On July 2 2026, the FBI and IRS Criminal Investigation division seized hundreds of NetNut domains in a coordinated action with Google Threat Intelligence Group, Lumen Technologies, and the Shadowserver Foundation, dismantling the Popa botnet — a 2-million-device residential proxy network built on hijacked Android smart TVs, streaming boxes, and off-brand devices via malicious SDKs. Google's GTIG observed 316 distinct threat clusters (criminal and espionage) using NetNut exit nodes in a single week during June 2026, including for password spraying, credential stuffing, and masking APT C2 traffic. This is Google's second major residential proxy botnet disruption in 2026, following the IPIDEA takedown in January.
Hyadina is a 4-year-old RaaS operation tracked by Symantec that has serially rebranded its locker: Monster (2022) → Beast (Jun 2024) → GodDamn (May 2026). Its latest iteration, GodDamn, disclosed by Symantec on July 9, 2026, introduces PoisonX — a kernel-mode driver that obtained a legitimate Microsoft Hardware Compatibility Publisher signature and is weaponized to silently kill EDR and antivirus processes before ransomware deployment, a significant escalation in defensive evasion capability. The group's consistent toolchain (AnyDesk, NirSoft suite, PsExec, Mimikatz) across all iterations confirms a single persistent developer organization systematically hardening the same operation.
The Gentlemen emerged in September 2025 following a payment dispute within the Qilin RaaS program and scaled to 478+ publicly claimed victims across 66+ countries by mid-2026 — the fastest growth trajectory of any RaaS operation on record, comparable to early LockBit 3.0. As of July 10, 2026, the group remains the #2 most active ransomware operation globally by victim count. A May 4, 2026 backend database leak exposed the group's full operator roster, toolchain, victim lists, and Bitcoin laundering chains, yet failed to interrupt operations. Microsoft tracks the encryptor as Storm-2697; it uses Go with Garble obfuscation and supports a self-propagating worm mode (--spread flag) enabling enterprise-wide encryption within minutes via Group Policy weaponization.
Scattered Spider is a Western, English-speaking cybercrime collective specializing in social engineering rather than technical exploits, responsible for 100+ intrusions and $100M+ in ransom payments. In a major law enforcement development on July 1, 2026, the DOJ announced the extradition of 19-year-old Peter Stokes ('Bouquet') from Finland to face federal conspiracy, computer intrusion, and fraud charges — the latest in a sustained dismemberment campaign also including guilty pleas from UK members Thalha Jubair and Owen Flowers in June 2026, and a prior April 2026 guilty plea from Tyler Buchanan. International pressure is materially degrading the group's operational leadership roster, though the crew continues activity.
INTERPOL announced on July 9, 2026 the results of Operation First Light 2026, a four-month enforcement campaign (Jan 15–Apr 30) across 97 countries and territories that resulted in 5,811 arrests, $293 million in intercepted illicit assets, and identification of over 142,000 victims across 152,808 analyzed fraud cases. The operation targeted industrialized social engineering syndicate networks running BEC, romance scams, pig-butchering crypto investment fraud, sextortion, and authority impersonation schemes — many operating out of Southeast Asian scam compounds with trafficked workers. A 20-year-old Thai suspect's crypto wallet was found to have processed over $122.5 million in romance-scam proceeds in 10 months using cross-chain token swaps to obscure the financial trail. DOJ had previously indicted operators of the Shunda compound in Myanmar for targeting American victims via fake crypto investment platforms.
A newly exposed initial access broker operation, active since at least February 2026 and disclosed publicly in June-July 2026, that deployed a custom Golang tool called FortigateSniffer onto compromised FortiGate devices to passively intercept VPN credentials at scale across 150+ countries. SOCRadar confirmed on July 2, 2026 that an operator with access to FortiBleed infrastructure was simultaneously logged into ransomware negotiation panels for both INC Ransom and Lynx, directly tying the credential-harvesting pipeline to live extortion deployments for the first time. The operation involved roughly 20 individuals in a tiered structure and utilized approximately 500 servers globally.
JADEPUFFER is the first documented threat operator to conduct a ransomware attack entirely end-to-end via a large language model agent, with no human at the keyboard. Disclosed by Sysdig TRT on July 1, 2026, the LLM autonomously performed reconnaissance, credential theft, lateral movement, persistence, and database encryption against a production Nacos/MySQL server after pivoting from an exploited Langflow instance. The attack self-corrected in real time — recovering from a failed login to a working fix in under 31 seconds — signaling the arrival of autonomous 'agentic' extortion at operational scale.
Turla (Secret Blizzard), attributed to Russia's FSB Center 16 and active since at least 2004, received a major intelligence update on July 7, 2026, when researchers published fresh analysis of its STOCKSTAY and Kazuar backdoor campaigns targeting Ukraine and Europe. A defining and re-highlighted tradecraft is its brazen hijacking of rival threat actors' C2 infrastructure — previously co-opting Iranian OilRig, Pakistani Storm-0156, and Russian cybercriminal Amadey botnet infrastructure — to conduct operations while degrading attribution. Recent campaigns deploy STOCKSTAY via compromised Ukrainian government and IT infrastructure, staging payloads on trusted local domains to evade detection.
Lynx/INC ransomware was newly linked on July 1, 2026, to the massive 'FortiBleed' credential theft campaign, which exposed credentials from over 73,000 FortiGate devices. SOCRadar's investigation identified a FortiBleed infrastructure server whose browser sessions accessed negotiation panels for both Lynx and INC, providing direct evidence of an affiliate overlap between the two groups. Lynx, which emerged in mid-2024, is broadly assessed by researchers as a rebrand of the INC ransomware operation. The FortiBleed operation used a custom 'FortiGate Sniffer' tool deployed on compromised firewalls to intercept VPN credentials in-transit from network traffic.
Sophos CTU disclosed on July 2, 2026 a formal operational partnership between TeamPCP (supply chain compromise specialists, ex-The Com) and Vect (RaaS operator launched Dec 2025), described by researchers as an 'unprecedented model of industrialized ransomware deployment.' TeamPCP poisons trusted open-source security tools (Trivy, KICS, LiteLLM) to harvest 500,000+ cloud credentials at scale, feeding them directly into Vect's ransomware affiliate network, which has also partnered with BreachForums to mass-distribute affiliate keys to ~300,000 registered users. At least one confirmed Vect ransomware deployment using TeamPCP-sourced credentials was verified. Prior to the Vect partnership, TeamPCP operated the CipherForce ransomware brand, and also collaborates with Lapsus$ for data-leak monetization.
Socket Threat Research Team disclosed on July 1–6, 2026 that the North Korea-linked PolinRider supply chain campaign has massively expanded across npm, Packagist, Go modules, and Chrome extensions, with 162 malicious artifacts identified across 108 unique packages. The campaign, attributed to the Famous Chollima / Contagious Interview cluster (Lazarus subset), compromises legitimate maintainer accounts and rewrites Git history to conceal injected obfuscated JavaScript loaders that deliver DEV#POPPER RAT and OmniStealer. As of July 7, 2026, the campaign remains fully active with new compromises continuously surfacing.
Google and the FBI disrupted the NetNut/Popa residential proxy botnet on July 2, 2026, seizing hundreds of domains and disabling Google accounts used for C2, cutting millions of devices from the network. NetNut covertly enrolled over 2 million Android devices (smart TVs, streaming boxes) as exit nodes via trojanized apps and Badbox 2.0 botnet plugins, renting the proxies to threat actors to mask attack origins. GTIG observed 316 distinct threat clusters using NetNut exit nodes in a single June 2026 week. NetNut also operated a white-label reseller program, meaning the takedown cascades across many apparently independent proxy brands.
