| Source1 | Publisherransomware.live | Published2026-07-26 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentLeak-site and extortion-tracker observations. A listed organization is an actor claim, not an independently confirmed intrusion; the API does not establish company size. | SourceRansomware.live Pro API — U.S. victim claims observed during the rolling window https://api-pro.ransomware.live/docs |
| Source2 | PublisherRansomLook | Published2026-07-26 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentA second collector can corroborate that a post was observed, but shared appearance across collectors still does not confirm the underlying intrusion. | SourceRansomLook recent posts API — independent collector reconciliation https://www.ransomlook.io/doc/ |
| Source3 | PublisherCheck Point Research | Published2026-07-09 | Publication / evidenceSource indexprimary research | Why used / claim treatmentVendor analysis of ransomware data-leak-site activity and operating context; published attacks remain actor claims unless separately confirmed. | SourceA New Ransomware Leader Emerges as June 2026 Attack Volumes Climb Worldwide https://blog.checkpoint.com/research/a-new-ransomware-leader-emerges-as-june-2026-attack-volumes-climb-worldwide/ |
| Source4 | PublisherCybersecurity and Infrastructure Security Agency | PublishedNot available | Publication / evidenceSource indexofficial | Why used / claim treatmentStanding defensive guidance used for practical prevention, containment, evidence-preservation, and recovery decisions; it does not control current victim-count claims. | Source#StopRansomware Guide https://www.cisa.gov/stopransomware/ransomware-guide |
| Source5 | PublisherIntelliOS | Published2026-07-26 | Publication / evidenceSource indexprimary research | Why used / claim treatmentCanonical identity and alias directory used to link tracker labels to source-backed actor cards. A name match does not establish incident attribution. | SourceIntelliOS Threat Actor Cards /threat-actor-cards |
| Source6 | PublisherU.S. Small Business Administration | PublishedNot available | Publication / evidenceSource indexofficial | Why used / claim treatmentControlling definition for the card’s small-business boundary. SBA size standards vary by NAICS industry and generally use employee count or average annual receipts, including affiliates. The source does not define one universal midsize threshold. | SourceSmall Business Size Standards https://www.sba.gov/federal-contracting/contracting-guide/size-standards |
| Source7 | Publisherabuse.ch / Spamhaus | Published2026-07-26 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentSeven-day API query of community-submitted, non-expired malware indicators. Indicators support hunting and validation; they do not identify a victim, prove an intrusion, or establish ransomware prevalence. | SourceThreatFox Community API — recent ransomware-tagged indicators https://threatfox.abuse.ch/api/ |
| Source8 | PublisherAlienVault Open Threat Exchange | Published2026-07-26 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentDiscovery query across the 50 most recently returned subscribed pulses. Pulse and indicator records are community and provider intelligence inputs, not confirmed incidents or victim-count evidence. | SourceAlienVault OTX subscribed-pulse API — recent ransomware-related pulses https://otx.alienvault.com/ |
| Source9 | PublisherAlienVault OTX | Published2026-07-25 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentOTX pulse containing 17 retained technical indicators. The pulse is a hunt input and does not confirm a victim or incident. | SourcePrinz Eugen ransomware: a deep dive into a new Go-based encryptor https://otx.alienvault.com/pulse/6a3d416ff54ce39010db1033 |
| Source10 | PublisherAlienVault OTX | Published2026-07-24 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentOTX pulse containing 42 retained technical indicators. The reported access-broker relationship remains source-qualified and does not establish ransomware attribution. | SourceNew Backdoor May be Linked to Ransomware Access Broker https://otx.alienvault.com/pulse/6a3bde32e46aafdb90f9593b |
| Source11 | PublisherAlienVault OTX | Published2026-07-23 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentOTX pulse containing four retained infrastructure indicators. The source title is explicitly provisional and is not promoted into a canonical threat-actor identity. | SourceA New Name in the Data Extortion Ecosystem? https://otx.alienvault.com/pulse/6a623272a8b581c080b0aee0 |
