| 1 | Threat / Category Actor momentum The Gentlemen leak-site and affiliate activity[1]Evidence dated Jul 9, 2026 | Why it mattersA fast-growing RaaS and access-broker operation led Check Point’s June published-attack dataset. | What to monitorNew victim posts; affiliate recruitment; negotiation or infrastructure changes; updated Windows, Linux, or ESXi capability; new access inventory claims. | IntelliOS coverage |
| 2 | Threat / Category Established RaaS Qilin activity and affiliate movement[1][8]First cited source Jul 9, 2026 · Latest cited source Jul 27, 2026 | Why it mattersQilin remained second in Check Point’s June dataset and Black Kite separately reports major annual growth for Qilin in its disclosure cohort. | What to monitorLeak-site changes; affiliate recruitment; rebrands; shared infrastructure; movement of known affiliates or access brokers; Qilin mentions in edge-exploitation reporting. | IntelliOS coverage |
| 3 | Threat / Category Initial access Email, malicious links, and AI-assisted impersonation[9][10]First cited source Jul 21, 2026 · Latest cited source Jul 22, 2026 | Why it mattersSophos and Proofpoint make user interaction, malicious links, and AI-enhanced trust abuse current ransomware entry concerns. | What to monitorHigh-risk URL clicks, phishing reports, new downloads, suspicious OAuth or device-code flows, impersonation reports, and employee interactions with realistic malicious content. | IntelliOS coverage |
| 4 | Threat / Category Initial access Internet-facing edge appliances[6][8][9]First cited source Jul 14, 2026 · Latest cited source Jul 27, 2026 | Why it mattersThe Gentlemen research, Arete FortiBleed reporting, Sophos firewall findings, and Black Kite posture data keep firewalls, VPNs, and gateways at the center of ransomware access review. | What to monitorUnknown administrative logins; impossible travel; new VPN sessions; management-interface exposure; KEV/critical vulnerabilities; unexplained configuration or account changes. | IntelliOS coverage |
| 5 | Threat / Category Identity Stolen credentials and MFA coverage gaps[9][10]First cited source Jul 21, 2026 · Latest cited source Jul 22, 2026 | Why it mattersValid access can shorten the path from entry to lateral movement and extortion; MFA must cover the systems attackers actually use. | What to monitorPassword spraying; dormant-account use; MFA changes; new tokens or sessions; privilege elevation; service-account misuse; VPN, firewall-admin, SaaS, and legacy-app MFA exceptions. | IntelliOS coverage |
| 6 | Threat / Category Recovery infrastructure VMware ESXi and virtualization administration[1]Evidence dated Jul 9, 2026 | Why it mattersCross-platform locker capability places hypervisors and management consoles inside the primary ransomware target set. | What to monitorNew root or administrative access; SSH enablement; mass VM shutdown; datastore changes; unfamiliar binaries or scripts. | IntelliOS coverage |
| 7 | Threat / Category Recovery infrastructure Backup deletion, policy change, or credential use[1]Evidence dated Jul 9, 2026 | Why it mattersAttackers gain leverage when backups and restoration paths are reachable from production identities. | What to monitorRetention changes; repository deletion; new admin grants; failed restore tests; unusual access to backup consoles or secrets. | IntelliOS coverage |
| 8 | Threat / Category Pre-encryption behavior Data staging and large outbound transfers[1][2]First cited source Jul 2, 2026 · Latest cited source Jul 9, 2026 | Why it mattersDouble-extortion pressure usually depends on data theft before encryption or public posting. | What to monitorArchive creation; unusual cloud or S3 transfers; bulk file access; new compression tools; egress to unapproved destinations. | IntelliOS coverage |
| 9 | Threat / Category Exposure management Post-incident unresolved vulnerabilities and stealer exposure[8]Evidence dated Jul 27, 2026 | Why it mattersBlack Kite's annual posture findings show that restored organizations may still present exploitable conditions to attackers. | What to monitorCritical CVSS exposure, KEV exposure, stealer-log hits, open management ports, vendor-risk exceptions, and external posture after incident closure. | IntelliOS coverage |
| 10 | Threat / Category Victimology Healthcare, manufacturing, services, education, and middle-market targeting[1][2][8][9]First cited source Jul 2, 2026 · Latest cited source Jul 27, 2026 | Why it mattersRetained sources place these sectors or revenue bands prominently in their separate June, annual, and survey datasets. | What to monitorSector-specific actor claims; vendor alerts; third-party access changes; outage or extortion reports; regional shifts; revenue-band concentration in disclosure datasets. | IntelliOS coverage |