146 Active Groups and Counting: Why Ransomware Fragmentation Makes Attribution Harder Than Ever

AUGUST 13, 2026

For much of the previous decade, ransomware defense was organized around a familiar model: identify which group was responsible for an attack, match their known tactics, techniques, and procedures against threat intelligence, and build detection based on what that group was known to do. LockBit used this initial access vector. Akira targeted Cisco VPN environments without MFA. Cl0p had a preference for managed file transfer platforms. The playbook logic was defensible because the ecosystem was legible: a small number of dominant operators accounted for the majority of incidents, and their behaviors were documented.That model is now breaking down under ransomware fragmentation.

That model has been structurally broken by a development that accelerated sharply in 2025 and has continued into 2026. Between April 2025 and June 2026, 61 new ransomware groups entered the market at a rate of more than one per week. The total count of active operations reached 146 by June 2026, more than double the 61 active groups counted in 2023. The average lifespan of an active group has fallen to 4.9 months, down from more than a year in 2024.

A detection framework built on known-group playbooks cannot cover 146 groups, 61 of which did not exist 15 months ago. A threat intelligence program that produces actor-specific IOC lists is producing lists that are outdated within weeks for a significant portion of the ecosystem. The fragmentation of the ransomware market is not a tactical shift. It is a structural change in the threat landscape that requires a corresponding structural change in how defense is organized.

146 active ransomware groups as of June 2026, up from 51 in Q4 2025 (Brandefense CTI / Black Kite 2026)91 distinct groups tracked by Brandefense CTI in Q2 2026 alone, up from 68 in Q1 20264.9 mo average active group lifespan in 2026, down from over 12 months in 2024 (Black Kite 2026)4,644 victims confirmed across Q1 and Q2 2026 combined in Brandefense CTI tracking data
Graph showing increase in groups from 2023 to June 2026.
The graph illustrates the growth of groups from 61 in 2023 to 146 in June 2026, highlighting shorter lifespans.

What Is Driving the Proliferation: Three Structural Forces

Force 1: Leaked Source Code Eliminated the Technical Barrier

The September 2022 leak of the LockBit 3.0 builder was the single most consequential event in lowering the barrier to ransomware operation. A functional, feature-complete ransomware encryptor with affiliate panel, negotiation portal, and multi-platform support became available to anyone capable of running a command-line tool. The Chaos and Babuk builders followed, each leaked at different points and each providing a starting point for new operations without requiring original malware development.

The effect was immediate and durable. Groups that would previously have needed months and significant technical investment to develop functional ransomware infrastructure could now stand up an operation in days. Black Kite’s 2026 report attributes a significant portion of new entrants directly to builder-derived tooling. The commoditization dynamic means the total operator count is unlikely to decline materially without either coordinated toolchain takedown, which has not proven durable, or sustained affiliate disruption at a scale not yet achieved.

Force 2: Disruption Disperses Affiliates Without Eliminating Them

Law enforcement operations against major ransomware brands, including Operation Cronos against LockBit in February 2024 and earlier actions against ALPHV/BlackCat, were genuinely disruptive at the brand level. Infrastructure was seized, decryption keys were recovered, and some operators faced arrest. But the affiliate networks that conducted the attacks dispersed rather than collapsed.

Former LockBit and ALPHV affiliates migrated to new platforms within days of disruption. Some joined existing programs. Others, with access to leaked builders, established new brands of their own. The Brandefense Q1 2026 analysis of TheGentlemen’s rapid ascent to Rank 2 with no prior track record illustrated this pattern precisely: the group was assessed as experienced affiliates migrating from a disrupted platform, not new entrants. The operational capacity that produced 183 victims in a single quarter did not emerge from nothing. It relocated.

Searchlight Cyber identified 73 new groups entering the market in 2025 alone. IBM X-Force documented that the top 10 groups’ share of disclosed victims fell from 71% in Q1 2025 to 56% by Q3, as market share dispersed to smaller actors. Disrupting dominant brands has, paradoxically, produced a more fragmented and harder-to-monitor ecosystem.

