voices.
Minimum Operating Standard
Restrict device-code flows and external collaboration, require phishing-resistant MFA, verify callbacks, govern Quick Assist, and rehearse help-desk impersonation.
- 7
Best Practice
Contain ClickFix-style user execution[2]Evidence dated Jun 3, 2026
Lesson Learned
Urgent fake prompts can bypass traditional controls by convincing users to run legitimate tools themselves.
Minimum Operating Standard
Block browser-to-shell patterns, control interpreters and unsigned installers, detect clipboard-driven execution, and train users to stop when instructions demand terminal commands.
- 8
Best Practice
Block vulnerable drivers[2][5]First cited source Jun 3, 2026 · Latest cited source Jul 6, 2026
Lesson Learned
Signed drivers can become an EDR bypass path.
Minimum Operating Standard
Maintain a blocklist, monitor kernel-driver loading, and test alerts for endpoint-control disablement.
- 9
Best Practice
Map laundering and extortion dependencies[7]Evidence dated Jun 23, 2026
Lesson Learned
Ransomware operations depend on infrastructure beyond the encryptor.
Minimum Operating Standard
Include wallets, negotiation portals, mule accounts, infrastructure, and law-enforcement coordination in the incident playbook.
- 10
Best Practice
Describe AI assistance precisely[2][8]First cited source Jun 3, 2026 · Latest cited source Jun 12, 2026
Lesson Learned
Arete's evidence supports generative and workflow acceleration more strongly than autonomous victim-side operation.
Minimum Operating Standard
State what the model did, where it operated, and what evidence supports the conclusion; treat AI inputs as untrusted and monitor AI data flows.
Automation Transparency
AI Agent Run Status
| Agent | Arete Rolling Intelligence Card Publisher |
|---|---|
| Status | Active · rolling one-year automation |
| Cadence | Weekly on Monday at midday ET |
| Previous run | 26 Jul 2026 · material revision · Run arete-publisher-activity-2026-07-26-one-year-archive-backfill |
| Previous result | Backfilled Arete's complete rolling-year archive with the Q3 2025 and 2025 Annual Crimeware Reports, monthly July 2025–June 2026 observations, and May technical research; rebuilt the chronology around observation-period dates while retaining publication dates in Citations. |
| What the previous run found |
|
| Next run | Weekly on Monday at midday ET |
| Sources monitored |
|
| Publication and alert policy | Check weekly on monday at midday et. Publish and alert only when a new Arete publication materially changes an actor, campaign, technology, initial-access, victimology, impact, response, resilience, or executive conclusion. No-change checks are logged but do not email subscribers. |
Related Intelligence and CARDS Records
Other IntelliOS Products
Rolling Intelligence
Government Cybersecurity Actions & Advisories
Official advisories, exploited technologies, deadlines, and government response priorities that can validate or constrain publisher reporting.
Open productCARDS
Threat Actor Cards
Canonical actor identities, aliases, attribution boundaries, behaviors, relationships, and linked campaigns.
Open productCARDS Actor Record
Akira Actor Card
Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.
Open productCARDS Actor Record
Qilin Actor Card
Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.
Open productCARDS Actor Record
INC Ransom Actor Card
Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.
Open productCARDS Actor Record
Lynx Actor Card
Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.