Kaspersky publicly named Armored Likho on July 4, 2026 after uncovering an active espionage campaign hitting government agencies and electric power operators in Russia, Kazakhstan, and Brazil using a newly documented Python-based infostealer called BusySnake Stealer. The group overlaps substantially with the threat cluster BI.ZONE tracks as Eagle Werewolf, active since May 2023, which previously targeted UAV development organizations and compromised a drone-focused Telegram channel to distribute AquilaRAT in February 2026. Notably, first-stage loader code shows signs of LLM-assisted generation, erasing traditional coding-style attribution fingerprints.
SOCRadar's Threat Research Unit on July 2, 2026 confirmed that the FortiBleed credential-harvesting campaign — which targeted over 430,000 FortiGate firewalls globally and collected 110 million+ credentials using a custom Golang sniffer — is directly operated by or feeding into the INC Ransom and Lynx RaaS groups, representing the first confirmed link between mass FortiGate credential theft and ransomware deployment. An operator with access to FortiBleed infrastructure was found simultaneously logged into negotiation panels for both groups, with victim overlap confirmed. The operation involves approximately 20 individuals with defined roles across a ~500-server infrastructure, and actors are also exploiting an unpatched Nextcloud zero-day to expand access.
Kairos is a data-extortion actor first appearing in November 2024 that, per a Ransom-ISAC case study published July 4–5, 2026, extorted approximately $1 million from a U.S. government entity (likely Union County, Ohio) using only stolen-data exposure threats — no ransomware encryption was ever deployed. The group accessed the network via brute-force credential attack, exfiltrated 1.6 million files (2+ TB), and leveraged prosecutors' office records as maximum-pressure leverage. Kairos's leak site was seized by the Ukrainian Security Service (SBU); its last known victim was posted June 2026 and a linked wallet showed activity as recently as May 2026.
Blackpoint Cyber's Adversary Pursuit Group disclosed on July 3, 2026 a previously undocumented modular malware framework called Avalon, featuring a ransomware component internally named CrownX, delivered through a multi-stage phishing chain abusing Proton Drive and ISO images to bypass email-layer security controls. Avalon is notable for consolidating credential theft, lateral movement, anti-forensics, recovery disruption, and ransomware execution into a single payload — and shows signs of AI-assisted development, significantly lowering the barrier to entry. The framework specifically targets backup and virtualization platforms (Veeam, Acronis, NetApp, vCenter, Hyper-V) to maximize recovery disruption.
The U.S. DOJ announced on July 1, 2026 the extradition of alleged Scattered Spider member Peter Stokes, 19, a dual U.S.-Estonian citizen, from Finland to face federal conspiracy, computer intrusion, and fraud charges in Chicago — the latest in an accelerating series of arrests dismantling the group. Scattered Spider has been linked to 100+ network intrusions resulting in over $100 million in ransom payments through help-desk impersonation, SIM swapping, and fake SSO phishing. The group's decentralized 'The Com' structure is proving resilient despite successive arrests of members including Tyler Buchanan (guilty plea April 2026), Noah Urban (sentenced August 2025), and UK members Thalha Jubair and Owen Flowers (guilty pleas June 2026).
UAT-9244 is a newly designated China-nexus APT cluster tracked by Cisco Talos, assessed with high confidence to closely overlap with FamousSparrow and Tropic Trooper based on shared tooling, TTPs, and victimology. The group has been targeting South American telecommunications providers since 2024 using three previously undocumented implants — TernDoor (Windows), PeerTime (Linux), and BruteEntry (edge devices) — revealing a comprehensive, multi-platform telecom intrusion toolkit. PeerTime's use of the BitTorrent protocol for C2 communications and BruteEntry's conversion of edge devices into ORB proxy nodes represent significant tradecraft innovations complicating attribution and detection.
World Leaks emerged January 1, 2025 as the confirmed rebrand of Hunters International ransomware, shifting entirely to encryption-less data exfiltration and extortion — a significant operational and strategic pivot driven by declining ransomware profitability and law enforcement pressure. The group has claimed 169 victims across 28 countries as of late June 2026, with a +80% month-over-month activity surge, targeting healthcare most heavily. Darktrace detected a World Leaks compromise in early 2026 where encryption was deployed despite the group's public claims, suggesting operational inconsistency and possible affiliate deviation. The group has also been linked to sharing leak site infrastructure with Secp0, positioning itself as shared extortion infrastructure for multiple threat groups.
AudiA6 was one of the most trusted cryptocurrency laundering platforms in the ransomware ecosystem, processing over €336 million (~$389M) in illicit funds between 2022 and 2025 for ransomware groups, darknet markets, and cybercriminals. On June 10, 2026, a coalition of international law enforcement including Europol, the US DOJ, Secret Service, IRS-CI, and Polish Police arrested two alleged administrators (Ruslan Igorevich Tkachuk and Alexander Vladimirovich Ledenev) in Batumi, Georgia, seized 25 domains, took 30+ servers offline, and froze ~€692,000 in cryptocurrency assets. The group also administered Dark2Web, a cybercrime forum where crimes against specific targets were commissioned. Blockchain analysis linked AudiA6 proceeds to over 15 international ransomware investigations including the 2022 LastPass breach and the Swissborg hack.
Palo Alto Networks Unit 42 published a detailed report on June 25, 2026 formally naming CL-STA-1062, a Chinese-speaking APT cluster active since March 2022 that shifted its focus to Southeast Asian government and state-owned critical energy infrastructure from mid-2025 onward. The group compromised at least 10 organizations between October and December 2025 alone and has now introduced TinyRCT, a bespoke previously undocumented .NET backdoor providing persistent access, command execution, screenshot capture, and AES-encrypted file exfiltration. Unit 42 assesses with high confidence this is the same cluster Cisco Talos previously tracked as UAT-7237 in connection with 2025 Taiwan web-hosting attacks.
Operation Endgame's latest phase, announced June 24, 2026, dismantled the infrastructure behind the Amadey loader and StealC infostealer simultaneously, seizing 326 servers and 142 domains and recovering approximately 27 million stolen credentials from over 385,000 compromised systems. Microsoft and Europol assessed that in the first two weeks of May 2026 alone, the two malware families infected over 140,000 computers globally. The operation, coordinated between June 15–19, 2026, used AI-assisted analysis under expanded RICO charges to treat both malware families as a single criminal conspiracy — a novel law enforcement tactic.
On June 26–27, 2026, the FBI and CISA issued an updated joint advisory (PSA I-062626-PSA) naming two previously untracked Russian Intelligence Services clusters, UNC5792 and UNC4221, behind an evolving campaign to hijack Signal and other commercial messaging app accounts. The actors evolved tactics since a March 2026 advisory, now targeting Signal Backup Recovery Keys to silently restore full account history even after victims change devices. The SSU and FBI confirmed on June 27 that the campaign has compromised thousands of accounts across Ukraine, Europe, and the United States.
Active since at least February 2026, FortiBleed is the largest confirmed Fortinet credential-harvesting campaign in history, compromising verified admin and SSL VPN credentials for 86,644 FortiGate devices across 194 countries — roughly 50% of all internet-facing Fortinet firewalls globally. The Russian-speaking IAB deployed a custom Golang-based tool (FortigateSniffer) to passively capture cleartext credentials passing through compromised firewalls, cracked hashes via a 45-GPU Hashtopolis cluster, and pivoted into Active Directory environments. A NATO defense contractor was confirmed compromised with classified documents exfiltrated on June 15. CISA, UK NCSC, and Fortinet all issued emergency advisories by June 18–19, 2026.