Force 3: The Economics of Short-Lived Operations

The 4.9-month average group lifespan is not evidence of failure. For many entrants, it is the business model. A group that operates for four to five months, runs campaigns against mid-market targets, collects payments, and dissolves before attracting law enforcement attention incurs minimal operational risk relative to the revenue generated. The lower victim counts per group that fragmentation produces are partially offset by the lower operational costs of running a short-lived program.

This model also produces a specific attribution challenge: groups that operate for less than five months frequently close without ever receiving a comprehensive public intelligence profile. The IOC sets that threat intelligence vendors publish often lag the group’s active period by weeks. By the time a detection rule incorporating a specific group’s known IOCs is distributed and deployed, the group may no longer be operating under that name. Their affiliates have already moved to the next platform.

The Attribution Paradox

Attribution, the process of identifying which ransomware group conducted an attack, has become simultaneously more important and less useful as a defensive input. More important because understanding the threat actor informs the investigation and may support law enforcement engagement. Less useful because the behaviours, tools, and infrastructure of a group that has been operating for 4.9 months on average may not match any existing intelligence profile at the time of the attack. The 56 operators beyond the top 10, which collectively contributed 44% of 2026 victim volume, include dozens of groups with no published threat intelligence profile, no documented TTPs in public databases, and no historical IOCs available for detection. A detection framework that depends on knowing who is attacking provides no coverage for attacks from this segment.

DemoBanner 88 - 146 Active Groups and Counting: Why Ransomware Fragmentation Makes Attribution Harder Than Ever

Why Known-Group Playbooks Fail Against a Fragmented Ecosystem

The known-group playbook model operates on a specific assumption: if you can identify the threat actor, you can anticipate their behavior. That assumption was reasonable when a small number of dominant groups accounted for the majority of activity. In an ecosystem where 44% of victim volume comes from groups outside the top 10, and where the average new entrant has no documented behavioral profile, the assumption breaks down.

Case Study: TheGentlemen and the 90-Day Coverage Gap

In Q4 2025, TheGentlemen did not exist as a documented ransomware operation. No published intelligence profile. No IOC set. No MITRE ATT&CK mapping. No historical victim pattern.

In Q1 2026, the group entered at Rank 2 globally with 183 confirmed victims, according to Brandefense CTI tracking. By Q2 2026, it had risen to 239 victims while maintaining Rank 2, a 30.6% quarter-on-quarter increase. By June 2026, Brandefense CTI assessed the group as the primary candidate to challenge Qilin for the top position. No threat intelligence program operating on a known-group playbook model had any coverage for TheGentlemen for the first 90 days of its operational existence. Every organization breached by TheGentlemen in Q1 2026 was breached by a group with zero published intelligence, because the group had not existed long enough to have been documented. This is not an edge case. In a market with 61 new entrants in 15 months, it is the baseline condition for a significant share of attacks.

Problem 1: The IOC Staleness Cycle

Traditional threat intelligence produces IOC lists: IP addresses used for command and control, file hashes of known malware binaries, domain names associated with specific operations. These indicators are published after a group has been observed in one or more incidents, which means they describe historical behavior.

A group with a 4.9-month lifespan rotates its infrastructure on cycles measured in days to weeks. By the time the threat intelligence publication cycle produces a set of IOCs for a new operator, those IOCs may already be outdated. The group has changed its C2 infrastructure, recompiled its encryptor with a new hash, and moved its negotiation portal. A detection system that blocks last month’s IOCs provides no protection against this month’s campaign.

IBM X-Force explicitly noted in its 2026 Threat Intelligence Index that the dominance of attacks attributed to the top 10 groups dropped by 25%, with the volume dispersing to smaller actors who rotate infrastructure faster than intelligence can track it. The IOC staleness problem is most acute precisely in the segment of the ecosystem that is growing fastest.

