JULY 24, 2026
The Brandefense CTI team monitored 2,509 confirmed ransomware victims across 91 distinct threat actor groups during Q2 2026, the period ending July 3, 2026. Every one of those 2,509 cases was independently verified before inclusion: modern operators now publish proof-of-exfiltration data samples alongside victim listings to establish negotiation credibility, making the confirmation rate in this dataset 100%.
The headline number tells part of the story. Q2 2026 saw a 17.5% increase in confirmed victims compared to Q1 2026. June 2026 produced 919 victim posts, the highest single-month total in the current Brandefense tracking window. The monthly trajectory across the quarter moved in one direction: up.
Behind those numbers are 91 active groups ranging from established platforms with mature affiliate networks to newly launched operations running commodity builders. The top 10 groups accounted for 53.4% of all attributed victims. The top 5 held 28.4%. This blog profiles each of those five groups in detail: their origins, how they gain access, what makes them technically distinctive, which sectors and countries they target, and what the Q2 2026 data reveals about their current trajectory.
| 2,509 confirmed victims monitored in Q2 2026, period ending July 3, 2026 | 91 distinct ransomware groups active in Q2 2026, up from 68 in Q1 | +17.5% increase in confirmed victims quarter-over-quarter vs Q1 2026 | 919 victim posts in June 2026, highest single month in current tracking window |

| FROM THE BRANDEFENSE Q2 2026 RANSOMWARE TRENDS REPORT The top three operators collectively hold 28.4% of victim share; the top ten account for 53.4%. This concentration profile is a hallmark of a mature Ransomware-as-a-Service ecosystem in which platform operators achieve dominant market positions by offering affiliates superior tooling quality, reliable payment infrastructure, and revenue-sharing rates that create strong switching costs. |
| #1 Qilin aka Agenda 305 Q2 victims 12.2% of Q2 2026 tracked activity |
Qilin emerged in 2022 under the name Agenda, initially written in Go before transitioning to Rust in 2023. The shift to Rust was deliberate: it enables cross-platform compilation for Windows, Linux, and VMware ESXi from a single codebase, and Rust binaries are significantly harder to reverse-engineer than Go equivalents, reducing the value of signature-based detection. The rebranding to Qilin, which takes its name from a mythological Chinese creature, accompanied a major expansion of the affiliate program.
Qilin operates under the RaaS model, with the core team developing and maintaining infrastructure while affiliates conduct attacks. The affiliate revenue split is one of the most competitive in the ecosystem: up to 85% of ransom payments go to affiliates, with the platform retaining 15% to 20%. This rate has been a primary driver of affiliate recruitment, particularly following the disruption of LockBit, ALPHV/BlackCat, and RansomHub, whose displaced affiliates largely migrated to Qilin throughout 2025.
The most frequently observed initial access vector in confirmed Qilin intrusions is valid account abuse: VPN and RDP credentials procured from dark web access brokers and infostealer log markets. Spearphishing with weaponised Office or LNK documents represents a secondary vector, less prevalent than credential-based access but observed across multiple intrusion chains. In 2026, social engineering campaigns using fake CAPTCHA pages have also been documented as a lure mechanism leading to credential theft and subsequent VPN access.
Qilin’s encryptor uses two-pass ChaCha20 plus AES-256 encryption with BCryptGenRandom key generation. The ESXi variant halts virtual machines before encrypting VMDK files, delivering simultaneous impact across all hosted VMs. Thirteen major operators in Q2 2026 deploy dedicated ESXi encryptors; Qilin’s remains best-in-class among active RaaS platforms.
Defense evasion includes XOR-based custom unpacking with in-memory payload decryption, CPUID hypervisor bit inspection for sandbox detection, password-protected execution that prevents re-deployment on already-encrypted hosts, and PowerShell-based event log clearing post-encryption. The encryptor self-deletes after execution to minimize forensic artifacts. In 2025, Qilin added a DDoS capability, giving affiliates a third pressure lever alongside encryption and data leaking, and introduced a ‘Call Lawyer’ feature in the negotiation panel to increase settlement pressure.