UNC3886 is a highly disciplined China-nexus APT group that confirmed its status as one of the most capable telecom-targeting actors globally after Singapore's CSA disclosed on February 9, 2026 that the group had breached all four of Singapore's major telcos (M1, SIMBA Telecom, Singtel, StarHub) in a campaign persisting undetected for nearly a year. The group used a zero-day exploit to bypass perimeter firewalls, deployed the REPTILE and MEDUSA Linux kernel rootkits for stealth persistence, and exfiltrated technical network data. Singapore mounted Operation CYBER GUARDIAN — its largest-ever coordinated cyber incident response — involving 100+ defenders across 11 months to evict the group. Campaign TTPs overlap with broader Salt Typhoon telecom targeting patterns observed in the U.S., Canada, and Norway.
AudiA6 was an industrial-scale cryptocurrency laundering operation linked to more than 15 global investigations related to ransomware attacks and large-scale crypto theft. On June 10, 2026, Europol and the U.S. DOJ coordinated the arrest of two administrators — Ruslan Igorevich Tkachuk and Alexander Vladimirovich Ledenev — in Georgia, froze €692,000 in cryptocurrency assets, and seized the AudiA6 and associated Dark2Web cybercrime forum. The operation originated from a September 2025 Polish Police arrest of a Ukrainian national whose seized devices identified additional operators.
As part of the ongoing Operation Endgame Phase 4 (June 2026), Europol and partners from six countries disrupted the Amadey and StealC malware-as-a-service networks, seizing 326 servers, freezing $47M in criminal cryptocurrency, and recovering 27 million stolen login credentials from 385,000 compromised systems. Microsoft's Digital Crimes Unit filed a RICO civil lawsuit after AI-assisted analysis (using Microsoft Copilot) revealed Amadey and StealC shared the same C2 infrastructure despite being developed by separate criminal groups, enabling a unified takedown of 200+ C2 servers. In May 2026 alone, the two infostealers were linked to 140,000 infected computers.
On June 24, 2026, Europol announced Phase 4 of Operation Endgame — the largest international operation ever undertaken to dismantle ransomware enablers — targeting the criminal assembly line behind SocGholish (Evil Corp), Amadey, and StealC. Law enforcement and private-sector partners from six countries seized 326 servers and 142 domains, froze €41M ($47M) in criminal cryptocurrency, and recovered 27 million stolen credentials from 385,000 compromised systems. Microsoft's DCU simultaneously filed a civil RICO lawsuit against Amadey and StealC operators after AI-assisted analysis revealed shared C2 infrastructure, enabling unified takedown of 200+ servers in a single court action — a novel legal precedent in cybercrime prosecution.
SocGholish (TA569) is a long-running JavaScript-based malware framework and initial access broker, directly linked to Evil Corp (the Zeus/Dridex/WastedLocker syndicate), that converts compromised legitimate WordPress sites into drive-by malware delivery vehicles via convincing fake browser update prompts. On June 18, 2026, Operation Endgame — a multinational coalition led by the Dutch NHTCU, FBI, German BKA, and RCMP — seized 106 servers and domains and remotely cleaned ~14,971 compromised WordPress sites, its most significant disruption to date. A follow-on June 24 Europol action expanded Operation Endgame to seize 326 total servers, freeze $47M in criminal cryptocurrency, and recover 27 million stolen credentials targeting Amadey and StealC infostealer infrastructure that shared the same C2 backend.
KimWolf is an Android-focused IoT DDoS botnet operated as a DDoS-for-hire service, directly descended from the Aisuru botnet with a redesigned codebase to evade detection. At its peak it infected approximately 2 million devices (Android TV boxes, web cameras, DVRs, digital photo frames) generating ~12 million unique IPs weekly and was linked to a record-breaking 30 Tbps DDoS attack. Infrastructure was seized in a March 2026 international operation; operator Jacob Butler ('Dort') was arrested by Ontario Provincial Police on May 21, 2026 and faces U.S. extradition on computer intrusion charges.
DragonForce has transitioned from a standard RaaS operation to a highly organized cartel structure with APT-grade tradecraft. A Symantec/Carbon Black report published June 16–17 2026 revealed the group deployed Backdoor.Turn — the first known malware to abuse Microsoft Teams TURN relay infrastructure — to mask C2 traffic as legitimate Teams traffic during a months-long dwell inside a major US services firm. The group also used a then-undocumented BYOVD exploit against a Huawei driver, reflecting substantial investment in offensive tooling.
Qilin (aka Agenda) is a highly active RaaS operation that dominated the ransomware landscape in 2025 and remains a top-tier threat in 2026, ranking #1 by total victim count over the past 12 months with an estimated 1,448 attacks. In a major escalation disclosed June 8, 2026, a Qilin affiliate was confirmed to have exploited CVE-2026-50751 — a critical CVSS 9.3 authentication bypass zero-day in Check Point Remote Access VPN — since May 7, 2026, a full month before a patch was available. CISA added the vulnerability to its KEV catalog on June 9, 2026 with a three-day federal patch deadline, underscoring the severity of active exploitation.
The FortiBleed threat cluster is a newly identified Russian-speaking group responsible for what researchers are calling the largest industrialized credential-harvesting campaign in Fortinet's history. First publicly surfaced on June 13, 2026, by researcher Volodymyr Diachenko, the group systematically collected configuration files from internet-facing FortiGate firewalls, cracked SHA-256 password hashes using a dedicated 45-GPU cluster, and built a verified database of working administrator and VPN credentials for up to 86,644 devices across 194 countries. CISA issued an emergency advisory on June 18, Fortinet's PSIRT published a formal warning on June 19, and the UK NCSC issued a global alert — all within a six-day window. The credential pool is confirmed to be circulating in criminal underground markets and is already being leveraged by both opportunistic criminals and more sophisticated state-adjacent actors for targeted intrusions, including confirmed exfiltration of classified documents from a Turkish NATO defense contractor.
Twill Typhoon (Mustang Panda) was identified by Darktrace in May 2026 conducting a sustained APAC-focused espionage campaign active since September 2025, deploying an updated version (v3.2.5.1) of the FDMTP modular .NET backdoor via DLL sideloading. The campaign involved infrastructure impersonating Yahoo and Apple CDN services to blend malicious traffic with legitimate web activity, and used legitimate Windows binaries (vshost.exe, dfsvc.exe, Sogou Pinyin IME) as sideloading vehicles. In a concurrent development, Salt Typhoon — a related Chinese APT cluster — was observed targeting an Azerbaijani oil and gas company between December 2025 and February 2026, marking a geopolitical pivot linked to Azerbaijan's expanding role in European energy security.
AudiA6 was a prolific cryptocurrency laundering service and the operators of the Dark2Web underground cybercrime forum, collectively serving as a critical financial pipeline for ransomware groups and Eastern European cybercrime syndicates since 2021. The service laundered an estimated €336 million (~$389M) using thousands of fraudulent KYC-verified exchange accounts and was linked by Europol to more than 15 international ransomware investigations. On June 10, 2026, a coordinated international law enforcement operation involving the US DOJ/Secret Service/IRS-CI, Europol, Eurojust, Polish Police, and partners from 11 countries dismantled the operation — arresting both administrators in Georgia, seizing 30+ servers, taking down 25 domains, and recovering 6,000+ money mule KYC records.
Atomic Arch is a large-scale, actively expanding supply chain campaign first detected by Sonatype on June 11, 2026, in which an unidentified threat actor systematically adopted orphaned Arch Linux AUR packages and injected malicious PKGBUILD scripts to deploy a Rust-based credential stealer ('deps') and optional eBPF rootkit. By June 12 a second wave emerged using Bun-based delivery, and the total affected package count grew to approximately 1,500 — one of the largest documented AUR compromises on record. The attack targets developer workstations specifically, aiming to harvest credentials that enable lateral movement into enterprise environments without direct exploitation.