Problem 2: Shared Tooling Breaks Attribution Logic

The second breakdown in the known-group playbook model is shared tooling. When a leaked builder produces functionally equivalent ransomware across dozens of groups, a detection rule based on a specific encryptor’s signature, mutex, or file extension pattern may produce alerts attributed to multiple groups simultaneously, or may be defeated by a group that makes minimal modifications to the builder output.

The Brandefense Q2 2026 Ransomware Trends Report noted this dynamic in the RaaS concentration analysis: affiliate migration across platforms means that the same affiliate, using the same post-exploitation tools and lateral movement techniques, may appear across different group names in different quarters. The group name changes. The behavior patterns do not.

This creates an inversion of the attribution logic: the TTPs that remain consistent across group changes are exactly the behaviors that group-specific playbooks are weakest at documenting, because they are attributed to the affiliate rather than the operator brand. A defender trying to anticipate a specific named group’s behavior may be better served by tracking the affiliate community’s common techniques than by tracking the operator’s brand-specific indicators.

Problem 3: New Entrants Have No Playbook

The 61 new groups that entered between April 2025 and June 2026 have, by definition, no documented threat intelligence profile at the time of their first campaigns. A group that becomes the sector’s second most active operator within 90 days of formation, as TheGentlemen did in Q1 2026, produces no historical IOCs, no published TTP mapping, and no prior victim pattern that would allow defenders to anticipate targeting. The detection gap for new entrants exists for the entire period before the threat intelligence community has had time to observe, document, and publish the group’s behavior.

Known-Group Playbook AssumptionWhy It Fails in a Fragmented Ecosystem
IOC lists provide detection coverageGroups rotate infrastructure every days to weeks; IOCs published after observation lag the active campaign window
Named group = consistent behaviorAffiliates migrate across operator brands; behavior persists across group names while IOCs change
Major groups account for most riskTop 10 groups: 56% of 2026 victim volume, down from 71% in Q1 2025; 44% now from groups outside the top 10
Threat intelligence covers the threat61 of 146 active groups have no published intelligence profile; new entrants by definition cannot be pre-profiled
Group disruption reduces attack surfaceAffiliate dispersal reconstitutes operational capacity under new brands within days; victim volume persists after brand takedowns

What Works Instead: Behavioural Detection and Pre-Attack Intelligence

The structural response to ecosystem fragmentation is a shift from group-centric to behaviour-centric detection, combined with intelligence that surfaces attack indicators before group identity is established. Neither of these is a new concept, but both become the primary defensive mechanism rather than a supplementary one when the known-group playbook model fails.

Behavioural Detection: TTPs That Persist Across Group Changes

The behaviours that consistently appear across ransomware intrusions regardless of operator brand are documented in MITRE ATT&CK and in the aggregate of incident response data across multiple groups. Initial access via valid credentials purchased from initial access brokers appears across virtually every current ransomware operator. Credential dumping via LSASS access, shadow copy deletion via vssadmin or wmic, lateral movement via PsExec and remote services, and exfiltration via rclone or MEGAsync appear with such consistency across the ecosystem that detecting these behaviors provides coverage against new entrants with no intelligence profile.

IBM X-Force’s conclusion that behavioural detection frameworks will become progressively more important relative to signature-based approaches in subsequent reporting periods reflects exactly this dynamic. A detection rule that fires on LSASS credential access followed by lateral movement tool staging fires on every group that uses that sequence, regardless of whether the group is named, whether its IOCs are published, or whether it has been active for four months or four years.

Pre-Attack Intelligence: Surfacing Signals Before Group Identity Is Known

The second structural response is intelligence that provides early warning before an attack begins and before the attacking group has been identified. Initial access brokers list corporate network access for sale days to weeks before ransomware is deployed. Credential exposure in infostealer logs appears before credentials are used for initial access. Dark web targeting discussions reference sector-specific campaigns before specific victims are identified.