Open productPublication History
Version Change Log
| Version | Date | Change | Monitoring |
|---|---|---|---|
| Versionv1 | Date26 Jul 2026 | ChangeCreated the Arete rolling one-year publisher card with Research Framing, Timeline, BLUF, Executive Summary, top-ten findings, victimology, campaigns, actors, technologies, access vectors, operational practices, AI agent status, and citations. | MonitoringWeekly on Monday at midday ET; material-change-only Page Alerts. |
| Versionv3 | Date26 Jul 2026 | ChangeBackfilled Arete's complete rolling-year archive with the Q3 2025 and 2025 Annual Crimeware Reports, monthly July 2025–June 2026 observations, and May technical research; rebuilt the chronology around observation-period dates while retaining publication dates in Citations. | MonitoringWeekly on Monday at midday ET; material-change-only Page Alerts. |
Citations
Retained Sources and Claim Treatment
| # | Publisher | Published | Publication / Evidence | Why Used / Claim Treatment | Source |
|---|---|---|---|---|---|
| Source1 | PublisherArete | PublishedNot available | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentAuthoritative first-party corpus index monitored weekly. Individual publications control factual claims. | SourceArete Cybersecurity Resources and Reports https://areteir.com/resources/list |
| Source2 | PublisherArete | Published2026-06-03 | Publication / evidenceSource indexincident response | Why used / claim treatmentPrimary analytic source for this edition. Arete derives its statistics from anonymized ransomware and extortion incident-response engagements and excludes pre-ransomware disruptions from the statistical population. The sample primarily represents cyber-insured organizations and is not a global incident census. External research cited inside the report remains third-party evidence. | SourceArete's 2026 Q1 Crimeware Report — Full Report https://6288364.fs1.hubspotusercontent-na1.net/hubfs/6288364/Threat%20Intel%20Reports/Arete_Crimeware_Report%20_Q1_2026.pdf |
| Source3 | PublisherArete | Published2026-07-17 | Publication / evidenceSource indexprimary research | Why used / claim treatmentSource-qualified analysis of a newly reported extortion group. Relationships to other actor ecosystems remain unconfirmed. | SourceHelix Extortion Group Debuts in SharePoint Data Theft Attacks https://areteir.com/resources/helix-extortion-group-debuts-in-sharepoint-data-theft-attacks |
| Source4 | PublisherArete | Published2026-07-14 | Publication / evidenceSource indexprimary research | Why used / claim treatmentArete synthesis of reported campaign evidence. Device and attribution counts remain qualified to the cited research. | SourceFortiBleed Campaign Linked to INC and Lynx Ransomware Operations https://areteir.com/resources/fortibleed-campaign-linked-to-inc-and-lynx-ransomware-operations |
| Source5 | PublisherArete | Published2026-07-06 | Publication / evidenceSource indexincident response | Why used / claim treatmentMonthly Arete observations and internally sourced trend statements; activity counts are not a universal ransomware census. | SourceRansomware Trends & Data Insights: June 2026 https://areteir.com/resources/ransomware-trends-data-insights-june-2026 |
| Source6 | PublisherArete | Published2026-06-30 | Publication / evidenceSource indexprimary research | Why used / claim treatmentCampaign update combining public reporting with Arete's defensive interpretation. Exposure is not proof of compromise. | SourceUpdate on FortiBleed Credential Exposure https://areteir.com/resources/update-on-fortibleed-credential-exposure |
| Source7 | PublisherArete | Published2026-06-23 | Publication / evidenceSource indexprimary research | Why used / claim treatmentArete analysis of an official disruption. Seizure, arrest, and processing figures remain attributed to authorities. | SourceEuropol Disrupts AudiA6 Crypto Laundering Service https://areteir.com/resources/europol-disrupts-audia6-crypto-laundering-service |
| Source8 | PublisherArete | Published2026-06-12 | Publication / evidenceSource indexprimary research | Why used / claim treatmentSource-qualified analysis of AI-assisted development and evasion. It does not establish autonomous AI inside victim environments. | SourceThreat Actors Leverage AI for EDR Evasion https://areteir.com/resources/threat-actors-leverage-ai-for-edr-evasion |
| Source9 | PublisherArete | Published2025-12-03 | Publication / evidenceSource indexincident response | Why used / claim treatmentPrimary first-party evidence for Arete-handled activity observed from 1 July through 30 September 2025. Percentages describe Arete's engagement population, not global ransomware prevalence. | SourceArete Q3 2025 Crimeware Report — Full Report https://6288364.fs1.hubspotusercontent-na1.net/hubfs/6288364/Threat%20Intel%20Reports/Arete_Q3_2025_Crimeware_Report.pdf |