| FROM THE BRANDEFENSE Q2 2026 RANSOMWARE TRENDS REPORT Qilin retained #1 position for a third consecutive quarter with 305 confirmed victims, down 16.0% from Q1 2026 (363). The continued sequential decline alongside overall ecosystem growth of 17.5% indicates sustained affiliate diversification to competing platforms (TheGentlemen, DragonForce) rather than an operational retreat. Qilin’s ESXi encryptor and VMware-targeting capability remain best-in-class among current RaaS platforms. |
Since launch, Qilin has claimed approximately 1,500 total victims, with more than 500 in 2026 alone. Qilin’s most consequential known attack targeted Synnovis, a pathology provider serving major NHS trusts in London, in June 2024, which resulted in documented patient harm and a $50 million ransom demand. In 2026, the group listed Cushman and Wakefield, a global commercial real estate firm, on its leak site.
| Metric | Detail |
| Primary sectors | Manufacturing and Production (most frequent), Professional Services, Healthcare, Retail, Construction and Engineering |
| Geographic concentration | United States (highest victim count), Canada, United Kingdom, France, Germany; growing presence in Asia |
| State actor intersection | Microsoft observed North Korea-linked Moonstone Sleet deploying Qilin ransomware in 2025, the first documented case of a state actor using a RaaS platform’s payload |
| Affiliate revenue share | Up to 85% for affiliates, 15-20% platform retention |
| Leak site model | Clearnet (indexed by search engines), not Tor-only, amplifying public pressure on victims |
| #2 TheGentlemen aka The Gentlemen Group 239 Q2 victims 30.6% QoQ growth of Q2 2026 tracked activity |

TheGentlemen is the most significant ransomware emergence story of 2025 and 2026. The group launched in 2025 and recorded only 18 incidents in Q4 2025. By Q1 2026 that figure had risen to 183. In Q2 2026 it reached 239, a 30.6% quarter-on-quarter increase and the highest growth rate among any top-5 operator in the period. Two consecutive quarters at Rank 2 confirm the group’s transition from emerging to established RaaS platform status.
The group’s intelligence profile carries a lower confidence rating than Qilin, Akira, or LockBit5, reflecting its recent emergence and limited independent vendor corroboration. What is clear from the data is that the group has operational consistency, cross-sector targeting diversity, and expanding geographic reach that are characteristic of experienced affiliates running a purpose-built platform rather than an improvisational collective.
TheGentlemen’s primary initial access vector is valid accounts: credentials acquired from dark web brokers and infostealer logs, consistent with the ecosystem-wide shift away from direct vulnerability exploitation toward credential-based access. The group has also been observed exploiting FortiGate vulnerabilities, specifically CVE-2024-55591, a pattern also observed in Nightspire intrusions and associated with targeting Japan and Turkey in Q1 2026 data.
Encoded PowerShell scripts are used for payload staging, AMSI bypass, and persistence establishment. The group’s exfiltration methodology uses rclone and MEGAsync to stage stolen data prior to encryption, consistent with double extortion as a baseline operational step.
| FROM THE BRANDEFENSE Q2 2026 RANSOMWARE TRENDS REPORT TheGentlemen consolidated its Rank 2 position with 239 victims, a 30.6% increase from Q1 2026 (183). Two consecutive quarters at Rank 2, combined with the highest growth rate in the top-5, confirm the group’s transition from emerging to established RaaS operator. A challenge to Qilin’s #1 position cannot be excluded within the next reporting cycle. |
The Brandefense Q3 forward outlook rates a potential Rank 1 transition from TheGentlemen as MEDIUM CONFIDENCE, with TheGentlemen’s 30.6% growth rate and Qilin’s two-quarter volume decline identified as the conditions that make this possible. Year-to-date through May 2026, TheGentlemen held 335 total victims across five months, firmly established as the second most active operation globally.
| Metric | Detail |
| Primary sectors | Healthcare, Professional Services, Technology, Financial Services; broad cross-sector targeting consistent with mature affiliate selection |
| Notable geographic pattern | Thai organizations constitute 10.8% of TheGentlemen’s Q1 2026 victim total, the highest country concentration in the group’s profile; Thailand entered the top 10 targeted countries globally in Q1 primarily due to TheGentlemen |
| Exfiltration tools | rclone, MEGAsync; double extortion baseline with cloud staging |
| Platform maturity indicators | Consistent posting cadence, cross-sector diversity, expanding geographic spread; all three are pre-growth behavioral indicators per Brandefense CTI |
| #3 Akira 169 Q2 victims 3rd consecutive quarter at Rank 3 of Q2 2026 tracked activity |
Akira was first observed in March 2023 and has maintained consistent top-tier activity since. The group operates a double extortion model, exfiltrating data before encryption and threatening publication on its Tor-based leak site. Unlike Qilin and LockBit5, Akira appears to operate without an affiliate program on the standard RaaS model, functioning more as a closed or semi-closed operation with a stable, experienced team.