SniperDz was one of the world's longest-running phishing-as-a-service (PhaaS) platforms, active since 2015 and serving cybercriminals in at least 13 MENA-region countries. Operating via Telegram and Facebook, it offered 80 ready-made phishing templates in five languages targeting 30+ global brands including PayPal, Facebook, Netflix, and Steam across 20,000+ domains. The platform and its primary developer-administrator were taken down by INTERPOL Operation Ramz (announced June 11, 2026), resulting in 201 arrests across MENA and the seizure of 53 servers.
New CYFIRMA research published June 10, 2026 revealed that the energy and utilities sector appeared in 66.6% of all observed APT campaigns over the preceding three months — with Chinese actor Mustang Panda, North Korea's Lazarus Group, and Russia's Sandworm (APT44) identified as the most active adversaries across attacks spanning 18 countries. The China-aligned MISSION2074 cluster recorded the highest campaign count of any single actor across all sectors in the most recent reporting period, with Volt Typhoon, Salt Typhoon, Earth Estries, and Hafnium providing additional Chinese representation. Sandworm was separately linked to a destructive DynoWiper malware campaign targeting Poland's energy sector in late 2025.
First VPN Service was a criminal-focused virtual private network operating since 2014 across 27 countries, almost exclusively advertised on Russian-language dark web forums. At least 25 ransomware groups — including Avaddon — used its infrastructure to mask network intrusions and scope targets globally. The service was seized on June 9, 2026 as the first major action under the FBI's newly announced Operation Riptide, a 60-day coordinated international cyber enforcement campaign targeting criminal infrastructure, tools, and financial networks.
ESET Research disclosed on June 11, 2026 that OceanLotus (APT32) has undergone a significant strategic pivot toward domestic espionage inside Vietnam, marking a departure from its historically external targeting of China and Southeast Asian governments. Two distinct 2024–2026 campaigns were revealed: a 15-month intrusion into a Vietnamese infrastructure and transport construction corporation, and a precision supply-chain attack against FireAnt MetaKit — a stock market data platform — that selectively delivered the SPECTRALVIPER backdoor to a handful of high-value investors linked to Vietnam's ongoing financial market investigations. Researchers assess OceanLotus is now acting as a digital surveillance arm of the Vietnamese state's anti-corruption apparatus.
Scattered Lapsus$ Hunters (SLSH) is a declared alliance of three notorious English-speaking cybercrime collectives — Scattered Spider, Lapsus$, and ShinyHunters — that formalized a joint operation in August 2025 following a series of coordinated Salesforce platform intrusions claiming 91 victim organizations. The alliance is now developing ShinySp1d3r, a custom RaaS platform featuring novel ETW hook-based logging suppression, self-propagating encryptor, and planned Linux/VMware ESXi variants — representing a leap from the groups' historical reliance on third-party encryptors (BlackCat, Qilin, DragonForce). The collective is actively recruiting corporate insiders targeting organizations with $500M+ annual revenues, excluding CIS countries and healthcare, with aggressive commission-based IAB deals and insider outreach on Telegram and dark web forums heading into mid-2026.
On June 9, 2026, the FBI's Cyber Division announced Operation Riptide — a coordinated, 60-day international law enforcement campaign targeting the full criminal ecosystem supporting cyber-enabled crime, including infrastructure, tools, communications platforms, and financial networks. The first major action under Riptide was the international takedown of 'First VPN Service' (active 2014–2026, 27 countries), used by at least 25 ransomware groups including Avaddon; concurrently, on June 10, Europol dismantled the AudiA6 Russian cryptocurrency mixing service — linked to over €336M ($389M) in laundered ransomware proceeds since 2021 — and its associated Dark2Web cybercrime forum. Additional actions by FBI, France's DNPJ, Dutch National Police, and partners across Ukraine, UK, Switzerland, and Luxembourg have included arrests, indictments, cryptocurrency seizures, and server confiscations; further actions are expected through August 2026.
Vect is a newly emerged RaaS operation identified by Halcyon and analyzed by Red Piranha, notable for building its encryptor in C++ from scratch (not repurposing LockBit 3.0 or Conti leaked code) and using ChaCha20-Poly1305 AEAD encryption — 2.5x faster than AES-256-GCM on non-accelerated hardware. The group demonstrates unusual operational maturity for its age: cross-platform targeting of Windows, Linux, and VMware ESXi; Safe Mode execution to suppress security tools; Monero-only payments; TOX protocol for affiliate communications; and exclusively TOR hidden services with no clearnet presence. Analysts from Red Piranha assess Vect is likely a rebrand or new venture by experienced RaaS operators, given the sophistication of its initial launch.
Payload emerged in February 2026 and rapidly listed 50+ victims across 7+ countries within its first month of operations. The group uses Babuk-derived source code for cross-platform Windows and ESXi encryption (ChaCha20 + Curve25519 ECDH per-file key exchange) paired with aggressive anti-forensics including ETW memory patching, VSS deletion, and Windows Event Log clearing. Notable for a 'MakeAmericaGreatAgain' mutex string embedded in its binary — a distinct operator fingerprint — and for targeting emerging markets including the MENA region as a primary focus.
Rapid7 disclosed in May 2026 that MuddyWater (Seedworm) conducted a sophisticated false-flag ransomware operation in early 2026, operating under the Chaos RaaS banner while forensic analysis revealed MOIS-linked code-signing certificates ('Donald Gay' + 'Amy Cherne' cert cluster) tying the intrusion to Operation Olalampo. The group used interactive Microsoft Teams sessions to harvest MFA credentials under an 'IT Support' social engineering persona. This marks a significant evolution: MuddyWater adopting a commercially available RaaS brand to project a cybercriminal identity while conducting intelligence-driven targeted operations, blurring the line between espionage and ransomware.
SHADOW-EARTH-053, disclosed by Trend Micro on April 30, 2026, is a newly identified China-aligned intrusion cluster targeting government and defense sectors across South, East, and Southeast Asia — including Pakistan, Thailand, Malaysia, India, Myanmar, Sri Lanka, Taiwan — as well as Poland (a NATO member). Analysts at The Diplomat characterized the campaign as a qualitative shift in Beijing's playbook, with a single workflow fusing traditional state espionage against ministries of defense with active phishing of Uyghur, Tibetan, Taiwanese, and Hong Kong dissidents abroad. The campaign is among the first major operations assessed to have emerged under China's reorganized Cyberspace Force following the April 2024 dissolution of the Strategic Support Force.
CARR, founded, funded, and directed by the GRU, claimed credit for hundreds of destructive cyberattacks worldwide including attacks on US public drinking water systems across multiple states and a November 2024 attack on a Los Angeles meat processing facility that triggered an ammonia leak. A Ukrainian national, Victoria Dubranova (aka SovaSonya), was extradited to the US and faces trial in 2026 for her roles supporting both CARR and NoName057(16) under DOJ Operation Red Circus — the first prosecution of a GRU-directed hacktivist operator. CARR had over 100 members and 75,000+ Telegram followers at peak activity.
LockBit resurfaced in September 2025 with LockBit 5.0 (internally codenamed 'ChuongDong'), announcing the release on the group's sixth anniversary on underground forums. The new variant introduces advanced anti-forensics including ETW patching, DLL reflection loading, randomized 16-character file extensions, and full cross-platform support for Windows, Linux, ESXi, and Proxmox. In Q1 2026, LockBit posted 163 victims — a 106% increase over Q4 2025 — climbing to 4th globally. In October 2025, LockBit formalized an alliance with Qilin and DragonForce, creating a ransomware cartel with shared infrastructure, mutual affiliate referrals, and coordinated OPSEC designed to resist law enforcement disruption.