| Source12 | PublisherAlienVault OTX | Published2026-07-23 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentOTX pulse containing two retained network indicators. Indicators require local validation and do not establish a victim or campaign prevalence. | SourceChaos ransomware's msaRAT: Living off the browser to build a covert C2 channel https://otx.alienvault.com/pulse/6a62019ab2f0f4c8bf6527a0 |
| Source13 | PublisherAlienVault OTX | Published2026-07-21 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentOTX pulse containing five retained indicators, including hashes, one CVE reference, and one IPv4 address. It is a discovery and hunt input, not victim evidence. | SourceJADEPUFFER evolves: ransomware built to destroy AI models https://otx.alienvault.com/pulse/6a5eb7c2617139caf1fe0f2d |
| Source14 | PublisherHudson Rock | Published2026-07-26 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentPlanned authenticated integration for infostealer-derived credential, employee, domain, and third-party exposure signals. It has not been queried for this edition and cannot increase victim totals, corroborate a victim claim, or prove ransomware access. | SourceCavalier Infostealers API MCP Server https://docs.hudsonrock.com/docs/mcp |
| Source15 | PublisherGuidePoint Security GRIT | Published2026-07-09 | Publication / evidenceSource indexprimary research | Why used / claim treatmentGlobal public victim-post and ecosystem monitoring. Its quarter-over-quarter totals measure reported victims, not confirmed incidents, successful encryption, ransom demands, or a U.S. SMB-only population. | SourceGRIT Q2 2026 Ransomware & Cyber Threat Insights Report https://www.guidepointsecurity.com/resources/grit-q2-2026-ransomware-cyber-threat-insights-report/ |
| Source16 | PublisherAlienVault OTX | Published2026-09-03 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentOTX pulse containing 15 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution. | SourceAlmost Half of Malware Samples Communicate Direct to IP https://otx.alienvault.com/pulse/6a71e43a0127c62218b7c365 |
| Source17 | PublisherAlienVault OTX | Published2026-08-31 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentOTX pulse containing 28 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution. | SourceCampaign deploys a reverse tunnel through multistage intrusion https://otx.alienvault.com/pulse/6a94c765ccca1cbf809fc70f |
| Source18 | PublisherAlienVault OTX | Published2026-09-03 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentOTX pulse containing 7 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution. | SourceImpersonating IT support: how threat actors turn a remote session into enterprise-wide access https://otx.alienvault.com/pulse/6a98ece13ef339971e686ab5 |
| Source19 | PublisherAlienVault OTX | Published2026-08-29 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentOTX pulse containing 24 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution. | SourceToy Ghouls’ new toy: the GenieLocker ransomware https://otx.alienvault.com/pulse/6a6b1c3ea08dbc663eb8f4c0 |
| Source20 | PublisherAlienVault OTX | Published2026-09-02 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentOTX pulse containing 13 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution. | SourceOne leftover build path links an infostealer, a remote-access tool, and a ransomware family https://otx.alienvault.com/pulse/6a9756cad8fd625876d6a1a5 |
| Source21 | PublisherAlienVault OTX | Published2026-09-03 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentOTX pulse containing 11 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution. | SourceInside The Gentlemen: Undisclosed TukTuk C2 Framework and EDR Neutralization Research https://otx.alienvault.com/pulse/6a9869cb21bbf3f757424b7f |
| Source22 | PublisherAlienVault OTX | Published2026-09-03 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentOTX pulse containing 180 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution. | SourceNode.js: Old Technique Makes a Comeback https://otx.alienvault.com/pulse/6a996ed3562f794a642feaaf |
| Source23 | PublisherAlienVault OTX | Published2026-09-04 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentOTX pulse containing 21 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution. | SourceThe Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2 https://otx.alienvault.com/pulse/6a72f3bde4df792f5fa8956d |