Akira’s encryption uses ChaCha20-Poly1305 for Windows targets and a Rust variant targeting ESXi .vmdk, .vmem, and .vswp files. The group collected an estimated $150 million in ransom payments in 2025. Ransom demands range from $200,000 to over $4 million and are typically denominated in Bitcoin.
Akira’s defining and most consistently observed initial access vector is exploitation of Cisco AnyConnect SSL VPN in environments without MFA enforcement, specifically CVE-2023-20269. The CISA and FBI joint advisory AA23-272A remains the definitive public reference for Akira mitigation controls. In 2025 and 2026, Akira affiliates have expanded to additional edge device vulnerabilities: Cisco IOS XE (CVE-2025-20188) and Palo Alto GlobalProtect (CVE-2024-3400) are both observed as emergent initial access vectors in recent Akira-attributed intrusions.
Post-access, Akira uses Advanced IP Scanner and SoftPerfect Network Scanner for internal network mapping. The group’s most distinctive defensive evasion technique is Bring Your Own Vulnerable Driver (BYOVD): RTCore64.sys, the driver associated with MSI Afterburner, is deployed to blind EDR solutions at kernel level prior to encryption. This technique severely limits the detection and response window. Backdoor local admin accounts are created on domain controllers for persistent re-access, surviving initial incident response attempts.
| FROM THE BRANDEFENSE Q2 2026 RANSOMWARE TRENDS REPORT Akira maintained Rank 3 for a third consecutive quarter with 169 victims (Q4 2025: 222, Q1 2026: 177, Q2 2026: 169). Cross-quarter rank consistency despite modest volume decline reflects a stable, attrition-resistant affiliate base. Cisco VPN exploitation and BYOVD EDR-blinding remain the group’s defining technical profile. |
| Metric | Detail |
| Primary sectors | Manufacturing (primary), Healthcare, Education, Professional Services; cross-sector but with consistent manufacturing concentration |
| Geographic concentration | North America and Europe are primary targets; the United States accounts for the largest single-country share |
| Key technical risk signal | Any Cisco AnyConnect VPN deployment without MFA represents the highest-probability Akira initial access pre-condition |
| Backup targeting | Akira specifically targets Veeam backup infrastructure to harvest credentials, systematically eliminating disaster recovery capability before payload deployment |
| #4 DragonForce aka Dragon Force 144 Q2 victims New entry into Q2 top-5 of Q2 2026 tracked activity |
DragonForce has been active since 2023 and built its technical foundation on the leaked LockBit 3.0 builder, which became publicly available in September 2022. While builder-derivative groups frequently represent low-sophistication operations, DragonForce distinguishes itself through operational strategy rather than technical originality. The group has positioned itself as a cartel operator, publicly announcing an umbrella organization for multiple sub-brands. Check Point Research’s Q1 2026 analysis found the cartel model to be smaller than advertised in practice, with independent sub-brands posting significantly lower victim counts than the parent operation, but the branding approach reflects genuine marketing investment and affiliate recruitment sophistication.
DragonForce’s genuine technical innovation is a data audit service that analyzes stolen datasets exceeding 300 GB to identify the highest-value information for targeted extortion leverage. This service, offered to affiliates, represents a meaningful advancement in the extortion model beyond standard data leak threats.
DragonForce’s most operationally significant initial access vector is supply chain compromise via MSP and MSSP targeting. The group uses compromised managed service providers as launchpads for downstream client compromise, with a single MSP intrusion potentially yielding dozens of downstream victims. This approach, mapped to MITRE ATT&CK T1195.002, delivers exponential victim multiplier potential and is the primary reason DragonForce-attributed incidents should be treated as potential supply chain exposure events.