JINX-0164 is a newly identified, financially motivated threat actor first named by Wiz Research in May 2026 after investigating multiple intrusions against cryptocurrency organizations. The group targets macOS-reliant software developers via LinkedIn recruiter-themed social engineering, deploying two custom malware families — AUDIOFIX (Python-based infostealer/RAT) and MINIRAT (Go-based backdoor) — and has demonstrated supply chain attack capability by trojanizing the npm package @velora-dex/sdk (v4.9.1) in April 2026. Despite tactical similarities to known North Korean clusters, no confirmed infrastructure overlap with state-sponsored groups has been established.
GHOST STADIUM is a Chinese-speaking, financially motivated threat actor exposed by Group-IB in late May 2026 as the primary operator at the center of a massive fraud ecosystem targeting the 2026 FIFA World Cup. The group runs 300+ active phishing domains built on a custom React/Layui phishing kit that clones fifa.com to near pixel-perfect fidelity, replicating even the PingIdentity SSO authentication flow using the real FIFA client_id. Campaign losses across all six associated fraud schemes — credential phishing, fake ticket sales, counterfeit merchandise, fake streaming, fraudulent betting, and infostealer-driven theft — are projected to reach into the billions, with premium ticket fraud alone estimated at $71M–$474M.
SideCopy, a Pakistan-linked sub-cluster of the broader Transparent Tribe (APT36) umbrella, disclosed a new campaign on June 2, 2026 (Operation XENOFISCAL) targeting Afghanistan's Ministry of Finance and all 34 provincial revenue and finance directorates. The group deployed Xeno RAT 1.8.7 via Pashto-language LNK lure files and a compromised Afghan education domain as a staging server, demonstrating operational familiarity with the Afghan government environment. The campaign is assessed as ongoing since at least May 2025 and reflects a sustained effort to collect national financial intelligence.
Crimson Collective is an emerging extortion group that surfaced in September 2025 and rapidly gained notoriety by breaching Red Hat's internal GitLab in October 2025, exfiltrating approximately 570 GB of data from 28,000+ repositories with downstream impact on Nissan customer PII. In January 2026, the group claimed to have stolen data on over 1 million Brightspeed fiber broadband customers and listed the dataset for sale at 3 BTC. The group specializes in targeting misconfigured cloud environments, AWS IAM exploitation, and development infrastructure rather than traditional endpoint ransomware deployment, using Telegram-based extortion pressure.
UAT-9244 is a China-nexus APT cluster tracked by Cisco Talos that has been targeting critical telecommunications infrastructure in South America since 2024, deploying three previously undocumented malware implants: TernDoor (Windows), PeerTime (Linux/embedded), and BruteEntry (ORB proxy builder). Disclosed publicly on March 6, 2026, the campaign demonstrates continued Chinese state investment in telecom compromise tradecraft, including P2P BitTorrent-based C2 on Linux and ORB-style relay infrastructure designed to complicate attribution and defeat IOC-based blocking. Cisco Talos assesses with high confidence that UAT-9244 closely overlaps with FamousSparrow and Tropic Trooper based on shared tooling and TTP overlap, though a confirmed direct link to the separately tracked Salt Typhoon cluster has not been established.
Salt Typhoon, the China-linked APT behind the 2024 US telecom lawful intercept compromise, remains confirmed 'still very much ongoing' per FBI leadership as of February 2026. New confirmed 2026 activity includes: breach of US House Committee staff emails (January 9, 2026) focused on national security personnel overseeing China policy; penetration of all four major Singapore telecom providers (disclosed February 2026, triggering Singapore's largest-ever cyber counteroperation CYBER GUARDIAN); and reports of operations now spanning 80+ countries. New implants TernDoor, PeerTime, and BruteEntry attributed to the closely related UAT-9244/FamousSparrow cluster further illustrate the breadth of China-aligned telecom targeting.
TeamPCP is a highly sophisticated criminal threat actor responsible for the ongoing Shai-Hulud supply chain worm campaign, the most technically advanced open-source supply chain attack series documented to date. The May 2026 'Mini Shai-Hulud' wave compromised 172+ npm and PyPI packages across 518 million cumulative downloads—including TanStack, Mistral AI, UiPath, OpenSearch, and OpenAI packages—by defeating SLSA Build Level 3 provenance attestations through GitHub Actions CI cache-poisoning rather than signature forgery. The group has confirmed partnerships feeding harvested credentials to the Vect RaaS operation and LAPSUS$ extortion group, and on May 13, 2026 open-sourced the Shai-Hulud worm on BreachForums, transforming into a platform operation with affiliate contest mechanics targeting the AI developer toolchain.
First VPN was a criminal anonymization service operating since 2014 that marketed exclusively on cybercriminal forums, promising no-logging and no-cooperation with judicial authorities across 5,000+ accounts. It was dismantled May 19–20, 2026 in Operation Saffron, led by French and Dutch authorities with Europol/Eurojust support, seizing 33 servers across 27 countries and identifying hundreds of users. Intelligence generated was linked to 25 distinct ransomware groups including the Phobos RaaS outfit, and 83 intelligence packages covering 506 users were shared with partner countries for follow-on prosecution.
The BlueNoroff/UNC1069 sub-unit of Lazarus executed the most significant npm supply chain attack of 2026 on March 30-31, poisoning the axios JavaScript package (~100M weekly downloads, present in ~80% of cloud environments) by socially engineering the lead maintainer to steal a long-lived npm access token and publish two malicious versions injecting the WAVESHAPER.V2 RAT (also tracked as SILKBELL by GTIG). The attack was contained in roughly three hours but generated ~600,000 poisoned downloads; OpenAI's macOS app-signing pipeline was exposed, forcing full code-signing certificate rotation. CISA issued an advisory on April 20, 2026, and attribution was confirmed by Microsoft (Sapphire Sleet), Google GTIG (UNC1069), and ThreatBook (Lazarus) independently.
Lapsus$ returned to headlines in late April 2026 with a confirmed breach of Vodafone UK's internal network, publishing 7.1GB of source code, infrastructure diagrams, GitHub repository trees, and internal network maps on May 28, 2026 after Vodafone refused to pay within a 15-day negotiation window. This is the second Vodafone breach by Lapsus$ (the first was in February 2022). In mid-2025, Lapsus$ merged with Scattered Spider and ShinyHunters into the loosely federated 'Scattered Lapsus$ Hunters' (Trinity of Chaos) conglomerate, sharing infrastructure and leak sites while maintaining individual operational autonomy.
First VPN was a cybercriminal anonymization service operating since 2014 that was marketed exclusively on Russian-speaking cybercrime forums and used by at least 25 ransomware groups including Phobos RaaS affiliates. On May 19-20, 2026, Operation Saffron — led by French and Dutch authorities with Europol and Eurojust support — seized 33 servers across 27 countries, shut down all domains, and interviewed the Ukrainian-based administrator in a house search. Intelligence packages covering 506 identified users were shared with 83 partner countries. Law enforcement obtained live access to criminal traffic prior to the takedown, de-anonymizing the entire user base.
IRGC-affiliated Iranian APT that dramatically accelerated operations during the US-Israeli military campaign against Iran in early 2026, deploying a brand-new AI-assisted backdoor (MiniFast) mid-conflict across three distinct campaign waves between February and April 2026. Check Point Research disclosed the campaigns on May 22-26 2026, marking this as the most significant Iranian APT disclosure in the last 48 hours. The group introduced SEO poisoning for the first time as a delivery vector, pushing a fake SQL Developer download page to the top of Bing and DuckDuckGo results, and replaced DLL sideloading with AppDomain hijacking.