| Source10 | PublisherArete | Published2025-09-08 | Publication / evidenceSource indexincident response | Why used / claim treatmentMonthly Arete observations for August 2025. Publication followed the observation month; counts are not a universal census. | SourceRansomware Trends & Data Insights: August 2025 https://areteir.com/resources/august-2025-ransomware-trends-data-insights |
| Source11 | PublisherArete | Published2025-10-06 | Publication / evidenceSource indexincident response | Why used / claim treatmentMonthly Arete observations for September 2025. Extortion-only and actor-share statements remain bounded to Arete's evidence. | SourceRansomware Trends & Data Insights: September 2025 https://areteir.com/resources/ransomware-trends-data-insights-september-2025 |
| Source12 | PublisherArete | Published2025-11-07 | Publication / evidenceSource indexincident response | Why used / claim treatmentMonthly Arete observations for October 2025, including attributed campaign context. External actor claims remain qualified. | SourceRansomware Trends & Data Insights: October 2025 https://areteir.com/resources/october-2025-ransomware-trends-data-insights |
| Source13 | PublisherArete | Published2025-11-21 | Publication / evidenceSource indexprimary research | Why used / claim treatmentArete analysis of official law-enforcement action. Infrastructure, arrest, and credential figures remain attributed to the participating authorities. | SourceOperation Endgame Season 3 https://areteir.com/article/operation-endgame-season-3/ |
| Source14 | PublisherArete | Published2026-01-12 | Publication / evidenceSource indexincident response | Why used / claim treatmentMonthly Arete observations for December 2025. Vulnerability and actor reporting establishes defensive relevance, not local compromise. | SourceRansomware Trends & Data Insights: December 2025 https://areteir.com/resources/ransomware-trends-data-insights-december-2025 |
| Source15 | PublisherArete | Published2026-02-05 | Publication / evidenceSource indexincident response | Why used / claim treatmentMonthly Arete observations for January 2026. Group shares describe Arete's stated population. | SourceRansomware Trends & Data Insights: January 2026 https://areteir.com/resources/ransomware-trends-data-insights-january-2026 |
| Source16 | PublisherArete | Published2026-03-09 | Publication / evidenceSource indexincident response | Why used / claim treatmentMonthly Arete observations for February 2026, including source-qualified vulnerability and BYOVD reporting. | SourceRansomware Trends & Data Insights: February 2026 https://areteir.com/resources/ransomware-trends-data-insights-february-2026 |
| Source17 | PublisherArete | Published2026-03-27 | Publication / evidenceSource indexincident response | Why used / claim treatmentFirst-party annual synthesis of Arete's 2025 ransomware and extortion engagement population. Actor, sector, demand, payment, and disclosure statistics are not a global incident census. | SourceArete 2025 Annual Crimeware Report — Full Report https://6288364.fs1.hubspotusercontent-na1.net/hubfs/6288364/Threat%20Intel%20Reports/Arete_Annual_Report%20_2025.pdf |
| Source18 | PublisherArete | Published2026-04-06 | Publication / evidenceSource indexincident response | Why used / claim treatmentMonthly Arete observations for March 2026. Actor and access findings remain bounded to Arete's stated evidence. | SourceRansomware Trends & Data Insights: March 2026 https://areteir.com/resources/ransomware-trends-data-insights-march-2026 |
| Source19 | PublisherArete | Published2026-05-04 | Publication / evidenceSource indexincident response | Why used / claim treatmentMonthly Arete observations for April 2026, including group-share and BYOVD findings. | SourceRansomware Trends & Data Insights: April 2026 https://areteir.com/resources/ransomware-trends-data-insights-april-2026 |
| Source20 | PublisherArete | Published2026-05-29 | Publication / evidenceSource indexprimary research | Why used / claim treatmentTechnical campaign analysis of compromised websites and ClickFix delivery. Affected-site observations do not establish downstream victim compromise. | SourceCMS Vulnerability Leads to ClickFix Campaign https://areteir.com/resources/cms-vulnerability-leads-to-clickfix-campaign |
| Source21 | PublisherArete | Published2026-05-26 | Publication / evidenceSource indexprimary research | Why used / claim treatmentTechnical campaign analysis of PowerShell-based delivery and remote-management-tool abuse. Campaign indicators do not establish local compromise. | SourceThreat Actors Leverage Fake JPEG Files for Initial Access https://areteir.com/resources/threat-actors-leverage-fake-jpeg-files-for-initial-access |