Windows Command Shell with batch automation scripts deploys the ransomware payload to network shares and remote systems via PsExec. 7-Zip is used to compress and stage exfiltrated data, with archives split to evade DLP size thresholds. The encryptor binary self-deletes post-execution and includes a custom wiper component to minimize forensic artifacts. The Linux variant specifically targets ESXi VM datastore paths.
| FROM THE BRANDEFENSE Q2 2026 RANSOMWARE TRENDS REPORT DragonForce entered at Rank 4 (144 victims), displacing Q1’s IncRansom. In Q1 2026 DragonForce posted 101 victims, a 29% increase from Q4 2025. Year-to-date through May 2026, DragonForce held 248 victims, third highest in the ecosystem. The MSP/MSSP targeting strategy demonstrates operational sophistication above that of typical builder-derivative groups. |
DragonForce was also directly implicated in the Marks and Spencer attack in April 2025, one of the highest-profile retail breaches of the year, which resulted in approximately 300 million pounds in lost sales and significant operational disruption across the retailer’s online and in-store systems. The attack was attributed to DragonForce-affiliated actors and demonstrated the group’s capacity for high-impact retail sector targeting.
| Metric | Detail |
| Primary sectors | Manufacturing, Technology, Business Services, Retail; MSP targeting creates cross-sector downstream exposure |
| Primary geographic targets | United States, United Kingdom, Brazil, Germany; Marks and Spencer attack demonstrated high-profile UK retail impact |
| Supply chain multiplier | A single MSP intrusion can yield dozens of downstream victims across sectors and geographies |
| Cartel model assessment | Publicly marketed as an umbrella cartel with multiple sub-brands; independent analysis indicates cartel structure is smaller than advertised but affiliate recruitment remains active |
| #5 LockBit5 aka LockBit Black / LockBit 4.0 115 Q2 victims Resurgence post-Operation Cronos of Q2 2026 tracked activity |
LockBit is the most consequential ransomware brand of the past five years. At its peak in 2023, LockBit was responsible for approximately 25% of all documented ransomware incidents globally. Operation Cronos, the international law enforcement action in February 2024, seized LockBit’s infrastructure, disrupted its operations, and led to the arrest of key affiliates. Most analysts assessed LockBit as a collapsed operation following Cronos.
That assessment proved incorrect. Residual LockBit affiliates and rebuilt infrastructure reconstituted under successive designations. Brandefense classifies the current iteration as LockBit5, reflecting the operational lineage while distinguishing it from prior versions. The re-entry into the Q2 2026 top-5 at Rank 5 with 115 victims signals that the LockBit ecosystem has successfully reconstructed platform-level operations, not merely individual affiliate activity.
LockBit5 supports Windows, Linux, macOS, VMware ESXi, and FreeBSD targets, the broadest platform coverage of any group in the top 5. The encryptor uses Salsa20 cipher with StealBit, a custom exfiltration tool, for pre-encryption data theft. The ‘LockBit Black’ variant is based on the leaked Conti and LockBit 3.0 builder.
LockBit5’s initial access vectors span multiple edge device vulnerabilities: Citrix Bleed (CVE-2023-4966), Palo Alto PAN-OS (CVE-2024-3400), and Fortinet exploits from prior periods remain relevant. In 2025 and 2026, affiliates have actively exploited Ivanti Connect Secure (CVE-2025-0282) and Palo Alto Expedition (CVE-2024-9474). The breadth of exploited vulnerabilities reflects the diverse technical profiles of LockBit’s affiliate network rather than a single standardized access methodology.
LockBit5’s most operationally disruptive technique is Group Policy Object abuse to mass-deploy the ransomware payload across an entire Active Directory domain simultaneously, mapped to MITRE ATT&CK T1484.001. A single execution can encrypt every domain-joined machine in an environment without per-host deployment. Privilege escalation uses Kerberoasting and AS-REP Roasting to obtain domain admin Kerberos tickets from environments where privileged accounts authenticate from general-purpose workstations.
| FROM THE BRANDEFENSE Q2 2026 RANSOMWARE TRENDS REPORT Lockbit5’s re-entry post-Operation Cronos signals successful RaaS infrastructure reconstitution. LockBit5 entered the top-5 at Rank 5 with 115 victims alongside DragonForce at Rank 4, displacing Q1’s IncRansom and Cl0p. The re-entry into the top-5 signals that the LockBit ecosystem continues to generate successor operators capable of top-tier victim volumes. |
By June 2026, LockBit5 was posting victims at an accelerating rate, with a reported 87% increase month-over-month in the most recent tracking period. Top targeted sectors in the current period include Business Services (47 victims), Manufacturing (45), Technology (36), Healthcare (27), and Agriculture and Food Production (23), with the United States, Brazil, Italy, Germany, and Mexico as the most frequently targeted countries.