A Russia-linked extortion group that spun off from the Conti post-shutdown ecosystem in 2022 and has now escalated to a historically unprecedented physical intrusion tactic: sending operatives in person to victim law firm offices, disguised as IT support staff, to insert USB drives and exfiltrate data directly. The FBI issued a FLASH-severity alert (FLASH-20260526-01) on May 26, 2026 — the highest-urgency classification — detailing this active Spring 2026 development. SRG deploys no malware or encryption, leaving minimal forensic artifacts and defeating most EDR tooling; 38+ firms have had data publicly posted and total attack count exceeds 100 confirmed incidents.
First VPN was a criminal VPN service operating since 2014 that provided anonymization infrastructure to over 25 ransomware groups and 5,000+ criminal accounts. It was dismantled on May 19-20, 2026 under Operation Saffron, led by France and the Netherlands with Europol/Eurojust coordination, resulting in 33 server seizures across 27 countries and the interviewing of the Ukrainian operator. The operation exposed 506 identified users whose intelligence packages have been shared with partner countries, generating ongoing investigative leads into ransomware attacks, fraud schemes, and the Phobos RaaS operation.
Operation Saffron, executed May 19–20, 2026 by French and Dutch authorities with Europol/Eurojust support, dismantled First VPN — a criminal anonymization service operational since 2014 that appeared in virtually every major Europol cybercrime investigation in recent years. The service was used by at least 25 ransomware groups (including Avaddon and Phobos), had over 5,000 accounts, and was promoted exclusively on Russian-speaking cybercrime forums. Law enforcement obtained criminal traffic logs, seized 33 servers across 27 countries, arrested the Ukrainian administrator, and shared 83 intelligence packages on 506 users with partner nations — generating downstream investigative leads for ongoing ransomware prosecutions.
CERT-UA issued an advisory on May 21, 2026 warning that Ghostwriter (UAC-0057/UNC1151) had launched a new phishing campaign against Ukrainian government organizations using lures themed around the Prometheus online learning platform. The attack delivers a three-stage malware chain: OYSTERFRESH (JS decoy/dropper), OYSTERBLUES (registry-persisted encrypted payload), and OYSTERSHUCK (decoder), with C2 infrastructure hidden behind Cloudflare on .icu TLD domains. This represents a fresh tooling update from the group's prior tradecraft.
Operation Saffron, executed May 19–20, 2026 by French and Dutch authorities with Europol/Eurojust support, dismantled First VPN — a criminal anonymization service operational since 2014 and embedded in virtually every major Europol cybercrime investigation in recent years. 33 servers across 27 countries were seized, the administrator was arrested in Ukraine, and 83 intelligence packages were shared with partner countries covering 506 identified users. Bitdefender supported the investigation. This marks the first VPN-category takedown in Europol history and will fuel follow-on prosecutions across the ransomware ecosystem.
SpaceBears, a Phobos RaaS affiliate first observed in April 2024, posted a new victim on ransomware.live on May 27, 2026 (within the last 48 hours) — Ridge Law Firm in the Bronx, New York — with an attack estimated on May 12. On May 26, the group also claimed an attack against Italian logistics firm BASE S.p.A. The group is notable for its 'corporate' aesthetic data leak site and has accumulated 122+ listed victims primarily in the US, Germany, Spain, Italy, and Canada across technology, healthcare, and manufacturing sectors.
Iran-nexus APT group newly detailed by Unit 42 (Palo Alto Networks) in a report published May 22, 2026. Between February and April 2026, the group dramatically escalated operations aligned with the outbreak of the US-Israel-Iran regional conflict on Feb 28, deploying six new RAT variants across two new malware families (MiniUpdate and MiniJunk V2) against targets in the US, Israel, UAE, and at least two additional Middle Eastern countries. For the first time, researchers observed the group fusing its standard DLL sideloading techniques with advanced AppDomainManager hijacking, disabling security mechanisms before applications fully start. The group's campaigns are tightly correlated to geopolitical escalation, with campaign spikes tracked within 72–96 hours of kinetic events.
Rapid7 disclosed on May 6, 2026 that MuddyWater — Iran's MOIS-linked APT — conducted a sophisticated false-flag operation disguised as a Chaos ransomware attack in early 2026. The group used Microsoft Teams social engineering to harvest credentials and manipulate MFA, then deployed the custom Darkcomp (Game.exe) RAT, but deliberately withheld file encryption to prioritize long-term espionage persistence while creating the illusion of a financially motivated attack. Confirmed targets include a US bank, a US airport, nonprofits, and a defense/aerospace software supplier with Israeli operations. Attribution rests on the 'Donald Gay' code-signing certificate, C2 infrastructure at moonzonet[.]com, and use of pythonw.exe for process injection — all previously tied to MuddyWater's 'Operation Olalampo.'
Formally attributed by the US DOJ (March 2026) as an Iranian MOIS 'fake activist persona,' Handala dramatically escalated operations following the Feb 28 US-Israel military strikes on Iran. In March 2026 alone, the group executed a destructive MDM-abuse wiper operation against Stryker Corporation deleting data from 200,000+ devices across 79 countries, compromised FBI Director Kash Patel's personal email, and published PII for 28 Lockheed Martin engineers in Israel. The State Department issued a $10M reward for operator identification; the FBI seized four Handala leak site domains. The group continued operating through Iran's internet blackout by using Starlink VSAT connectivity, and executed a WhatsApp threat campaign against US Marines at Naval Support Activity Bahrain in late April 2026.
First VPN — a criminal VPN service operating since 2014 and marketed exclusively on Russian-speaking cybercrime forums — was dismantled May 19–20, 2026 in Operation Saffron, led by French and Dutch authorities with Europol and Eurojust support. The service had over 5,000 accounts, was linked to at least 25 ransomware groups including the Phobos RaaS outfit, and facilitated more than $70M in illicit proceeds laundering. Law enforcement seized 33 servers across 27 countries, shut down domains including 1vpns.com and associated .onion addresses, and generated 83 intelligence packages covering 506 users shared with partner countries. All users were notified their identities are now known to authorities. This represents a significant blow to the anonymization layer of the ransomware supply chain.
KimWolf was a massive IoT DDoS-for-hire botnet operated by Jacob Butler (alias 'Dort'), a 23-year-old Ottawa resident arrested by Canadian authorities on May 21, 2026 under a US extradition warrant. Assessed as a variant/successor of the AISURU botnet, KimWolf infected nearly two million devices globally — targeting inherently vulnerable endpoints including digital photo frames, web cameras, and Android smart TVs — and issued over 25,000 attack commands linked to a record-breaking 31.4 Tbps DDoS attack. The DOJ unsealed charges the same day and simultaneously disrupted 45 DDoS-for-hire platforms that collaborated with the KimWolf ecosystem.
First VPN was a criminal VPN service operating since 2014, marketed exclusively on Russian-speaking cybercriminal forums and used by over 5,000 accounts including at least 25 ransomware groups (notably Phobos RaaS affiliates). Taken offline May 19–20, 2026 via Operation Saffron — a joint French/Dutch/Europol/Eurojust action seizing 33 servers across 27 countries and interviewing the Ukrainian operator. Before shutdown, law enforcement gained covert visibility into criminal user traffic; 83 intelligence packages covering 506 identified users were disseminated to partner countries for ongoing ransomware and fraud investigations.
Rapid7 disclosed on May 6, 2026 that MuddyWater conducted a sophisticated false-flag intrusion in early 2026, masquerading as a Chaos RaaS affiliate to conceal state-sponsored espionage. The campaign involved Microsoft Teams social engineering, MFA manipulation, credential harvesting, and deployment of a custom Darkcomp (Game.exe) RAT — but never deployed file-encrypting ransomware, exposing the espionage intent. This follows a pattern: MuddyWater previously used Qilin ransomware against an Israeli organization in late 2025, then switched to Chaos branding post-attribution to reduce detection risk. Confirmed U.S. victims include a bank, an airport, nonprofits, and a defense/aerospace software supplier.