This layer of intelligence is group-agnostic. An IAB listing for VPN access to a manufacturing company at a specific revenue range is an indicator regardless of which of the 146 active groups purchases that access. A credential exposure alert for a corporate SSO account is actionable regardless of whether the group that will use it has a published intelligence profile. Pre-attack intelligence closes the coverage gap that group-specific playbooks leave for unknown actors.

Continuous Operator Monitoring: Tracking the Long Tail

The third response is active monitoring of the full operator ecosystem, not just the top 10 or top 20 groups. Brandefense CTI tracks all 146 active groups including the 28 emerging programs identified in the Q2 2026 report, monitoring their leak site activity, their victim posting patterns, and their sector targeting as it evolves. This monitoring provides early warning when a lower-volume group begins targeting a specific sector or geography at elevated rates, allowing defenders in that sector to treat the emerging group as an active threat before it achieves top-tier volume.

What a Fragmented Ecosystem Requires From Threat Intelligence

Group-centric intelligence: which named groups are active, what their documented TTPs are, and what their recent victim patterns show. This remains necessary for the top-tier operators that account for the majority of disclosed volume.

Behaviour-centric detection: rules that fire on TTPs observed consistently across the ecosystem regardless of operator brand. This provides coverage for the 44% of volume from groups outside the top 10.

Pre-attack intelligence: IAB monitoring, credential exposure detection, and dark web targeting surveillance that surfaces attack indicators before group identity is established. This closes the gap for new entrants with no published profile. Full ecosystem monitoring: active tracking of all active groups including emerging operators, not just the named brands with published intelligence profiles.

How Brandefense Addresses the Ransomware Fragmentation Challenge

CapabilityHow It Addresses the Fragmented Ecosystem
Full ecosystem monitoring across 146+ groupsTracks all active ransomware operators, including emerging programs with no public intelligence profile, across leak sites, dark web forums, and criminal communication channels
Initial access broker (IAB) surveillanceMonitors IAB marketplaces for access listings associated with your organization, your sector, and your technology stack, providing pre-attack intelligence that is group-agnostic
Credential exposure monitoringDetects organizational credentials in infostealer logs and breach databases before they are used for initial access, regardless of which group ultimately purchases the access
Ransomware group activity trackingSurfaces sector targeting patterns and campaign activity from emerging groups before they achieve top-tier volume, enabling early warning for targeted sectors
Dark web targeting intelligenceMonitors threat actor communication for discussions that reference your organization, sector, or technology stack as targeting subjects
Continuous 24/7 monitoringProvides real-time intelligence against an ecosystem where group emergence, campaign activation, and infrastructure rotation all occur faster than periodic intelligence cycles can track

RELATED READING

Top 5 Ransomware Groups in Q2 2026:  https://brandefense.io/blog/top-5-ransomware-groups-q2-2026/ : Brandefense CTI profiles of Qilin, TheGentlemen, Akira, DragonForce, and LockBit5 with full TTP analysis

Why CVSS Scores Are Lying to Your Security Team: https://brandefense.io/blog/why-cvss-scores-are-lying-to-your-security-team/ : how vulnerability prioritization models fail against threat actors who move faster than patch cycles
The 5-Day Breakout:  https://brandefense.io/blog/breakout-time-vs-dwell-time/ : the timeline that behavioural detection must operate within to be effective

Triple Extortion Anatomy:https://brandefense.io/blog/what-is-triple-extortion/: the multi-layer pressure model that both established and emerging operators are adopting

Illustration of cybersecurity ecosystem with multiple groups and monitoring tools.
Brandefense highlights 146 ransomware groups, emphasizing the complexity of attribution in cybersecurity.

SHARE THIS

Get insight, Analysis &
News Straight to Your
Inbox

By submitting this form, you agree to our Privacy Policy

Latest News