| Metric | Detail |
| Primary sectors | Business Services, Manufacturing, Technology, Healthcare; broadest sector coverage of any top-5 group |
| Geographic reach | 68 countries hit; United States, Brazil, Italy, Germany, Mexico are current top-5 targets |
| Law enforcement resilience | Operation Cronos disrupted but did not eliminate the LockBit ecosystem; affiliate redistribution and infrastructure reconstitution occurred within 6-12 months |
| Key defensive priority | Environments with privileged accounts authenticating from general-purpose workstations are highest-priority remediation target for LockBit5’s Kerberoasting technique |
Across five different operators with different tooling, different affiliate structures, and different targeting preferences, three attack patterns appear consistently enough to represent structural features of the current threat landscape rather than group-specific tactics.
| Pattern | Which Groups | What It Means for Defense |
| Credential-based initial access via IAB markets | Qilin (primary), TheGentlemen, LockBit5, Akira (secondary) | Perimeter vulnerability patching is necessary but not sufficient. Credentials purchased from infostealer log markets produce no initial intrusion signal. Dark web credential monitoring is the only pre-intrusion detection layer. |
| ESXi hypervisor targeting | Qilin (best-in-class), Akira (Rust variant), DragonForce (Linux variant), LockBit5 (multi-platform) | A single ESXi host compromise simultaneously encrypts all hosted VMs. Organisations without ESXi-specific backup isolation, management network segmentation, and SSH restrictions face compounded incident severity from four of the top five operators. |
| Double extortion as baseline | All five groups | Backup recovery eliminates encryption pressure but does not eliminate extortion pressure. All five groups exfiltrate before or alongside encryption. Containment must address data exposure, not only system restoration. |
The Q2 2026 data supports the following forward assessments for Q3, drawn directly from the Brandefense Ransomware Trends Report:
| Forecast | Confidence | Basis |
| Activity volume will remain elevated or increase | HIGH | Sustained upward monthly trajectory; June 2026 peak of 919 victims; no historical precedent for sustained decline without simultaneous multi-operator law enforcement action |
| TheGentlemen may challenge Qilin for Rank 1 | MEDIUM | 30.6% Q2 growth rate vs Qilin’s two-quarter volume decline; conditions for Rank 1 transition exist but outcome is not certain |
| Cl0p resurgence in H2 2026 | MEDIUM | Cl0p’s campaign-burst pattern and Q2 2026 exit from top-5 are consistent with pre-campaign dormancy; MFT platforms are the highest-priority pre-emptive remediation target |
| ESXi targeting will intensify across mid-tier groups | HIGH | 13 major operators already deploy ESXi encryptors; capability is proliferating into mid-tier programs via affiliate knowledge transfer; cost per ESXi compromise continues to rise for victims |
| RaaS tooling commoditisation will sustain new entrant count | HIGH | Leaked builders sustain low-barrier entry; 28 emerging operators in Q2 2026 with several showing pre-growth behavioral indicators |
| Capability | Relevance to Top 5 Groups |
| Ransomware leak site monitoring | Real-time monitoring of all five groups’ leak sites; victim listings surfaced at first publication, before mainstream reporting |
| Dark web credential and IAB market monitoring | Tracks credential listings for your organization’s domains across the broker markets that supply Qilin, TheGentlemen, LockBit5, and DragonForce affiliates with initial access |
| Infostealer log surveillance | Monitors newly published stealer log batches for corporate credentials that feed the IAB pipeline; detection before credentials are brokered |
| Threat actor activity tracking | Maintains profiles on all 91 groups monitored in Q2 2026; actor-specific intelligence briefs for top-5 operators available on request |
| External attack surface management | Identifies internet-facing assets matching the vulnerability profiles exploited by Akira (Cisco VPN), LockBit5 (Citrix/Ivanti/Palo Alto), and Qilin (VPN/RDP) |
| Continuous 24/7 monitoring | Provides the detection cadence required against operators posting new victims in real time and rotating infrastructure on day-to-week cycles |
| Read the Full Report This blog draws on findings from the Brandefense Ransomware Trends Report Q2/2026, which covers 2,509 confirmed victims across 91 groups, full MITRE ATT&CK TTP analysis for all five operators profiled above, IOC tables for each group, sector macro-category analysis, geographic distribution across 113 countries, and the complete Q3 2026 forward outlook with Admiralty confidence ratings. The full report is available to download at brandefense.io. |
Take control of your digital security with an exclusive demo of our powerful threat management platform.