KimWolf was a record-breaking IoT DDoS botnet operated as a criminal rental service, assessed by the DOJ as a variant of the AISURU botnet. The botnet infected nearly 2 million IoT devices globally — including digital photo frames, web cameras, and streaming TV boxes — and generated attack traffic peaking at nearly 30 Tbps, the largest DDoS volume publicly disclosed at the time. Its administrator, Jacob Butler ('Dort') of Ottawa, was arrested on May 20, 2026 under a U.S. extradition warrant and charged in the District of Alaska; infrastructure was seized in a March 2026 multinational operation alongside related botnets Aisuru, JackSkid, and Mossad.
First VPN was a cybercriminal-market VPN service operating since 2014, dismantled May 19–20, 2026 in Operation Saffron by French and Dutch authorities with Europol/Eurojust support. The service had over 5,000 accounts and was confirmed used by at least 25 ransomware groups, including Phobos RaaS affiliates. Europol seized 33 servers across 27 countries and generated 83 intelligence packages covering 506 identified users, enabling downstream ransomware and fraud investigations across multiple countries. All active users were notified their identities are known to law enforcement.
GopherWhisper is a previously undocumented China-aligned APT group publicly disclosed by ESET Research on April 23, 2026, after being discovered in January 2025 targeting a Mongolian government institution. The group wields a seven-tool Go-based malware suite routing all C2 traffic through legitimate enterprise platforms — Slack, Discord, and Microsoft 365 Outlook — to evade network detection. Analysis of recovered C2 traffic from attacker-controlled Slack and Discord servers indicates dozens of additional victims beyond the confirmed Mongolian target.
Rapid7's May 6, 2026 report 'Muddying the Tracks' disclosed that MuddyWater conducted a sophisticated false-flag intrusion in early 2026, masquerading as a Chaos RaaS affiliate to conceal state-sponsored espionage objectives. The campaign used Microsoft Teams social engineering to harvest credentials and manipulate MFA, deploying the custom Darkcomp/Game.exe RAT and remote management tools (DWAgent, AnyDesk) for persistent access — but never deployed actual file-encrypting ransomware. This follows a pattern established in late 2025 when MuddyWater used Qilin RaaS against an Israeli organization; the switch to Chaos branding is assessed as a deliberate move to reduce attribution risk after the Qilin incident was attributed to MOIS.
APT73, also known as Bashe, is a ransomware group that emerged in mid-April 2024, self-styling as an Advanced Persistent Threat and operating a TOR-based data leak site bearing a striking resemblance to LockBit's infrastructure. The group has surged in activity in May 2026, posting multiple high-profile victims within 48 hours including Turkey's General Directorate of Land Registry (TKGM, a government agency), Thailand's National Astronomical Research Institute (NARIT), and Mexican corn producer Minsa S.A.B. de C.V. — all claimed on May 21–22, 2026. The group previously claimed 50GB stolen from UK investment platform Hargreaves Lansdown in late April 2026.
KryBit is an emerging RaaS operation that launched in late March 2026, offering affiliates an aggressive 80/20 revenue split with cross-platform ransomware builders for Windows, Linux, ESXi, and NAS devices. The group posted 10 legitimate victims within its first two weeks and engaged in a high-profile ransomware turf war with rival group 0APT in April 2026, in which KryBit successfully hacked back, defaced 0APT's infrastructure, and exposed its full operational dataset — revealing that 0APT's 190+ claimed victims were entirely fabricated. Despite active affiliate operations and staged victim data (10–250GB per victim, ransom demands $40K–$100K), KryBit had collected zero ransom payments as of mid-April 2026 per leaked wallet data. The group employs structured double-extortion with shadow copy deletion and TOR-based leak infrastructure.
First VPN was a criminal-facing VPN anonymization service active since 2014, advertised exclusively on Russian-speaking cybercrime forums and used by threat actors across ransomware, fraud, and data theft operations including the Phobos RaaS outfit. The service was dismantled on May 19–20, 2026, by French and Dutch authorities under Operation Saffron with Europol/Eurojust support, in one of the first VPN-category takedowns in law enforcement history. Authorities seized 33 servers across 27 countries, took down domains including 1vpns.com/net/org and .onion mirrors, and generated 83 intelligence packages on 506 users linked to active ransomware investigations.
Silver Fox is a China-linked APT group newly documented by Kaspersky (May 2026) as having significantly expanded its geographic targeting to include Russia and India, using tax-authority impersonation phishing to deploy a newly discovered Python-based backdoor called ABCDoor alongside the established ValleyRAT (Winos 4.0) RAT. The group's technical maturity is growing: ABCDoor features visual remote control via FFmpeg screen-broadcasting, DPAPI-encrypted persistence, and self-updating/self-deletion logic — distinct from traditional shell-based RATs. Over 1,600 malicious emails were recorded in a single month-long period in early 2026.
First VPN was a criminal VPN service operating since 2014, exclusively promoted on Russian-speaking cybercrime forums, used by ransomware actors including those linked to the Phobos RaaS operation. On May 19–20, 2026, French and Dutch authorities dismantled the service under Operation Saffron, seizing 33 servers across 27 countries, shutting down domains (1vpns.com/.net/.org and .onion mirrors), and interviewing the Ukrainian administrator. Law enforcement had covert access to criminal traffic prior to takedown and issued identification notifications to over 5,000 user accounts, generating 83 intelligence packages covering 506 users for partner nations.
SYLVANITE is a newly named Dragos-tracked threat group identified as a dedicated initial-access broker operating in direct support of Volt Typhoon. The group gains footholds across OT-adjacent organizations in North America, Europe, South Korea, Guam, the Philippines, and Saudi Arabia, then hands off access to Volt Typhoon for deeper persistence and OT reconnaissance. Dragos has attributed several recent high-profile vulnerability exploitation campaigns — including Ivanti and Trimble Cityworks GIS — to SYLVANITE, making it a critical link in China's critical infrastructure pre-positioning strategy.
Coinbase Cartel is a data-extortion-only group active since September 2025, assessed by Halcyon and Fortinet FortiGuard Labs as an offshoot of the ShinyHunters, Scattered Spider, and LAPSUS$ ecosystems. The group does not deploy ransomware encryption; instead it steals sensitive data and extorts victims under threat of public disclosure, amassing 170+ victims. In the last 48 hours (May 15–18, 2026), the group claimed Grafana Labs after exploiting a misconfigured GitHub Actions workflow to exfiltrate Grafana's entire private codebase.
UAT-8616 is a highly sophisticated, assessed China-nexus threat actor designated by Cisco Talos that has been persistently exploiting Cisco Catalyst SD-WAN infrastructure since at least 2023. In the last 48 hours (May 14–15, 2026), the group was attributed with high confidence to exploitation of CVE-2026-20182 (CVSS 10.0), the sixth SD-WAN zero-day exploited in 2026, prompting a CISA Emergency Directive 26-03 mandating federal patching by May 17. The actor's infrastructure overlaps with Operational Relay Box (ORB) networks previously associated with China-nexus espionage operations by Mandiant researchers.
Gunra first emerged in April 2025 targeting South Korean organizations using a Conti-based locker, then evolved into a full RaaS operation by pivoting to a custom-built encryptor. Confirmed at 32 victims as of March 2026 following a late-2025 lull, with activity surging again after new affiliate recruitment. The group is notable for imposing no restrictions on target industries — including hospitals and critical infrastructure — and operating almost exclusively in darkweb forums including RAMP, Rehub, Tierone, and Darkforums.