| Source24 | PublisherAlienVault OTX | Published2026-09-05 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentOTX pulse containing 75 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution. | SourceUNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments https://otx.alienvault.com/pulse/6a75078f7b8e057bc29b8769 |
| Source27 | PublisherAlienVault OTX | Published2026-09-07 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentOTX pulse containing 3 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution. | SourceAngry Birds: Toy Ghouls’ new toys https://otx.alienvault.com/pulse/6a9abac288231f0634632e30 |
| Source30 | PublisherAlienVault OTX | Published2026-09-10 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentOTX pulse containing 10 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution. | SourceActive exploitation of Cisco Secure Firewall Management Center vulnerabilities https://otx.alienvault.com/pulse/6aa1c2281252d98a241ae632 |
| Source31 | PublisherAlienVault OTX | Published2026-09-10 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentOTX pulse containing 200 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution. | SourceMantax Otax: Indonesian Mobile Ransomware with Spyware Integration https://otx.alienvault.com/pulse/6aa1c8a04d40933ab841482f |
| Source32 | PublisherAlienVault OTX | Published2026-09-10 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentOTX pulse containing 14 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution. | SourceGrand Theft Auto VI hype leads to malware https://otx.alienvault.com/pulse/6aa18179c7eb1a5f0426ed7a |
| Source33 | PublisherAlienVault OTX | Published2026-09-10 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentOTX pulse containing 9 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution. | SourceActive Cloud Data Theft and Extortion Campaign Targeting Microsoft 365 and SaaS Platforms https://otx.alienvault.com/pulse/6aa2affe4ab7ba9012836da5 |
| Source36 | PublisherAlienVault OTX | Published2026-09-11 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentOTX pulse containing 38 retained technical indicators. The pulse is a discovery and hunt input and does not confirm a victim, incident, or attribution. | SourceSloppyRAT: A New Tool For Ransomware Attacks https://otx.alienvault.com/pulse/6aa2ea5fc313035064df8d21 |
| Source7 | PublisherCheck Point Research | Published2026-05-13 | Publication / evidenceSource indexprimary research | Why used / claim treatmentPrimary vendor analysis of leaked internal material describing The Gentlemen’s operating model, access paths, tooling, affiliate economics, and victim-chain reuse. It does not independently confirm every actor or victim claim in the leaked material. | SourceWhen the Ransomware Gang Gets Hacked: What The Gentlemen Leak Reveals About Modern Ransomware Risk https://blog.checkpoint.com/research/when-the-ransomware-gang-gets-hacked-what-the-gentlemen-leak-reveals-about-modern-ransomware-risk/ |
| Source8 | PublisherCheck Point Research | Published2026-06-08 | Publication / evidenceSource indexprimary research | Why used / claim treatmentVendor incident and product telemetry describing active exploitation beginning May 7 and a medium-confidence association with a financially motivated actor using Qilin ransomware. It does not establish that every Qilin claim used this vulnerability. | SourceActive exploitation of CVE-2026-50751 in deprecated IKEv1 VPN deployments https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/ |
| Source17 | PublisherCoveware by Veeam | Published2026-04-30 | Publication / evidenceSource indexincident response | Why used / claim treatmentPrimary Coveware Q1 2026 casework. Its Q4-to-Q1 payment comparisons describe Coveware-managed cases, not all U.S. incidents or a verified SMB-only population. Paid amounts are not initial ransom demands. | SourceQ1 2026 Quarterly Ransomware Report — Patch management goes from hard, to ludicrous in the agentic AI era https://coveware.com/2026/04/patch-management-goes-from-hard-to-ludicrous-in-the-agentic-ai-era/ |
| Source19 | PublisherArete | Published2026-06-03 | Publication / evidenceSource indexincident response | Why used / claim treatmentArete incident-response statistics for ransomware and extortion engagements, primarily involving cyber-insured organizations. Demand, payment, and payment-rate figures are bounded to Arete's case population and do not establish a Q2 or U.S. SMB-wide result. | SourceArete 2026 Q1 Crimeware Report https://areteir.com/resources/arete-s-2026-q1-crimeware-report |