As cited
Copy frozen at (site build).
ransomware
Ransomware and Cyber Extortion in Q2 2026
A ransomware threat report covering Q2 2026 activity found that group rankings shifted significantly, with "The Gentlemen" claiming the top spot while previously dominant groups like Qilin and DragonForce declined. Notable developments include Deadlock's resurgence with blockchain-based command and control and kernel-level endpoint detection and response (EDR) evasion techniques, alongside steady targeting patterns favoring professional, scientific, and technical services sectors across 90 groups in 99 countries. Despite quarterly fluctuations in victim counts, underlying attack techniques remained consistent, with the US absorbing approximately 49 percent of victim activity.
Why it matters: Security teams must prioritize detection of ransomware behaviors (remote-service abuse, identity compromise, lateral movement, defense evasion) rather than tracking group rankings, and should immediately assess exposure to Deadlock's blockchain-based command and control and kernel-level EDR termination tactics that may evade current defenses.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
Ransomware and Cyber Extortion in Q2 2026
A ransomware threat report covering Q2 2026 activity found that group rankings shifted significantly, with "The Gentlemen" claiming the top spot while previously dominant groups like Qilin and DragonForce declined. Notable developments include Deadlock's resurgence with blockchain-based command and control and kernel-level endpoint detection and response (EDR) evasion techniques, alongside steady targeting patterns favoring professional, scientific, and technical services sectors across 90 groups in 99 countries. Despite quarterly fluctuations in victim counts, underlying attack techniques remained consistent, with the US absorbing approximately 49 percent of victim activity.
Why it matters: Security teams must prioritize detection of ransomware behaviors (remote-service abuse, identity compromise, lateral movement, defense evasion) rather than tracking group rankings, and should immediately assess exposure to Deadlock's blockchain-based command and control and kernel-level EDR termination tactics that may evade current defenses.
- Source published
- First seen by Cybersecurity Tracker