A previously undocumented threat cluster disclosed by Google Threat Intelligence Group (GTIG) / Mandiant in April 2026. UNC6692 combines email-bombing tactics with Microsoft Teams helpdesk impersonation to deliver the custom 'SNOW' malware suite (SNOWBELT browser extension, SNOWGLAZE Python tunneler, SNOWBASIN persistent backdoor). The group abuses legitimate cloud infrastructure — AWS S3 buckets and Heroku subdomains — for payload delivery and C2, and targets senior-level employees at an elevated rate (77% of observed incidents from March–April 2026). Assessed as financially motivated based on credential-focused post-compromise actions including LSASS dumping, Pass-the-Hash, and Active Directory database exfiltration.
A rapidly maturing ransomware group first observed in February 2025 and strongly assessed as a rebrand of the defunct Rbfs operation, based on overlapping victims, shared infrastructure, and synchronized activity cessation. NightSpire reached 259 claimed victims across 30+ countries by May 2026, posting 74 victims in Q1 2026 alone to rank among the top active groups. In April 2026, the group publicly announced a shift toward a RaaS affiliate model, marking a structural evolution from its closed in-house operation.
DragonForce has evolved from a pro-Palestine hacktivist group into a self-styled ransomware 'cartel' offering a white-label infrastructure model where affiliates operate independent brands using DragonForce encryption, negotiation portals, and leak sites. Ranked 6th by victim volume (426 DLS postings) with 56 victims in March 2026 alone, the group absorbed displaced RansomHub affiliates in April 2025 and formalized a partnership with Scattered Spider. The alliance struck Marks & Spencer (April 2025), Co-op, and Harrods in a coordinated UK retail wave causing over £500M in M&S market cap loss. Law enforcement pressure on Scattered Spider is intensifying: alleged leader Tyler Buchanan pleaded guilty in early April 2026, and member 'Bouquet' (Peter Stokes, 19) was arrested at Helsinki Airport on April 10, 2026 and federally charged on April 28.
Rapid7 disclosed in early May 2026 that MuddyWater conducted a sophisticated false-flag operation, masquerading as the Chaos ransomware-as-a-service group to obscure Iranian state espionage activity. Rather than encrypting files, the group focused exclusively on credential harvesting via Microsoft Teams screen-sharing, MFA manipulation, and deploying remote access tools (DWAgent, AnyDesk, Game.exe RAT) for long-term persistence. The operation — linked to MOIS via the 'Donald Gay' code-signing certificate and moonzonet[.]com C2 infrastructure — represents a documented escalation in Iranian state actors adopting criminal RaaS branding to complicate attribution and delay defensive response.
Bitdefender Labs disclosed on May 13, 2026 that FamousSparrow conducted a multi-wave intrusion against an unnamed Azerbaijani oil and gas company between December 2025 and February 2026 — the first documented FamousSparrow targeting of South Caucasus energy infrastructure. The group repeatedly re-exploited the same vulnerable Microsoft Exchange Server entry point across three distinct waves despite remediation attempts, deploying the Deed RAT (ShadowPad successor) and TernDoor backdoors. This campaign is assessed as geopolitically driven: Azerbaijan has become a critical European energy supplier following the 2024 expiration of Russia's Ukraine gas transit agreement and 2026 Strait of Hormuz disruptions.
Newly tracked threat actor disclosed in Google/Mandiant's May 2026 GTIG report. In March 2026, TeamPCP (UNC6780) compromised multiple GitHub repositories including LiteLLM (a widely-used AI gateway library) and the Trivy vulnerability scanner, embedding a credential stealer called SANDCLOCK in affected build environments. Stolen AWS keys and GitHub tokens were then provided to ransomware affiliates, marking the first documented AI supply chain attack specifically targeting LLM infrastructure for downstream ransomware operations.
On May 11, 2026, Google's Threat Intelligence Group disclosed the first confirmed real-world case of a threat actor using an AI-developed zero-day exploit targeting a popular open-source web-based system administration tool. The group used a large language model to identify a semantic logic flaw — a hard-coded trust assumption in the authentication flow — and generated a Python-based 2FA bypass exploit bearing unmistakable LLM fingerprints (educational docstrings, a hallucinated CVSS score, textbook Pythonic formatting). The group had planned a mass exploitation event; Google coordinated a silent patch with the vendor to disrupt the operation before it launched.
Bitdefender published a major report on May 13, 2026 documenting FamousSparrow's first confirmed intrusion into South Caucasus energy infrastructure — a multi-wave campaign against an Azerbaijani oil and gas company running from December 2025 through February 2026. The group exploited the ProxyNotShell Exchange vulnerability chain (CVE-2022-41082/41040), returned to the same access vector three separate times despite remediation attempts, and deployed evolved variants of the Deed RAT and Terndoor backdoors with a novel two-stage DLL sideloading technique designed to evade sandbox analysis. This expansion marks a strategic pivot into European energy supply-chain targets driven by Azerbaijan's growing role as a gas supplier to 13 EU nations after the collapse of Russian transit agreements.
Rapid7 published research on May 6, 2026 exposing a new MuddyWater false-flag operation in which the Iranian MOIS-affiliated group masqueraded as the Chaos ransomware-as-a-service gang to conduct credential harvesting and long-term espionage against U.S. and MENA organizations. Rather than encrypting files, attackers used Microsoft Teams social engineering with interactive screen-sharing to steal VPN credentials and manipulate MFA, then established persistence via DWAgent and AnyDesk RATs. The operation follows a late-2025 case where MuddyWater similarly impersonated the Qilin RaaS ecosystem against an Israeli target, reflecting a systematic escalation of RaaS false-flag tradecraft to confuse defenders and complicate attribution.
The Gentlemen is the breakout ransomware group of Q1 2026, climbing to #2 globally with 400+ public victims in under 10 months of operation. Founded by 'hastalamuerte,' a former senior Qilin affiliate who departed after a $48,000 commission dispute, the group arrived with a pre-staged stockpile of approximately 14,700 compromised FortiGate devices (exploited via CVE-2024-55591) and 969 validated brute-forced VPN credentials. On May 4, 2026, the group itself was breached by an anonymous party who exfiltrated its internal database from hosting provider 4VPS, exposing full operational structure, ransom negotiations, and confirmed use of DeepSeek and Qwen AI models to accelerate ransomware development. Chain-victimization — using data from one victim to attack that victim's clients — is a confirmed tactic.
On May 11, 2026, Google's Threat Intelligence Group (GTIG) disclosed the first confirmed in-the-wild case of a threat actor using an AI model to discover and weaponize a zero-day vulnerability — a 2FA bypass logic flaw in a popular open-source web-based administration tool. The AI-generated Python exploit script contained hallmark indicators of LLM generation: educational docstrings, a fabricated CVSS score, and textbook Pythonic formatting. GTIG assessed with high confidence that the actors planned a mass exploitation campaign and intervened with the vendor to silently patch the flaw before it could launch. The case demonstrates that AI has compressed the timeline from vulnerability existence to weaponized exploit from weeks to days.
CYFIRMA's Research and Advisory Team discovered Rex Ransomware in underground forums on or before May 15, 2026. The strain encrypts files appending a '.rex48' extension (numeric suffix varies by variant) and drops an HTML ransom note (RANSOM_NOTE.html) claiming to have exfiltrated data for double-extortion leverage. Currently assessed as an early-stage threat with conventional encryption mechanics and no confirmed advanced capabilities, though CYFIRMA assesses it has potential to mature into a more sophisticated operation with expanding cross-platform support and structured extortion methodologies.